Hacker News new | ask | show | jobs
by hathchip 1023 days ago
The email allows you to enter a new password, it doesn't validate some other access to your account by clicking yes.
1 comments

They will just wait for you to get used to this, then stop triggering Facebook to send you legitimate emails and start sending you similarly-looking phishing emails similarly often. It may happen to be enough to view a phishing email, let alone click anything in it to get pwned.
What if they send you dozens of these, then one that actually looks legitimate, saying something like "We have detected 24 login attempts to your account in the past 30 days coming from this location, click here to see additional details and / or improve your account security", containing a phisher's login form.
surely the more of these they send, the less likely you are to click on them
Maybe they would at some point send an email offering to turn off these annoying notifications with a malicious URL?
Very questionable. Some people will come to completely ingoring them (which isn't good either), some will click anything out of being too annoyed. Whatever, people can be manipulated into doing some statistically predictable actions with decreased awareness this way and this is a vulnerability.