Hacker News new | ask | show | jobs
by bee_rider 812 days ago
IT still might not want you to follow the link.

* Other users might have, instead, an incompetently secured browser that they think is locked down on their work devices. It is hard for IT to distinguish between you and them.

* If the URL is personalized, it tells the attacker that the address is active. This is probably pretty limited help to the attacker. But it might tell them if your company emails follow a particular format, right?

1 comments

> * If the URL is personalized, it tells the attacker that the address is active. This is probably pretty limited help to the attacker. But it might tell them if your company emails follow a particular format, right?

I just asked chatgpt and it knows what email format the company I work for follows, so I'm not sure this is of particular value.

It's useful, even if you aren't a scammer, but it's generally not hard info to get elsewhere.