Hacker News new | ask | show | jobs
by jimbob45 16 days ago
They’ve done this to my workplace too. We have several domains for employee-concerning content and they’ve mirrored them and placed them at the top of Google’s search results. If you’ve forgotten the URL and go to Google it, you can get phished super easily.

I can see the elderly and the tech illiterate falling for similar schemes with mirrors of the NYT, CNN, FOX, etc.

1 comments

I’m experimenting with serving different content to users based on the presence of an mTLS cert in their USB key.

The idea is that authenticated employees see the company logo but scrapers get an IIS welcome page. Prevents cloned content from showing up on squatted domains.