Security Is Hard, Y'all
2 hours ago
- The author encountered a seemingly legitimate Cloudflare product page that exhibited multiple signs of a phishing attack, such as an unfamiliar domain and a suspicious permission request.
- Despite initial suspicion, the product ('Wallet') was later confirmed to be legitimate, highlighting the difficulty in distinguishing real sites from phishing attempts.
- The author criticizes the lack of best practices, including a missing 'Report' option and a misleading green checkmark UI element, and urges developers to follow security standards.
- Recommendations include hosting content on trusted domains, providing clear security cues, enabling easy scam reporting, and testing security flows.