• 0 Posts
  • 19 Comments
Joined 1 year ago
cake
Cake day: August 18th, 2023

help-circle





  • How do you know this? Of course there are lots of reasons for why they’d want to enforce minimum browser versions. But security might very well be one of them. Especially if you’re a bank you probably feel bad about sending session tokens to a browser that potentially has known security vulnerabilities.

    And sure, the user agent isn’t a sure way to tell whether a browser is outdated, but in 95% of cases it’s good enough, and people that know enough to understand the block shouldn’t apply to them can bypass it easily anyway.


  • There’s no reason your clients can’t have public, world routeable IPs as well as security.

    There are a lot of valid reasons, other than security, for why you wouldn’t want that though. You don’t necessarily want to allow any client’s activity to be traceable on an individual level, nor do you want to allow people to do things like count the number of clients at a particular location. Information like that is just unnecessary to expose, even if hiding it doesn’t make anything more secure per se.










  • Many real scams are not this obvious, plus a lot of old people are senile to some degree, which these scammers are exploiting. My grandma was contacted by “her bank” about verifying her identity, and after a few minutes of establishing a backstory they asked her for her debit card info including CVV. It all sounded very legit, and they even “transferred her to another department” with hold music and everything. Luckily, she didn’t fall for it.