Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sorry but the imagecontent-x.com url should throw red flags for anyone.




This is exactly how not to defend against phishing. The meaningful defense is to foreclose on it entirely, not to just get super good at spotting fakes.

> The meaningful defense is to foreclose on it entirely

Sounds easy enough in theory. How do you do that in practice?


Use passkeys. Bully services that don’t offer them or lock them behind enterprise plans into implementing them.

That’s it. The single working Defense against credential theft.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: