Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    680comments
  2. Claude Opus 5.5(anthropic.com)
    897comments
  3. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    381comments
  4. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    167comments
  5. Data-only attacks are easier than you think (2024)(usenix.org)
    11comments
  6. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    378comments
  7. Transit rewards (Waymo pays you to take the train)(waymo.com)
    83comments
  8. ReBarUEFI: Resizable BAR for almost any UEFI system(github.com/xcuri0)
    40comments
  9. What California is learning from solar panels built over irrigation canals(kqed.org)
    296comments
  10. No Easy Fix for Bogus Respondents in Online Opt-In Polls(pewresearch.org)
    3comments
  11. SAML: A fractal of bad design(trailofbits.com)
    125comments
  12. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    112comments
  13. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    93comments
  14. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    80comments
  15. Pentagon says overreliance on AI contributed to missile strike on Iran school(bloomberg.com)
    282comments
  16. Unreal Agent(unreallabs.ai)
    95comments
  17. The current balance of power in open models(interconnects.ai)
    22comments
  18. The softness of metal(psyche.co)
    4comments
  19. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    162comments
  20. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    204comments
  21. Obscura: VPN that can't log your activity(obscura.com)
    91comments
  22. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    22comments
  23. Grammarly will send unhinged messages to all your users if you try to cancel(reddit.com)
    9comments
  24. Native apps written in TypeScript and CSS(github.com/geastack)
    35comments
  25. Side-stepping the Secretary Problem, unwittingly(evalapply.org)
    13comments
  26. Markdown in /src(htmx.org)
    59comments
  27. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    502comments
  28. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    15comments
  29. Delta: Highly available, strongly consistent storage using chain replication (2022)(fb.com)
    1comments
  30. Show HN: Training a model to identify AI web content from structure alone(arxiv.org)
    14comments

Revolut confirms customer data breach, falling for fake government requests

53 pointsby 10d agoreuters.com
1 comments
10d agoHN ↗

sent from a legitimate government agency email domain,

DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case.

Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them.

After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.