Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. GPT-6 Sol and Luna(openai.com)
    696comments
  2. Claude Opus 5.5(anthropic.com)
    909comments
  3. Transit rewards(waymo.com)
    94comments
  4. Data-only attacks are easier than you think (2024)(usenix.org)
    14comments
  5. OpenAI GPT–6 Astra breaks Enigma message that has resisted solution since 2005(cryptocellar.org)
    381comments
  6. Microsoft killed FoxPro in 2007. Anyway, here's FoxPro revived(foxscript.org)
    169comments
  7. 'We hacked the FBI:' Hackers say they have data on all FBI employees(404media.co)
    392comments
  8. ReBarUEFI: Resizable BAR for almost any UEFI system(github.com/xcuri0)
    41comments
  9. Show HN: Npunlock – Run custom C kernels for Intel NPUs(github.com/hsfzxjy)
    1comments
  10. What California is learning from solar panels built over irrigation canals(kqed.org)
    310comments
  11. SAML: A fractal of bad design(trailofbits.com)
    128comments
  12. How did AMD Ryzen get 50% faster in two years?(lemire.me)
    115comments
  13. No Easy Fix for Bogus Respondents in Online Opt-In Polls(pewresearch.org)
    5comments
  14. WordPress: Unauthenticated path traversal leading to conditional RCE(github.com/wordpress)
    93comments
  15. Claude Opus 5.5 Intelligence, Performance and Price Analysis (Max)(artificialanalysis.ai)
    82comments
  16. Pentagon says overreliance on AI contributed to missile strike on Iran school(bloomberg.com)
    294comments
  17. Unreal Agent(unreallabs.ai)
    99comments
  18. The softness of metal(psyche.co)
    5comments
  19. Grammarly will send unhinged messages to all your users if you try to cancel(reddit.com)
    17comments
  20. The current balance of power in open models(interconnects.ai)
    25comments
  21. Delta: Highly available, strongly consistent storage using chain replication (2022)(fb.com)
    1comments
  22. People hooked on vapes try a new way to quit: cigarettes(bloomberg.com)
    171comments
  23. OpenAI is well positioned to fast-follow Jev(arcturus-labs.com)
    205comments
  24. Obscura: VPN that can't log your activity(obscura.com)
    93comments
  25. Show HN: JevBench, a reproducible benchmark for typed decision models(benchmarkheaven.com)
    24comments
  26. Side-stepping the Secretary Problem, unwittingly(evalapply.org)
    13comments
  27. Markdown in /src(htmx.org)
    61comments
  28. Native apps written in TypeScript and CSS(github.com/geastack)
    36comments
  29. Apple has added persistent 'ads' to iOS, and it's driving users crazy(techradar.com)
    506comments
  30. 16-bit Intel 8088 chip (c. 1985)(allpoetry.com)
    15comments

Revolut confirms customer data breach, falling for fake government requests

53 pointsby 10d agoreuters.com
1 comments
10d agoHN ↗

sent from a legitimate government agency email domain,

DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case.

Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them.

After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.