526

From 2024, but funny to read....

What makes this situation so ridiculous is that while we're all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers!

you are viewing a single comment's thread
view the rest of the comments
[-] SpaceCowboy@lemmy.ca 74 points 3 days ago

The mentality around online security now is to push the responsibility onto someone else instead of investing any real effort into it. So you need to be aware of phishing scams, but the company isn't going to make any kind of effort towards it. That's on you, not on us!

Microsoft is really terrible about this. They have at least 20 different domains and many of them ask you to enter your credentials into them. Usually you're redirected to something like login.microsoft-online.com or something like that and enter in your credentials into that. Always seems like a phishing thing... why wouldn't it just be login.microsoft.com? I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain. So instead ever department registers a domain that they can control. The end result is you're dumping your credentials into random looking domains, then downloading and installing software from other random domains.

They just don't really care as long as there's no legal liability. You're data gets compromised because you didn't notice that you put your credentials into online.microsoft-login.com instead of login.microsoft-online.com, that's your mistake and no one can sue microsoft for it. As long their negligence doesn't meet the legal definition of negligence, they're not going to put an any kind of effort.

Anti-phishing training could be so much better... "don't put your credentials into anything other that *.microsoft.com". But since these companies won't make any effort, anti-phishing training amounts to "Just be careful or whatever LOL!"

[-] daychilde@lemmy.world 22 points 3 days ago

You’re data

Bad grammar is the hallmark of a scam. THIS COMMENT IN A SCAM, PEOPLE!!! DO NOT READ!!!

;-)

I think you're spot-on regarding those domains. People trying to make things work and fighting (and losing) against internal pressures, making the situation ten times worse.

For years, anti-phishing training sucked most places - I suspect it still does most places - but my previous employer actually got a better one in the last couple of years before I left. Most phishing training just says "Don't click links from sources you don't trust" and doesn't teach you what to look for.

To me, understanding how URLs work is essential. Being able to identify the actual domain is critical, but also at least being able to identify when the parameters start is also critical. But that fails when companies register weird domains or use third-party shorteners and things like that.

The linked article is a fantastic example of the worst legit comms I've seen. Absolutely looks scammy all the way through.

[-] billwashere@lemmy.world 5 points 2 days ago

I'm guessing within Microsoft, it's probably was a pain in the ass to get whatever department in MS that controls the microsoft.com domain to set up a subdomain.

I’ve had to deal with shit like this personally so I guarantee that was at least one reason. The departments that control the domain treat it like some sort of power trip and make it hard to do the smart thing.

[-] Zenorbi@lemmy.world 13 points 2 days ago

And what is even better, is that microsoft-online.com isn't owned my microsoft. It is a potential phishing site. The correct one is microsoftonline.com

[-] trolololol@lemmy.world 4 points 2 days ago

Hey fellow interneter, can I join you at screaming at the clouds?

[-] Evotech@lemmy.world 1 points 2 days ago

Microsoft is just a web of legacy software mixed with modern shit. Its a web of stuff that one human just cannot comprehend. Sp yeah

[-] Buddahriffic@lemmy.world 2 points 1 day ago

Plus probably a ton of AI slop by now.

this post was submitted on 20 Sep 2026
526 points (98.3% liked)

Technology

88199 readers
3873 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS