←back to thread

802 points rexpository | 1 comments | | HN request time: 0.663s | source
1. pests ◴[] No.44503079[source]
Support sites always seem to be a vector in a lot of attacks. I remember back when people would signup for SaaS offerings with organizational email built in (ie join with a @company address, automatically get added to that org) using a tickets unique support ticket address (which would be a @company address), and then using the ticket UI to receive the emails to complete the signup/login flow.