You could even combine the two. Post the blog to hacker news, then send phishing email pointing to HN post. That is a trusted link. Then the user will likely click the source link in HN.
Obviously, a lot harder and lower chance of success, but not impossible.
In general maybe, in this particular case it's gonna be challenging however, as gitlab is a remote company so most employees will logon from residential ips
My present employer's VPN client goes a step further and mangles the routing table to deny access to my own LAN while connected.
it was always only the 10.0.0.0/8 and some /24 ranges from 192.168.0.0/16 at my current job
I guess they both suck pretty hard.
You definitely could perform a watering hole attack if you compromised a site that always gets on the front page of HN. If I were an evil hacker and I wanted to compromise HN I would instead attack a site like rachelbythebay.com or some other popular blogger then just wait for HN’ers to click the link.
(Myself included)
Not a phishing attempt, I swear!
"Why rust is not a real programming language"
"It's a complete waste of time to learn C++ in 2020"
"Rust is 2x as fast as C++"
And then just point to an article about Rust the game.
Jokes aside, I love the name, the pun is nice, but man it makes searching a pain. I’ve ended up too many times in pages related to the game or to actual rust (as in iron).