"Access your new employee bonus plan here at HR's portal: dropbox.hr/phishinglink" etc...
I don't know why big companies, especially, allow other domains to be used for official business.
"Access your new employee bonus plan here at HR's portal: dropbox.hr/phishinglink" etc...
I don't know why big companies, especially, allow other domains to be used for official business.
I also regularly get XSS warning from the myriad login domains that they pass credentials through in their web portals.
Sometimes I wonder how their services are set up to talk to each other, I'm sure it's a terrifying Gordian knot.
A complete shitshow.
https://www.ghacks.net/2019/04/17/microsoft-lost-control-ove...
Many large US banks bounce the customer through several totally different and unrecognizable top level domains as part of routine web access.
If I'm Example Ltd. and my customers are trusting me to keep their data on example.com safe, and I use example.blog for my blog hosted by Jimbo's Blogging Service, I don't need to worry about Jimbo or his employees or hackers targeting my blog getting access to example.com's cookies, local storage, etc.
Cf. It's really hard—in some cases impossible, without use of the Public Suffix List[0]—to completely wall off blog.example.com from example.com.
[0] https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Se...
The security policy at the FAANG I used to work at required third party vendor code to run on other domains for this reason.
Dropbox already had this when I joined in 2015 drl/X "dropbox redirect link" would direct you to various internal sites and documentation.