New Security Warning Issued for Google's 1.8B Gmail Users
forbes.com
forbes.com
They've got that "Opinions expressed by Forbes Contributers are there own" hover tip hidden on the byline of just about every article. I don't think their editors vet or screen articles beyond passing them through Grammarly, if even that.
The site has as much credibility as Tumblr.
A vulnerability found in Google’s implementation of SPF in Gmail. The company is prioritizing a fix.
I think for people who fall for email scams the behavior change is to ignore all emails and training them to trust some stupid blue check mark is not good.
[1] - https://www.fastmail.help/hc/en-us/articles/7002542139663-Us...
I suspect that GMail is going to have to start caching of verified CA chain links ... at browser-level ... in JavaScript.
Google's security team seems to make mistakes like this more often recently. I know they've got an onslaught of reports and (lacking a real support system) the security report channel has become an alternate way to escalate non-security issues, so I don't envy the challenge.
I knew a guy who wouldn't open my email to him, because the icon/avvie was a question mark or something, and so it must be malware. He pointed it out to me in person.
Now there is a social-medial industry standard 'blue check' or 'verified account'. Instead of a golden padlock meaning the same, narrow thing, everywhere and always, the blue checks are implemented however they want. You can put a blue check in your Slack status if you feel like it. So what does a blue check mean?