These are the rules
internetrules.info
internetrules.info
My credit card company once called me up on some matter and the rep at the other end tried to verify my identity using the usual method (asking me about my mother's maiden name etc). I had to actually say "Wait, you called me. You should be verifying yourself to me". It actually turned out to be a legitimate call, but if I wasn't aware of this rule, a scammer might have easily got me.
P.S. I knew this rule because most of Kevin Mitnick's exploits (as he explains in his book) were based on this one vulnerability.
>How many other conveniences do we drop?
We evaluate them on a case by case basis, because we're thoughtful people.
Besides, I was genuinely curious. I know about phishing, but I don't know if you had anything else in mind. I learn a lot from the HN community.
Even if (and that's a big if) the hover-over doesn't fake you out because of a bug, are you willing to make sure you don't suffer from any of the problems in this?
Also issues with fonts having identical visuals for one and el and sometimes lower case eye, capital oh and zero, etc. And soon, probably (already?), unicode and other escape codes in urls.
DON'T RELY ON HOVERING OVER.
I can see the value in not blindly visiting URLs received via email. I do not see the value in refusing to send links via email. Unless you yourself are a scammer, making people do error-prone extra work to access your site does not protect anyone from getting scammed.
A little bit of suspicion can save you a world of hurt.
Nicely put. It's just a shame that so much of the modern world works to "a little bit of suspicion is literally the same as claiming aliens probe you nightly".