9 ms·
I was thinking about exactly that and then I found this comment. One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absol
by someoneeestis 4d ago
I was thinking about exactly that and then I found this comment.
One spoofs an email domain and then is able to get trust from a "modern global fintech"? Absolutely ridiculous. Having worked for several global scale tech companies, I've seen first hand how security is at the absolutely bottom of the list. It does not translate to $$$ so it is uncared for.
Revolut keeps pestering me with requests for interviews and I keep running away from it. One more con (pun intended) to the list.
- throw-the-towel 4d agoThey also pay peanuts, and the culture is toxic.
- Maxion 4d agoIn the countries you are licensed in you are legally required to reply to law enforcement requests. In most places there is no official channel for this. It is literally stuff like LE@Fintech.com. Emails come from all over and random domains that appear official-ish. Most official domains do not have DKIM or SPIF setup, very easy to spoof. LE by and large do not take security seriously, they do not take data transfer seriously. Most requests are digitally signed PDFs that come via email, require a response sent to another email.
- ifwinterco 4d agoYeah the secure thing is to ignore all requests from domains without DKIM, but that would mean ignoring a lot of legitimate requests which is illegal. Revolut are known to be a bit shady but in this case they're damned if they do and damned if they don't
- someoneeestis 4d agoBut that's the thing, they have the money to have people chasing down the official channels of whatever email that comes from to confirm their authenticity. Cybersecurity 101: Call back the bank at the official number and all that yada yada.