Hacker News new | past | comments | ask | show | jobs | submit login

"We used to do it as jokes but it was never used for something like this and I can’t imagine anyone that would hate me enough to go this far."

It's all fun and games, until ...




What even is the point of requiring a dongle if you can do this? Checkbox security at its best.


You can do this with most systems. Just edit the From field in a script. External emails will usually be blocked and you can still see in the header that it was not sent from the actual account so that the risk of fraud is low.

If it happened with a script it should be easy to find out by looking at logs and/or header.


Yeah, at this point if it's an actual cryptographic security key, it could be used to sign each and every e-mail.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: