{"id":42655,"date":"2024-03-27T14:43:12","date_gmt":"2024-03-27T18:43:12","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=42655"},"modified":"2024-06-24T15:33:16","modified_gmt":"2024-06-24T19:33:16","slug":"1password-co-tracking-links","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2024\/03\/27\/1password-co-tracking-links\/","title":{"rendered":"1Password.co Tracking Links"},"content":{"rendered":"<p><a href=\"https:\/\/social.panic.com\/@cabel\/112050188008815465\">Cabel Sasser<\/a>:<\/p>\n<blockquote cite=\"https:\/\/social.panic.com\/@cabel\/112050188008815465\">\n<p>PSA: 1Password uses &ldquo;1Password.co&rdquo; for email links &mdash; instead of their usual &ldquo;1Password.com&rdquo; domain.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.social\/@chockenberry\/112049988291729734\">Craig Hockenberry<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.social\/@chockenberry\/112049988291729734\"><p>So the &ldquo;phishing link&rdquo; with the .co domain was a valid link and <a href=\"https:\/\/support.1password.com\/email-domains\/\">documented as such<\/a>.<\/p><p>But I still find it inexcusable.<\/p><p>That link caused 30 minutes of complete panic. I know enough about how phishing works to know how absolutely fucked I&rsquo;d be if that link hadn&rsquo;t just been to track my click in the email.<\/p><p>Which brings up another question: why is a company I pay to protect my private information using tracking links in the emails it sends me?<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/social.panic.com\/@cabel\/112050188008815465\">Cabel Sasser<\/a>:<\/p>\n<blockquote cite=\"https:\/\/social.panic.com\/@cabel\/112050188008815465\">\n<p>Craig isn&rsquo;t an idiot; it 100% feels like phishing. If you ask me, tracking link clicks and opens in emails is simply not worth the potential freak-out when you think you&rsquo;ve been phished[&#8230;]<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.online\/@sam@samschmitt.social\/112050216460174955\">Sam Schmitt<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.online\/@sam@samschmitt.social\/112050216460174955\"><p>Another way of looking at this: [it&rsquo;s] best practice to use a different domain for stuff like this. If the marketing tool gets compromised, you don&rsquo;t want it to have the ability to send actual phishing domains on the real domain. You&rsquo;ll see it with other stuff, like Microsoft logins being on &ldquo;microsoftonline.com&rdquo;. I agree it does mean you do some double takes.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/mastodon.online\/@hexbatch\/112050520827801615\">Hex Batch<\/a>:<\/p>\n<blockquote cite=\"https:\/\/mastodon.online\/@hexbatch\/112050520827801615\">\n<p>best practice is using subdomains and not cousin domains.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.troyhunt.com\/thanks-fedex-this-is-why-we-keep-getting-phished\/\">Troy Hunt<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.troyhunt.com\/thanks-fedex-this-is-why-we-keep-getting-phished\/\"><p>What makes this situation so ridiculous is that while we&rsquo;re all watching for scammers attempting to imitate legitimate organisations, FedEx is out there imitating scammers! Here we are in the era of burgeoning AI-driven scams that are becoming increasingly hard for humans to identify, and FedEx is like &ldquo;here, hold my beer&rdquo; as they one-up the scammers at their own game and do a perfect job of being completely indistinguishable from them.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/12\/07\/fastspring-risk-screening\/\">FastSpring Risk Screening<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Cabel Sasser: PSA: 1Password uses &ldquo;1Password.co&rdquo; for email links &mdash; instead of their usual &ldquo;1Password.com&rdquo; domain. Craig Hockenberry: So the &ldquo;phishing link&rdquo; with the .co domain was a valid link and documented as such.But I still find it inexcusable.That link caused 30 minutes of complete panic. I know enough about how phishing works to know [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2024-03-27T18:43:14Z","apple_news_api_id":"4c42e90a-67a7-4326-862f-cf1863e0593e","apple_news_api_modified_at":"2024-03-27T18:43:14Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/ATELpCmenQyaGL88YY-BZPg","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[284,150,1200,355,2614],"class_list":["post-42655","post","type-post","status-publish","format-standard","hentry","category-technology","tag-1password","tag-email","tag-phishing","tag-privacy","tag-shipping"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42655","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=42655"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42655\/revisions"}],"predecessor-version":[{"id":42656,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/42655\/revisions\/42656"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=42655"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=42655"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=42655"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}