A rant about phishing: It's not the user's fault (and not DNS either)

Curated from Lobsters

Phishing remains the primary vector for corporate breaches, yet post-incident reviews often default to blaming user error. This piece challenges that narrative by dissecting the technical architecture that makes spoofing trivial. It argues that relying on human vigilance against sophisticated spoofing is a flawed security model. The author highlights how modern infrastructure, including DNS and email authentication failures, creates an environment where even trained professionals are vulnerable. For SREs and DevOps leads, this shifts the focus from training fatigue to systemic hardening. The core argument is that security must be designed to fail safely, not depend on perfect user behavior. A concrete takeaway: audit your organization’s DMARC, SPF, and DKIM records immediately. If they are not strictly enforced, you are leaving the front door open, regardless of how well your staff is trained.

p a href="https://lobste.

— Lobsters

Read the full article on Lobsters →