// SPDX-License-Identifier: UNLICENSED
on 6 lines of trivial example code? Of all the things to make proprietary...https://stackoverflow.com/questions/68332228/spdx-license-id...
For the fun history, @DonHopkins had a thread a few years back:
https://bjk5.com/post/44698559168/breaking-down-amazons-mega...
Deleted Comment
1. You go to evil.example.com, which uses this flow.
2. It prompts you to enter your email. You do so, and you receive a code.
3. You enter the code at evil.example.com.
4. But actually what the evil backend did was automated a login attempt to, like, Shopify or some other site that also uses this pattern. You entered their code on evil.example.com. Now the evil backend has authenticated to Shopify or whatever as you.
Wait what? Anyone here getting 4.7% pay rises?
https://vorpus.org/blog/why-im-not-collaborating-with-kennet...
In this case, the user has already authenticated with three factors(!). Framing potential VPN use as "suspicious" normalizes a more locked down, surveilled web with fewer rights for humans. We shouldn't be pushing that direction.
https://lyons-den.com/CV/David_Lyon_CTO_CV_2025.pdf
EDIT: he has added three(!) separate mentions of the same incident to his résumé