Archive for April 21, 2025

Google OAuth Abused by Phishers to Spoof Google in DKIM Replay Attack

Posted in Commentary with tags on April 21, 2025 by itnerd

In a novel attack, hackers are sending fake emails that appear to come from Google’s systems – no-reply@google.com – bypassing all verifications and the DomainKeys Identified Mail (DKIM) authentication method and pointing to a fraudulent page that collects logins.

You can get more details about this here: https://threadreaderapp.com/thread/1912439023982834120.html

Roger Grimes, data-driven defense evangelist at KnowBe4, commented:

“DMARC, DKIM, and SPF all focus on the DNS domain involved. The “email address” portion can change and the DMARC, DKIM, and SPF check will be just fine. So, if I can get an email sent from a common, global domain like google.com or hotmail.com, I can get nearly any email address name I like (e.g., the realbillgates@gmail.com) and it’s going to pass the checks.

DMARC, DKIM, and SPF should be understood this way: I claim to be from this and this domain (e.g., google.com) and if I pass the checks, I really am from that claimed domain. The user still has to look at the entire email address (friendly name and domain name) and figure out if it is or isn’t legitimate for the domain being claimed. On top of that, malicious scammers deploy DMARC, DKIM, and SPF at higher rates than non-scammers. Scammers early on decided that they needed all the domains they used to have DMARC, DKIM, and SPF enabled so their scammy email didn’t end up in the Junk Mail, Spam folder, or be rejected and never make it to the end-user. To that end, DMARC, DKIM, and SPF have been a total success. And at the same time it is a victim of its own success, with scammers using it even more than legitimate senders.”

I have certainly seen this with this attack that makes refund scam emails look like they are coming from Microsoft. Thus I am not shocked that this is happening on the Google side of the fence. And I fully expect to see more of this sort of thing going forward.

Introducing Rogers Xfinity Multiview: Watch multiple 2025 Stanley Cup Playoff games all on one screen

Posted in Commentary with tags on April 21, 2025 by itnerd

As the first round of the 2025 Stanley Cup Playoffs heats up, Rogers announced today a preview of Rogers Xfinity Multiview, a new service that gives Canadian hockey fans the chance to watch two games at once – all on the same screen.

Rogers Xfinity Multiview will launch on select nights throughout the first round of the 2025 Stanley Cup Playoffs starting Monday, April 21 at 9:30 p.m. ET. Customers just need to say “Multiview” into their award-winning voice remote to enjoy side-by-side coverage, with the ability to switch audio and add captions.

These exclusive events are a free preview of the new Rogers Xfinity Multiview experience, starting with this year’s 2025 Stanley Cup Playoffs. Rogers plans to continue building on its Rogers Xfinity Multiview experience, including the ability to watch up to four live events at the same time, increasing the number of sports, and the ability for customers to build their own Multiview experience.

Starting tonight, customers can experience these matchups using Rogers Xfinity Multiview:

  • April 21: Colorado at Dallas (9:30 p.m. ET) and Edmonton at Los Angeles (10 p.m. ET)
  • April 22: New Jersey at Carolina (6 p.m. ET) and Ottawa at Toronto (7:30 p.m. ET), Florida at Tampa Bay (8:30 p.m. ET) and Minnesota at Vegas (11 p.m. ET)
  • April 23: Dallas at Colorado (9:30 p.m. ET) and Edmonton at Los Angeles (10 p.m. ET)
  • April 24: Florida at Tampa Bay (6:30 p.m. ET) and Toronto at Ottawa (7 p.m. ET), Vegas at Minnesota (9 p.m. ET) and Winnipeg at St. Louis (9:30 p.m. ET)
  • April 25: Washington at Montreal (7 p.m. ET) and Carolina at New Jersey (8 p.m. ET)

Sportsnet is the place to catch all the 2025 Stanley Cup playoff action and Rogers Xfinity gives Canadians the best seat in the house. To learn more about Rogers Xfinity visit rogers.com/xfinity.

Is There An Issue With Apple TV+ Where User Accounts Are Being Locked Right After Purchasing?

Posted in Commentary with tags on April 21, 2025 by itnerd

I am asking this question because a reader of this blog pinged me via email on Sunday asking this question and directing me towards this Reddit thread which has a few people who have lodged complaints about their Apple TV+ accounts being locked hours or days after signing up for the service. I have to admit that I have not heard of this issue, but a quick search found a this thread on Apple’s own support forums. Not to mention this and this on Reddit. All of which have similar enough experiences to get my attention .

Now Apple does have this support document that offers some advice in terms dealing with this issue. But given that these Reddit and Apple Support Forums post exist, I wonder how effective this document is. Thus I am asking for your help on this. Have you had this issue? If so, how did you fix it? Or have you not fixed it? I’d love to figure out how widespread this problem is. Leave your feedback in the comments and let’s get a discussion going.

Tom Whaley Joins Hammerspace as Head of Americas Sales

Posted in Commentary with tags on April 21, 2025 by itnerd

Hammerspace today announced the appointment of Tom Whaley as its Vice President of Americas Sales. He joins the company from WEKA with an extensive sales leadership history focusing on revenue delivery at organizations including VAST Data, mParticle and NetApp.

With over 20 years of experience focusing on Fortune 500 customers, Whaley excels in guiding sales strategy and execution centered around customers’ changing business and technical needs, with a track record of delivering consistent year-over-year revenue growth.

Whaley’s appointment comes at a time of unprecedented growth at Hammerspace. Recently, the company announced several of its strategic venture investors who invested $100 million in new growth capital in Hammerspace. The company has also rapidly bolstered its global sales team with top performers as demand surges for its Data Platform as the future of AI and hybrid cloud storage.

Today’s enterprises are challenged by the need to optimize high-performance data access for AI workloads, scale their infrastructure efficiently, and manage complex, distributed data environments. Hammerspace’s award-winning Data Platform delivers a competitive edge across every dimension of unstructured data: storage, access, movement and deployment. Whether training thousands of GPUs on-premises or in the cloud, deploying large-scale inference or maximizing NVMe performance in local GPU servers, Hammerspace is purpose-built to unleash data performance at scale.

Whaley stated that Hammerspace’s technology and culture were what drew him to the company.

Current open positions at Hammerspace are available on its Careers page.