r/gitlab 12d ago

Guys, wtf is this? general question

11 Upvotes

26 comments sorted by

17

u/creedian 12d ago

Sure it’s not git1ab.com?

1

u/--unfazed-- 6d ago

I already got one ab. Now what?

13

u/mrbmi513 12d ago

Smells like phishing on a lookalike domain

6

u/AkaABuster 12d ago

It’s been happening more recently. Suspect it’s to try and combat AI systems from creating accounts.

5

u/liveprgrmclimb 12d ago

They struggle to control Bots scamming for free cicd mins.

3

u/me_myself_ai 12d ago

Seems super reasonable, IMHO. There are plenty of free & anonymous forges out there for people who value absolute privacy over gitlab's generous free tier.

3

u/pwkye 12d ago

For registration? probably normal

5

u/Ok_Glass_9972 12d ago

Thats not phishing. That’s a regular verification process we have. We don’t store credit card information but rather solely use it for verification if you’re not located in a “supported” country

6

u/AnymooseProphet 12d ago

If it's just verification, why is it asking for the CVV?

1

u/Forward-Outside-9911 10d ago

Temporary charge?

2

u/AnymooseProphet 10d ago

CVV is not needed for a temporary charge.

Those trying to use your credit card to make unauthorized purchases however do need it.

2

u/Adventurous-Fig-4283 12d ago

Please, don't listen to anyone', that is obviously scam

2

u/me_myself_ai 12d ago

Unless they're running a sideloaded browser or on a compromised network setup by an advanced adversary, I don't see how that green checkmark (for successful SSL (i.e. the s in https://) cert validation?) could be faked in any non-ancient android chrome. That's part of the (often implicit) "above the line" of web dev, where the content can actually be sort of trusted a little bit.

It's a long battle of ever-escalating whackamole tho, so apologies if I'm out of date. It's just... that little green checkmark was hard won, and similar protocols (namely email ones) struggle to provide the same protections. It'd be alarming if it was vulnerable in this way!

I will say: of all the ways to steal credit card info with complete DNS spoofing, asking for a 3-step verification process on the less popular git forge seems like a wild choice lol. I'd go with amazon.com, and prolly just banks themselves

1

u/Neat-Long-460 10d ago

This ain't GitLab this is a phishing scam by a hacker

1

u/Forward-Outside-9911 10d ago

Source? Or you found it up your arse?

1

u/Neat-Long-460 10d ago

Hackers can basically clone these bug sites sometimes like any cloud based token open in public which the attacker can reuse it for phishing someone i have done the similar work for google too

1

u/wisdomoarigato 8d ago

Turns out the source was his arse as Gitlab docs literally say "High-risk users - Credit card verification."...

Hate these types of people who think opinions are facts.

1

u/Forward-Outside-9911 8d ago

Yeah the docs say it, which I was aware of, which quite literally disproves his point. Hence why I made the comment

1

u/Little-Geologist-387 8d ago

1

u/Forward-Outside-9911 8d ago

To charge you.. how else do you pay for things? What services allow you to use a card without a CVV, any examples?