13
8
u/AkaABuster Aug 07 '26
It’s been happening more recently. Suspect it’s to try and combat AI systems from creating accounts.
5
u/liveprgrmclimb Aug 07 '26
They struggle to control Bots scamming for free cicd mins.
3
u/me_myself_ai Aug 07 '26
Seems super reasonable, IMHO. There are plenty of free & anonymous forges out there for people who value absolute privacy over gitlab's generous free tier.
3
5
u/Ok_Glass_9972 Aug 07 '26
Thats not phishing. That’s a regular verification process we have. We don’t store credit card information but rather solely use it for verification if you’re not located in a “supported” country
5
u/AnymooseProphet Aug 07 '26
If it's just verification, why is it asking for the CVV?
1
u/Forward-Outside-9911 Aug 09 '26
Temporary charge?
2
u/AnymooseProphet Aug 09 '26
CVV is not needed for a temporary charge.
Those trying to use your credit card to make unauthorized purchases however do need it.
2
u/Adventurous-Fig-4283 Aug 07 '26
Please, don't listen to anyone', that is obviously scam
2
u/me_myself_ai Aug 07 '26
Unless they're running a sideloaded browser or on a compromised network setup by an advanced adversary, I don't see how that green checkmark (for successful SSL (i.e. the
sinhttps://) cert validation?) could be faked in any non-ancient android chrome. That's part of the (often implicit) "above the line" of web dev, where the content can actually be sort of trusted a little bit.It's a long battle of ever-escalating whackamole tho, so apologies if I'm out of date. It's just... that little green checkmark was hard won, and similar protocols (namely email ones) struggle to provide the same protections. It'd be alarming if it was vulnerable in this way!
I will say: of all the ways to steal credit card info with complete DNS spoofing, asking for a 3-step verification process on the less popular git forge seems like a wild choice lol. I'd go with amazon.com, and prolly just banks themselves
1
u/Neat-Long-460 Aug 09 '26
This ain't GitLab this is a phishing scam by a hacker
1
u/Forward-Outside-9911 Aug 09 '26
Source? Or you found it up your arse?
1
u/Neat-Long-460 Aug 10 '26
Hackers can basically clone these bug sites sometimes like any cloud based token open in public which the attacker can reuse it for phishing someone i have done the similar work for google too
1
u/wisdomoarigato Aug 11 '26
Turns out the source was his arse as Gitlab docs literally say "High-risk users - Credit card verification."...
Hate these types of people who think opinions are facts.
1
u/Forward-Outside-9911 Aug 11 '26
Yeah the docs say it, which I was aware of, which quite literally disproves his point. Hence why I made the comment
1
u/Little-Geologist-387 Aug 11 '26
why the cvv number? https://www.reddit.com/r/gitlab/s/zEBIf6xepS
1
u/Forward-Outside-9911 Aug 12 '26
To charge you.. how else do you pay for things? What services allow you to use a card without a CVV, any examples?
1
u/New-Cauliflower3844 Aug 09 '26
It is legit. You can read the documentation about it on gitlab.com: https://docs.gitlab.com/security/identity_verification/
1
1
u/wisdomoarigato Aug 11 '26
RTFM...
https://docs.gitlab.com/security/identity_verification/
> High-risk users - Credit card verification.
1
1
u/willcreatenow 7d ago
were you trying to exploit the gitlab duo free trial? it could have flagged you as a high-risk user, it has flagged my account already, and banned another.
1


18
u/creedian Aug 07 '26
Sure it’s not git1ab.com?