Live data from Hacker News

We Got Phished

exploratorium.edu

21–30 of 156 posts

Re: We Got Phished

#21
Google needs to add some optional intelligence to Chrome so that when it comes across a site with suspiciously similar design as key google urls by on a unrenognized url, it should warn the user.

Re: We Got Phished

#22
post #19

The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list" . Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.

Or it could come from an already infected account, which might make the e-mail even less suspicious.

Re: We Got Phished

#23
post #22
post #19

The beginning of the story is missing. PZ clicked on the link in the email because it was "received [...] from a familiar mailing list" . Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.

Or it could come from an already infected account, which might make the e-mail even less suspicious.

Yes but this would just mean an even bigger part of the story is missing — how that one got compromised.

Re: We Got Phished

#24

I use Lastpass and I just realized that it prevents phishing since it autocompletes my login info based on the domain.

That's why I love and recommend password managers to all my friends / relatives. Not only does it help prevent phishing but it promotes stronger passwords.

Re: We Got Phished

#25

I use Lastpass and I just realized that it prevents phishing since it autocompletes my login info based on the domain.

Which is yet another reason (not that we needed one) why those pages which try to prevent autocomplete of passwords are wrong, wrong, wrong.

Re: We Got Phished

#26
post #17

It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.

How does it help? Can't the attacker make a query to Google for the user image and display it on the phishing page?

[deleted]

Re: We Got Phished

#27
post #17

It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.

How does it help? Can't the attacker make a query to Google for the user image and display it on the phishing page?

No. There is no email-to-profile-pic mapping endpoint for unauthenticated users, to my knowledge.

Re: We Got Phished

#29

Google needs to add some optional intelligence to Chrome so that when it comes across a site with suspiciously similar design as key google urls by on a unrenognized url, it should warn the user.

[deleted]

Re: We Got Phished

#30

Google needs to add some optional intelligence to Chrome so that when it comes across a site with suspiciously similar design as key google urls by on a unrenognized url, it should warn the user.

You can use Google's AMP that is hosted on their domain, to host a redirect, effectively using their domain to host the phishing attempt. Check the screenshots on http://motherboard.vice.com/read/how-hackers-broke-into-john...
Post reply on HN