Obviously in the HN-type crowd, you know to always carefully check the URL of links and form submissions. But I just don't know how realistic it is for that to be expected of an average user.
We Got Phished
81–90 of 156 posts
Re: We Got Phished
#82It seems to me that browsers could be smarter about this kind of thing. Like, "Hey, you just put your Gmail credentials into a non-Gmail login form, did you really mean to do that?" Obviously in the HN-type crowd, you know to always carefully check the URL of links and form submissions. But I just don't know how realistic it is for that to be expected of an average user.
[0]:https://chrome.google.com/webstore/detail/password-alert/noo...
Re: We Got Phished
#83It seems to me that browsers could be smarter about this kind of thing. Like, "Hey, you just put your Gmail credentials into a non-Gmail login form, did you really mean to do that?" Obviously in the HN-type crowd, you know to always carefully check the URL of links and form submissions. But I just don't know how realistic it is for that to be expected of an average user.
Re: We Got Phished
#842FA is not enough here a user that does not have the required knowledge to see what is phishing and what is not will most likely enter the 2FA key giving the bad guys the auth tokens anyway.
Re: We Got Phished
#85At my company we get these things 2-3 times a year. Surprisingly many people understand that there is something fishy. But "Surprisingly many" is not enough. 2FA is not enough here a user that does not have the required knowledge to see what is phishing and what is not will most likely enter the 2FA key giving the bad guys the auth tokens anyway.
Re: We Got Phished
#86At my company we get these things 2-3 times a year. Surprisingly many people understand that there is something fishy. But "Surprisingly many" is not enough. 2FA is not enough here a user that does not have the required knowledge to see what is phishing and what is not will most likely enter the 2FA key giving the bad guys the auth tokens anyway.
That's why yubikey is important - it does it's own verification of the site. You can't MITM it.
Re: We Got Phished
#87Earlier quoted context omitted.
The phisher can just relay your token to establish a login from their end, and still have access to your account. In this article, the attacker created a filter to move all incoming messages to Trash (that doesn't require a token to do), then they deleted the contacts (I don't think that requires a token), and kept an active connection to the Inbox (also doesn't require a token).
This is true for the tokens which generate numbers you type in. I don't think it's the case for USB tokens, however.
Re: We Got Phished
#88Earlier quoted context omitted.
Then how does the image consistently display before the password has been provided? No matter what the answer is, I don't see how it could be an anti-phishing feature.
Google naturally has their own private APIs which will only show the profile image for legitimate logins.
Re: We Got Phished
#89It seems to me that browsers could be smarter about this kind of thing. Like, "Hey, you just put your Gmail credentials into a non-Gmail login form, did you really mean to do that?" Obviously in the HN-type crowd, you know to always carefully check the URL of links and form submissions. But I just don't know how realistic it is for that to be expected of an average user.
How often do you actually check super carefully? I'm pretty sure I'm not as careful as I know I should be. Especially when busy and distracted and thinking about other things.
Re: We Got Phished
#90It seems to me that browsers could be smarter about this kind of thing. Like, "Hey, you just put your Gmail credentials into a non-Gmail login form, did you really mean to do that?" Obviously in the HN-type crowd, you know to always carefully check the URL of links and form submissions. But I just don't know how realistic it is for that to be expected of an average user.
That would be tough, because most people use one or two email addresses for basically all their accounts. And unless you're storing all their passwords, which would be a sketchy thing to turn on by default, there's no way to tell if they just put in their Gmail credentials or they really meant to log into gmal.ru. And actually even if you're storing their passwords, a lot (most?) people use the same password for lots…