I think most "technical" users would have two-factor authentication enabled which would prevent this type of attack.
No - because the phishing page can act as a MITM attack - where they display the 2-factor login on the phishing page - and post the entered code to Google, confirm they are in (and receive the cookie enabling access) - while displaying the page back to you. So 2-factor actually provides a false sense of security here. Edit: unless you have U2F as per @makomk comment below
Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
11–20 of 49 posts
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#12Earlier quoted context omitted.
No - because the phishing page can act as a MITM attack - where they display the 2-factor login on the phishing page - and post the entered code to Google, confirm they are in (and receive the cookie enabling access) - while displaying the page back to you. So 2-factor actually provides a false sense of security here. Edit: unless you have U2F as per @makomk comment below
Unless the second factor is U2F, because the actual domain is handed to the U2F dongle by the browser and the authentication is tied to that.
But for the Google Authenticator and SMS - it would still be vulnerable.
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#13Are any advanced users on HN that would've overlooked the obvious signs in the address bar? I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different. IMHO only inexperienced users will fall for this. If you regularly look at the address…
While you probably wont fall for this 99.9% of the time - the 0.1% that someone "technical" does means the attacker will gain access.
All it takes is a moment of distraction, or you are tired, or in a rush etc...
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#14Are there legitimate use cases for 'data:...' URIs as clickable links? I understand these URIs can be useful for embedding resources directly into the HTML, e.g. images and icons. But as clickable links, I have only ever encountered them as a means to circumvent popup-blockers. Would it be reasonable for web browsers to offer an option for ignoring clicks on such links?
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#15Are any advanced users on HN that would've overlooked the obvious signs in the address bar? I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different. IMHO only inexperienced users will fall for this. If you regularly look at the address…
I'd hope my 2FA would freak out, around that point, and save me from myself. I guess it would depend on the type of 2FA.
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#16Stop saying that!
https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#17Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things that look like URLs.
Sorry if this sounds like victim blaming, but at some point, after enough time, you have to eventually go from "victim" to "culpable".
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#18This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea. Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things th…
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#19"Changing your password every few months is good practice in general." Stop saying that! https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
#20"Changing your password every few months is good practice in general." Stop saying that! https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
Anybody else seeing a certificate error on ftc.gov?