Live data from Hacker News

Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

wordfence.com

21–30 of 49 posts

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#21
post #3

Are any advanced users on HN that would've overlooked the obvious signs in the address bar? I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different. IMHO only inexperienced users will fall for this. If you regularly look at the address…

Pssh, I'll say it - I'd fall for this, more than 0% of the time. Am I an advanced user? I can try to give you an example of some client side TLS thing I have implemented and we can haggle over where the bar is for "advanced", but give me a Saturday night beer-riddled netflix binge and a midnight email check, I'm clicking this link. I'd hope my 2FA would freak out, around that point, and save me from myself. I guess i…

You'd probably notice because that page would not ask about the 2FA.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#22

Earlier quoted context omitted.

Anybody else seeing a certificate error on ftc.gov?

are you under chrome? https://knowledge.geotrust.com/support/knowledge-base/index?...

I'm running Chromium 54 on Arch Linux, which I am assuming is not affected, since that page only names version 53. Interestingly, there is no certificate problem on a Windows machine on the same network.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#23

This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea. Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things th…

You've completely misread the point: it appears -- to the user -- to be a regular gmail attachment. In the attack described, they're intending to click on an attachment, not a link.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#24

Earlier quoted context omitted.

are you under chrome? https://knowledge.geotrust.com/support/knowledge-base/index?...

I'm running Chromium 54 on Arch Linux, which I am assuming is not affected, since that page only names version 53. Interestingly, there is no certificate problem on a Windows machine on the same network.

I think that the bug is related, the error is NET::ERR_CERTIFICATE_TRANSPARENCY_REQUIRED .

A quick search displays many info on the bug, you need to upgrade chromium.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#29
Another issue is that browsers do not display the non-secure http:// prefix in the url bar (which should probably be red and striked through).

As a PoC, I bought the domain https.is, and now I can construct urls like https.is//accounts.google.com - which can look convincing when glimpsed over.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#30

This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea. Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things th…

So, there would never be a way to email someone a link to a site? Ever? Links are the whole point of having a Web!
Post reply on HN