Earlier quoted context omitted.
It's counter intuitive. I bet you $5 that if I target you, and you're not expecting it, I can phish you. I've seen this happen in the field, and it doesn't have much to do with education. Relax for an instant and I have you. The only real defense is to glance at the url bar every time you're about to enter your password. And even I find myself not doing that 100% of the time. It's a numbers game. A policy of popping…
> The only real defense is to glance at the url bar every time you're about to enter your password. With i18n not even that: https://www.theguardian.com/technology/2017/apr/19/phishing-... Benign POC: https://www.xn--80ak6aa92e.com/ (open it and it'll look like a normal "l" in the url box)
Our Copyfish extension was stolen and adware-infested
141–150 of 217 posts
Re: Our Copyfish extension was stolen and adware-infested
#142Re: Our Copyfish extension was stolen and adware-infested
#143Earlier quoted context omitted.
While I normally agree, I think it's important that they referred to the specific person without using blaming language. The team failed and screwed up because they had bad policies with their account. The individual team member who was holding the keys when the screw-up happened? Unlucky. Fix the process, not the people. It's good that they're not throwing the poor person under the bus.
Stating what happened is not blaming language. Characterizing the act as "unlucky" is excusing language, just as bad as blaming language. Assigning an error to mystical forces is unhelpful. Simply stating that the person entered the password into a phishing site is not blaming language, it is factual.
Re: Our Copyfish extension was stolen and adware-infested
#144I guess this is as good a place as any to post that I noticed something similar had happened to [User-Agent Switcher for Google Chrome]( https://chrome.google.com/webstore/detail/user-agent-switche... ) and [Block Site]( https://chrome.google.com/webstore/detail/block-site/eiimnmi... ). The "report abuse" link on the page is useless. The former is very insidious in that it actually hides the malware in a .jpg file th…
Re: Our Copyfish extension was stolen and adware-infested
#145Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt?
All these are common occurrences in automatically sent e-mails these days.
Re: Our Copyfish extension was stolen and adware-infested
#146> Back to standard, text-based email as the default. Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt? All these are common occurrences in automatically sent e-mails these days.
Thunderbird does this by default.
Re: Our Copyfish extension was stolen and adware-infested
#147Earlier quoted context omitted.
Stating what happened is not blaming language. Characterizing the act as "unlucky" is excusing language, just as bad as blaming language. Assigning an error to mystical forces is unhelpful. Simply stating that the person entered the password into a phishing site is not blaming language, it is factual.
I would kindly ask that the person who has never made a mistake throw the first stone.
Re: Our Copyfish extension was stolen and adware-infested
#148Earlier quoted context omitted.
More or less why I run a fairly minimal set of extensions. I was looking for a bulk downlowned about a week ago, and the only ones I found requested "Read data from all websites", which is a lot of trust to put in something I have limited ability to test/know if it is malicious. Side note: Chrome appears to have moved Extensions out of Settings since I last looked, and the "search settings" bar doesn't bring it up ei…
> I was looking for a bulk downlowned about a week ago, and the only ones I found requested "Read data from all websites", which is a lot of trust to put in something I have limited ability to test/know if it is malicious. AIUI that's a consequence of the Chrome extension security model. How could a bulk-downloader extension download files from arbitrary web sites without "Read[ing] data from all websites"? Compare t…
What I was hoping for was something along the lines of " wants to access this page" (similar to the notification when a website tries to access your location) upon use. I've no idea if that's possible or not in the Chrome security model.
Re: Our Copyfish extension was stolen and adware-infested
#149We should never have to read a title "disable immediately" by a developer. In a news article. That is not how this should be distributed, in case the original developer is the one distributing the news. Instead, Google should generate an emergency disable code that a developer can put into a simple web form from anywhere in the world, even if the developer has been locked out of every one of their accounts, which imm…
* instant revocation -> attacker will just revoke the code * delayed revocation where the code remains usable for some period -> accidental exposure is irrecoverable
Maybe it's viable as an option (extension owner takes on the risk of properly managing the secret, knowing it can't be revoked easily).
Re: Our Copyfish extension was stolen and adware-infested
#150> Back to standard, text-based email as the default. Yeah, but what will you do when your receive an HTML-only mail, or a mail with text/plain alternative saying "lol, get a better MUA", or a mail with text/plain alternative so mangled it can't be read without making your brain hurt? All these are common occurrences in automatically sent e-mails these days.
View the HTML mail, but with fancy rendering, images, all remote content, etc. disabled. Thunderbird does this by default.
And that's exactly what phishers want you to do.