Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

11–20 of 103 posts

Re: Google Phishing Quiz

#11
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.

Re: Google Phishing Quiz

#13
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.

Ah thanks, I must have missed that. If it's the wrong address then definitely suspect.

Re: Google Phishing Quiz

#16
A bit annoying that the fact that Dropbox used HTTPS-links are highlighted as a sign of it being legit. I have always suspected such advices makes people think HTTPS are actually somehow magically secure, while it has nothing to do with phishing related issues.

Re: Google Phishing Quiz

#17
While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

Re: Google Phishing Quiz

#19
post #8
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, anyone asking for that, even if it's not a phishing attempt would never get the OK from me. That's just crazy.

I suppose it might make sense if you were installing a 3rd party gmail application on your desktop.

I'm no oauth expert, but I would imagine an app would go through a flow like this.

Re: Google Phishing Quiz

#20
post #19
post #8

Earlier quoted context omitted.

Yeah, anyone asking for that, even if it's not a phishing attempt would never get the OK from me. That's just crazy.

I suppose it might make sense if you were installing a 3rd party gmail application on your desktop. I'm no oauth expert, but I would imagine an app would go through a flow like this.

I believe you can connect gmail to your local email client using IMAP/POP3, but I don't think that uses the oauth flow to do that (you just type in the password). I've never used any other kind of 3rd party gmail apps though.
Post reply on HN