Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

21–30 of 103 posts

Re: Google Phishing Quiz

#21
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

The PDF one seemed like a pitch for using Chrome as your PDF viewer.

Re: Google Phishing Quiz

#22
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, baffled me for a bit but then I remembered that question is whether is phishing attack or not; not if you gonna click "Allow". Then again there is no URL address bar to look for so it _might_ be some sort of phishing attack.

Re: Google Phishing Quiz

#23
post #7
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

The inclusion of that one kinda baffled me. No way for me to tell whether the app that's connecting would be one I'd want reading emails (I wasn't familiar with it) and without an address bar, hard to tell if it's a spoof or the real thing.

Yeah, I mean it doesn't say the context very well, so I assumed it I clicked on a link. Like if it said you signed up for a service and clicked on a link to do something very specific.

If I accidentally clicked on a link in my email and it brought that page up, could you call it phishing?

Also the email from the person with the PDF. Like, why is that phishing? What if I trusted the sender? People send pdfs all the time. are there no secure ways to read pdfs?

Re: Google Phishing Quiz

#24
post #17

While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

Re: Google Phishing Quiz

#25
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.

Re: Google Phishing Quiz

#26
I dislike several aspects of this quiz, and think it's actively harmful to users. It's great to train on the URLs, but that's not the only warning sign with these.

---

1) "Hey there. Here is the doc you asked for."

Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs.

---

2) Fax Message from efacks.com

Do you have an account with this service, where you explicitly signed up to receive faxes? If not, obviously you shouldn't be getting faxes from them so it's not legitimate.

---

5) "Please find attached the 2019 financial activity report for your perusal."

Aside from giving away the answer in the title [1], this isn't a good example.

First line of defense, once again: Do you have an account with "Westmount Day School", and are you expecting a "financial activity report"?

Also, spoofing "from" e-mail addresses is a thing, and completely trivial, so relying on that is not a way to verify authenticity.

What's not mentioned is being aware of what PDF reader you're using: eg, do you regularly make sure it's up to date? Personally, I use Chrome as my PDF reader as I'm not a fan of Adobe products or their security track record in general.

Also in my experience, these types of e-mails often come in with an attachment like "2019 F.A.R.pdf.exe" (or a zip file that contains an exe), and not an actual PDF file. This would have been a great way to train users on this point.

---

6) "Someone has your password"

The two reasons that this isn't legitimate are listed as "We don't use google.support to send emails" and "This link points to a subdomain of ml-security.org, not Google." [2]

So once again, spoofing "from" addresses is trivial -- so that is not a security measure. Secondly, how should I know what mail comes from? There was an earlier example of a legitimate message from Dropbox coming from a non-dropbox.com address (dropboxmail.com).

Also, the best defense against this is not mentioned: Never log into sites by clicking on links in e-mails! This includes changing your password. The only exception to this is a password reset mail when you explicitly just asked for a password reset.

---

7) "Government-backed attackers may be trying to steal your password"

Once again, "Change password" link in e-mail. Don't click it.

---

8) Tripit Security prompt [3]

Sorry, but this is a terrible example.

First of all, am I trying to perform some action with Tripit that this prompt is expected? If no, don't allow (in fact, just close the window)

Secondly, what does my browser window show? If you're on google.com (or gmail.com) and this appears, that's one thing, but if your browser is showing google.security-check.se then no, don't click anything and just close the window.

Third, even assuming this is all okay, do you want Tripit to have access to view email messages and settings? If all you were trying to do is use your Google account to authenticate, the fact it wants access to view all your messages is highly suspicious. In this particular case (because it's Tripit, a service that parses your email), this is probably your intention, but if it also asked for other permissions -- such as ability to manage contacts and send messages on your behalf -- you might want to think twice.

---

Training like this is good, but phishing e-mails can be very devious and training users on the wrong things -- such as trusting "from" addresses, not considering context, and not looking at actual attachment types -- is extremely dangerous. In the worst case, it can train users to click on things they otherwise wouldn't have, due to false confidence obtained by (inadequate) training.

[1] https://i.imgur.com/8mNePZS.png

[2] https://i.imgur.com/tpJMb5n.png

[3] https://i.imgur.com/KfNDuZI.png

Re: Google Phishing Quiz

#27
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

And that's the rub: knowing what's phishing depends on who you are. Receiving a PDF with financial data has a completely different probability of being an attack if you know who the sender is and were expecting them to send such a file today.

Also, assuming that a message is phishing is usually not harmful in any way. If I got an email from dropbox.com (and were a Dropbox customer), I'd ignore the email, and just type "dropbox.com" in my web browser to see what's up. If you're paranoid, you don't need to be super smart about what exactly is phishing.

This isn't a fair test.

Re: Google Phishing Quiz

#30
Hi All,

I posted this here because I think it's great there's some effort being put into free training in this region.

I do however agree with some of the comments here. I had been hunting for something like this to use as our own training, but it won't be this because I don't agree with the TripIt example.

Edit: Maybe there should be a "maybe" or "consider" answer. "This is a legitimate company. However, their desire to access your email is something you should carefully consider".

Post reply on HN