Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

31–40 of 103 posts

Re: Google Phishing Quiz

#31
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

I got that answer wrong too. But I guess they were asking specifically about phishing.

I think the rationale is that the page has to be a real permissions page to give the attacker access to your data. A fake page won't have any power in that regard.

And on a real permissions page, an attacker won't be able to fake the requesting app's link.

So: legit page + legit link = no phishing ... even though it is by no means a safe situation.

Re: Google Phishing Quiz

#32
post #24
post #17

While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

...so?

It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

Re: Google Phishing Quiz

#33
Phishing, especially the targeted type, is impossible to combat at scale, and expecting users to know the ins and outs of what's a safe domain (withgoogle.com? Is it safe or not?) or to try to identify legitimate communications is a stupid waste of time.

Long term the solution is ubiquitous hardware-based 2FA, ideally incorporated into the physical devices themselves.

Re: Google Phishing Quiz

#34
post #26

I dislike several aspects of this quiz, and think it's actively harmful to users. It's great to train on the URLs, but that's not the only warning sign with these. --- 1) "Hey there. Here is the doc you asked for." Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs. --- 2) Fax Message from efacks.com Do you have an account with this service, where you explicitly sig…

My read was not "trust From" but more "be distrustful when from does not align". Perhaps users will take the former from this, but my understanding of this exercise was more spotting negatives than spotting positives.

Re: Google Phishing Quiz

#35
post #28

It says PDF is a potential attack vector. Have there been any attacks on Preview.app, since it became sandboxed?

I think its referring to adobe reader which allows PDFs to run arbitrary code as well as 100000 other anti-features.

Re: Google Phishing Quiz

#36
post #17

While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

Google has one billion different domain names that they officially use for user facing features. Why would they register blog.google and use it other than to show off that they have their own tld

Re: Google Phishing Quiz

#38
post #27
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

And that's the rub: knowing what's phishing depends on who you are. Receiving a PDF with financial data has a completely different probability of being an attack if you know who the sender is and were expecting them to send such a file today. Also, assuming that a message is phishing is usually not harmful in any way. If I got an email from dropbox.com (and were a Dropbox customer), I'd ignore the email, and just typ…

This is exactly what I do for any kind of account stuff: never click on the email, always just sign into the website itself and look for the message. I really like the companies that just say "sign in and see a new message" or whatever, rather than, "click on this link."

Re: Google Phishing Quiz

#39
post #33

Phishing, especially the targeted type, is impossible to combat at scale, and expecting users to know the ins and outs of what's a safe domain (withgoogle.com? Is it safe or not?) or to try to identify legitimate communications is a stupid waste of time. Long term the solution is ubiquitous hardware-based 2FA, ideally incorporated into the physical devices themselves.

True, but a solution doesn't have to be single sided.

I can easily send this link to my parents and then they know a little more.

Expecting users to know is ridiculous, but offering tools for people to help educate their less tech savvy loved ones is awesome. That's kinda how I see this. It helps me empower my parents a little more.

Post reply on HN