Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

41–50 of 103 posts

Re: Google Phishing Quiz

#41
Funny considering Google still has a UX vulnerability in their gmail interface: https://eligrey.com/blog/google-inbox-spoofing-vulnerability...

"The link mailto:​”support@paypal.com”​ shows up as “support@paypal.com” in the Google Inbox composition window, visually identical to any email actually sent to PayPal."

It has been fixed in the web version, but apparently the Android app still has this issue

Re: Google Phishing Quiz

#42

Hi All, I posted this here because I think it's great there's some effort being put into free training in this region. I do however agree with some of the comments here. I had been hunting for something like this to use as our own training, but it won't be this because I don't agree with the TripIt example. Edit: Maybe there should be a "maybe" or "consider" answer. "This is a legitimate company. However, their desir…

100% this. I think sometimes people miss the target demographic for something like this. My 70s+ year old dad and mom got phished. This might help them understand why they shouldn't have clicked the link.

A technical solution to security should be sought out as well. This doesn't remove ANY responsibility from companies for having good security.

It does help to empower the less technical users.

Re: Google Phishing Quiz

#43
post #39
post #33

Phishing, especially the targeted type, is impossible to combat at scale, and expecting users to know the ins and outs of what's a safe domain (withgoogle.com? Is it safe or not?) or to try to identify legitimate communications is a stupid waste of time. Long term the solution is ubiquitous hardware-based 2FA, ideally incorporated into the physical devices themselves.

True, but a solution doesn't have to be single sided. I can easily send this link to my parents and then they know a little more. Expecting users to know is ridiculous, but offering tools for people to help educate their less tech savvy loved ones is awesome. That's kinda how I see this. It helps me empower my parents a little more.

I agree that it doesn't have to be single-sided, and we need multiple angles to protect against phishing.

This quiz isn't it, though. You and I know what domains are; we know what's possible; we can sense when somethings off. It's our bread and butter. The average user knows none of these things, and giving them a dozen rules to follow that will work a lot of the time is in the end confusing.

A better set of rules to link your parents to is this:

1) Trust nothing over email. If your bank sends you a notification, don't click on the link in your email: just go directly to your bank's website and log in.

2) That's about it.

Re: Google Phishing Quiz

#44
I missed only the .org instead of .edu (was thinking the establishment have the two domain name)

As for the TripIt we may don’t have the same definition of fishing

As the mail was a ligitime mail from google to request access to my account from an app (and that’s what’s about the quizz) as for if did I used that app or now that’s another story

Re: Google Phishing Quiz

#45
post #32
post #24

Earlier quoted context omitted.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

Just for example, the following domains are all available:

workingoogle.com labsgoogle.com labsatgoogle.com learngoogle.org learnatgoogle.com youatgoogle.com bygoogle.co securitywithgoogle.com mailatgoogle.com realgoogle.com

etc.

Re: Google Phishing Quiz

#47
post #25
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.

Not that I disagree with you but, do you...

- host your own email...

- on your own hardware...

- with your own software (hopefully doing end to end encryption)

Even then your surely not running your own fiber, though things like STARTTLS help mitigate this vector.

I only mean to say, some level of trust is assumed. But yea, you should aim towards less buggy, evil corporate dependencies.

Re: Google Phishing Quiz

#48
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

I wish the quiz had a fake url bar, that one I got right just out of a pure guess. Without the url bar and just assuming the html is legit, theres no way of really knowing.

Re: Google Phishing Quiz

#49
post #43
post #39

Earlier quoted context omitted.

True, but a solution doesn't have to be single sided. I can easily send this link to my parents and then they know a little more. Expecting users to know is ridiculous, but offering tools for people to help educate their less tech savvy loved ones is awesome. That's kinda how I see this. It helps me empower my parents a little more.

I agree that it doesn't have to be single-sided, and we need multiple angles to protect against phishing. This quiz isn't it, though. You and I know what domains are; we know what's possible; we can sense when somethings off. It's our bread and butter. The average user knows none of these things, and giving them a dozen rules to follow that will work a lot of the time is in the end confusing. A better set of rules to…

I’m not even convinced “don’t click links” is the best guidance. That message has been pushed so hard that people immediately think their machine has been compromised once they have clicked a shady link. That is nearly never the case. Clicking links isn’t something that should cause fear. Nobody is burning a modern browser vuln in a spam email. I think the message should be more focused on not manually entering credentials into a site. Lean on your browser to validate domains and know which sites are associated with which credential. I say that somewhat aspirationaly , as I still think there is lots of room for how well browsers and password managers work for novice users.
Post reply on HN