Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

51–60 of 103 posts

Re: Google Phishing Quiz

#51
post #25
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.

I've used TripIt. Reading your email is central to their "magic." The idea is that whenever you get any sort of travel confirmation, they automatically ingest it and compile all the info into trips, then handle stuff like reminding you to checkin, auto-filling up your checkin code, suggesting seats, etc.

They also have an alternative for the privacy-minded where you just forward any confirmation emails you want them to know about and the same stuff happens, but for the email address I was using for this, there wasn't anything I was worried about them accessing, and this was easier.

Re: Google Phishing Quiz

#52
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.

I don't know if that would be enough in real life for me. I know some organisations use two different domains (e.g. they did a transition but they don't want to turn off .org just in case something still uses it, the IT team forgot that Sam has two Outlook profiles, one is on .org).

And while pdfs can be attack vectors, they're not an especially strong one - it's not like running an exe with administrator privileges.

Comparatively giving a third party access to your emails should definitely raise flags.

Re: Google Phishing Quiz

#54
post #24
post #17

While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

I assumed that I passed the test by not filling out the form

Re: Google Phishing Quiz

#55
post #24
post #17

While the domain is a legit Google domain, I find it ironic that it’s hosted on “withgoogle.com”. If my parents followed my anti-phishing tips they would fail by clicking this link.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

Ask Equifax why this is such a terrible idea:

https://www.nytimes.com/2017/09/20/business/equifax-fake-web...

Re: Google Phishing Quiz

#56
post #54
post #24

Earlier quoted context omitted.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

I assumed that I passed the test by not filling out the form

You're supposed to use whatever information you wanted the example phishing e-mails do be directed to. I used "Bob" and "bob@example.com".

Re: Google Phishing Quiz

#57
post #52

Earlier quoted context omitted.

On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.

I don't know if that would be enough in real life for me. I know some organisations use two different domains (e.g. they did a transition but they don't want to turn off .org just in case something still uses it, the IT team forgot that Sam has two Outlook profiles, one is on .org). And while pdfs can be attack vectors, they're not an especially strong one - it's not like running an exe with administrator privileges.…

They even had a legitimate example, of Dropbox sending an email from dropboxemail.com.

I honestly think this should never be done because users shouldn't be expected to know which domains you do and don't own.

Re: Google Phishing Quiz

#58
post #43

Earlier quoted context omitted.

I agree that it doesn't have to be single-sided, and we need multiple angles to protect against phishing. This quiz isn't it, though. You and I know what domains are; we know what's possible; we can sense when somethings off. It's our bread and butter. The average user knows none of these things, and giving them a dozen rules to follow that will work a lot of the time is in the end confusing. A better set of rules to…

I’m not even convinced “don’t click links” is the best guidance. That message has been pushed so hard that people immediately think their machine has been compromised once they have clicked a shady link. That is nearly never the case. Clicking links isn’t something that should cause fear. Nobody is burning a modern browser vuln in a spam email. I think the message should be more focused on not manually entering crede…

Agreed that clicking links is usually safe.

My point is, as a broad-based message, as soon as you start saying complicated words like "browser" and "validate domains" and "credential" and "password managers," nontechnical eyes immediately glaze over. I think your advice works for the most technically inclined 25% of users. It just confuses the rest.

"Don't click links," despite having more false positives when used as an individual's safety heuristic, resonates more and thus will result in many fewer false negatives when applied to the general public. The cost of a false positive is relatively low, while the cost of a false negative is high.

Re: Google Phishing Quiz

#59
post #56
post #54

Earlier quoted context omitted.

I assumed that I passed the test by not filling out the form

You're supposed to use whatever information you wanted the example phishing e-mails do be directed to. I used "Bob" and "bob@example.com".

I guarantee at least 25% of users used their real name and email.

Re: Google Phishing Quiz

#60
post #16

A bit annoying that the fact that Dropbox used HTTPS-links are highlighted as a sign of it being legit. I have always suspected such advices makes people think HTTPS are actually somehow magically secure, while it has nothing to do with phishing related issues.

I guess that depends on whether or not MITM is an attack vector that you're concerned about
Post reply on HN