Google Phishing Quiz
81–90 of 103 posts
Re: Google Phishing Quiz
#82Hovering over the “allow” button doesn’t show anything. They need to reword that one.
Re: Google Phishing Quiz
#83Earlier quoted context omitted.
withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.
...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.
Re: Google Phishing Quiz
#84Earlier quoted context omitted.
The inclusion of that one kinda baffled me. No way for me to tell whether the app that's connecting would be one I'd want reading emails (I wasn't familiar with it) and without an address bar, hard to tell if it's a spoof or the real thing.
Yeah, I mean it doesn't say the context very well, so I assumed it I clicked on a link. Like if it said you signed up for a service and clicked on a link to do something very specific. If I accidentally clicked on a link in my email and it brought that page up, could you call it phishing? Also the email from the person with the PDF. Like, why is that phishing? What if I trusted the sender? People send pdfs all the ti…
The TLD of the context was .EDU and the one from the email was a .ORG.
Re: Google Phishing Quiz
#85Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
I got that answer wrong too. But I guess they were asking specifically about phishing. I think the rationale is that the page has to be a real permissions page to give the attacker access to your data. A fake page won't have any power in that regard. And on a real permissions page, an attacker won't be able to fake the requesting app's link. So: legit page + legit link = no phishing ... even though it is by no means…
Re: Google Phishing Quiz
#86Earlier quoted context omitted.
It's because google.com contains very valuable cookies which could be leaked if there was an XSS or something anywhere on the google.com domain. Thats why things like this (which are often developed by third party contractors, and might not go through the same level of review), are hosted on another domain. It's a flaw in the web though. A domain should have the ability to host content without that content gaining fu…
If they mark the cookies as http only then that wouldn't be a concern though, for xss attacks anyway. Subdomains would also solve that issue. https://www.owasp.org/index.php/HttpOnly Personally I think they separate them out for branding. Things that are on google.com are flagship products, and getting your thing under google.com means you and/or you're project has a lot of clot at Google.
Re: Google Phishing Quiz
#87Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
[_] phishing
[_] legit
[X] legit, but there's no chance I will accept that!
Re: Google Phishing Quiz
#88I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…
On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.
Re: Google Phishing Quiz
#89Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
Re: Google Phishing Quiz
#90Earlier quoted context omitted.
...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.
AFAIK they don't have any pages there that allow account login, for that and other security reasons.
> Create a name and email — neither need to be real — to make this quiz seem more realistic. Don’t worry, this information won’t leave your device.
I'd trust this notice if I knew it came from Google, but since it was placed on a phishy-looking website, it really gave me pause.