Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

91–100 of 103 posts

Re: Google Phishing Quiz

#93
post #83
post #32

Earlier quoted context omitted.

...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

AFAIK they don't have any pages there that allow account login, for that and other security reasons.

https://www.google.com/search?q=site%3Awithgoogle.com+login

Re: Google Phishing Quiz

#94
post #87
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

They should have proposed three answers for this one :- [_] phishing [_] legit [X] legit, but there's no chance I will accept that!

[X] Legit phishing

Re: Google Phishing Quiz

#96
post #57
post #52

Earlier quoted context omitted.

I don't know if that would be enough in real life for me. I know some organisations use two different domains (e.g. they did a transition but they don't want to turn off .org just in case something still uses it, the IT team forgot that Sam has two Outlook profiles, one is on .org). And while pdfs can be attack vectors, they're not an especially strong one - it's not like running an exe with administrator privileges.…

They even had a legitimate example, of Dropbox sending an email from dropboxemail.com. I honestly think this should never be done because users shouldn't be expected to know which domains you do and don't own.

Your first point is definitely correct - their guide is confused at best.

As to your second point, I agree in terms of 'best practices', but in terms of teaching about phishing, the fact is, companies do use multiple domains (and some deliverability guides actively encourage different domains for marketing emails and transactional emails - companies should use subdomains for this, but not all are that savvy).

Given that companies are sending from multiple domains, I think the litmus test for phishing is:

"Is the email trying to get me to give me information? E.g. a login on the wrong site, sending card details or anything like that"

Your pdf reader should allow you to open a pdf without being compromised (just as your browser should allow you to click a dodgy link without being compromised). So I think that item should pass the litmus test (unlike the email reading one).

Re: Google Phishing Quiz

#97
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

Can somebody explain to me how a PDF opened in, say your OS's default PDF viewer, could be harmful? Aside from you acting on some misinformation within it.

Re: Google Phishing Quiz

#98
post #26

I dislike several aspects of this quiz, and think it's actively harmful to users. It's great to train on the URLs, but that's not the only warning sign with these. --- 1) "Hey there. Here is the doc you asked for." Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs. --- 2) Fax Message from efacks.com Do you have an account with this service, where you explicitly sig…

> 1) "Hey there. Here is the doc you asked for."

> Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs.

Agreed. They also would be giant warning signs to the most non-tehcnical users. Quiz could definitely have included more context.

Re: Google Phishing Quiz

#99
post #25
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.

Do you apply that constraint to browser extensions as well? "Access and modify all site data" definitely includes your email, and is required by a fair number of useful extensions including all adblockers that I know of.

Re: Google Phishing Quiz

#100
post #25

Earlier quoted context omitted.

Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.

Do you apply that constraint to browser extensions as well? "Access and modify all site data" definitely includes your email, and is required by a fair number of useful extensions including all adblockers that I know of.

Only if you read your email in the browser.
Post reply on HN