Google Phishing Quiz
91–100 of 103 posts
Re: Google Phishing Quiz
#92[0]: https://www.pcworld.com/article/2921383/software/4-gmail-lab...
Re: Google Phishing Quiz
#93Earlier quoted context omitted.
...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.
AFAIK they don't have any pages there that allow account login, for that and other security reasons.
Re: Google Phishing Quiz
#94Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
They should have proposed three answers for this one :- [_] phishing [_] legit [X] legit, but there's no chance I will accept that!
Re: Google Phishing Quiz
#95Re: Google Phishing Quiz
#96Earlier quoted context omitted.
I don't know if that would be enough in real life for me. I know some organisations use two different domains (e.g. they did a transition but they don't want to turn off .org just in case something still uses it, the IT team forgot that Sam has two Outlook profiles, one is on .org). And while pdfs can be attack vectors, they're not an especially strong one - it's not like running an exe with administrator privileges.…
They even had a legitimate example, of Dropbox sending an email from dropboxemail.com. I honestly think this should never be done because users shouldn't be expected to know which domains you do and don't own.
As to your second point, I agree in terms of 'best practices', but in terms of teaching about phishing, the fact is, companies do use multiple domains (and some deliverability guides actively encourage different domains for marketing emails and transactional emails - companies should use subdomains for this, but not all are that savvy).
Given that companies are sending from multiple domains, I think the litmus test for phishing is:
"Is the email trying to get me to give me information? E.g. a login on the wrong site, sending card details or anything like that"
Your pdf reader should allow you to open a pdf without being compromised (just as your browser should allow you to click a dodgy link without being compromised). So I think that item should pass the litmus test (unlike the email reading one).
Re: Google Phishing Quiz
#97I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…
Re: Google Phishing Quiz
#98I dislike several aspects of this quiz, and think it's actively harmful to users. It's great to train on the URLs, but that's not the only warning sign with these. --- 1) "Hey there. Here is the doc you asked for." Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs. --- 2) Fax Message from efacks.com Do you have an account with this service, where you explicitly sig…
> Did you ask for a doc? Do you know this person? If no, these facts alone should be giant warning signs.
Agreed. They also would be giant warning signs to the most non-tehcnical users. Quiz could definitely have included more context.
Re: Google Phishing Quiz
#99Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.
Re: Google Phishing Quiz
#100Earlier quoted context omitted.
Yeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.
Do you apply that constraint to browser extensions as well? "Access and modify all site data" definitely includes your email, and is required by a fair number of useful extensions including all adblockers that I know of.