I'm not doubting the concerns raised but the fake failed in many ways for me on my phone with the latest chrome. It didn't appear. Then when it did it appeared below the existing bar. But I guess you just need it to work often enough.
The inception bar: a new phishing method
71–80 of 238 posts
Re: The inception bar: a new phishing method
#72"Make sure you’ve done a hard refresh of the page" An inception bar could include a fake refresh button, no?
This is why I think removing the physical (as in, below the screen --- whether they're capacitive or actual pushbuttons isn't the point here) buttons from Android devices is a horrible idea; a webpage can mess around with what's on the screen, but it can't stop the user pressing the physical menu button and choosing Refresh from there.
Re: The inception bar: a new phishing method
#73Re: The inception bar: a new phishing method
#74https://myki.com/blog/facebook-login-phishing-campaign/
It adds the browser elements to make it appear like a verified popup.
The only reason it was discovered was due to users complaining that the password manager did not auto-populate the form.
Re: The inception bar: a new phishing method
#75"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.
Re: The inception bar: a new phishing method
#76With a little polishing this would be quite the "exploit" - trap the user in your fake browser, actually load pages that are entered into the fake URL bar, replace content only on certain patterns... The only solution here is a proper line of death [0]. It defeats the purpose of the LoD when it dynamically shrinks from user action. [0]: https://textslashplain.com/2017/01/14/the-line-of-death/
Re: The inception bar: a new phishing method
#77"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.
It worked quite effectively on 3.x because you could just minimize progman.exe
Re: The inception bar: a new phishing method
#78Re: The inception bar: a new phishing method
#79Whenever I’m looking at an iPhone screenshot someone posted on social media on my iPhone, I try to navigate using the buttons in the image. There ought to be a long German word for that experience.
Re: The inception bar: a new phishing method
#80Earlier quoted context omitted.
I have an unquantified theory that the number of users that can distinguish between a Windows 7/8/10 dialog box that is presented directly by the operating system, versus as an image inside a browser coming from external http/https server, is diminishing greatly every year.
Except all the colorblind people who have altered their system defaults enough that anything internal to the browser will look very out of place.