Live data from Hacker News

The inception bar: a new phishing method

jameshfisher.com

71–80 of 238 posts

Re: The inception bar: a new phishing method

#71

I'm not doubting the concerns raised but the fake failed in many ways for me on my phone with the latest chrome. It didn't appear. Then when it did it appeared below the existing bar. But I guess you just need it to work often enough.

It's like the fake "Allow Notification" dialogs on some sites. They look off to pretty much anyone paying attention, but their target market probably isn't people paying attention

Re: The inception bar: a new phishing method

#72
post #37

"Make sure you’ve done a hard refresh of the page" An inception bar could include a fake refresh button, no?

This is why I think removing the physical (as in, below the screen --- whether they're capacitive or actual pushbuttons isn't the point here) buttons from Android devices is a horrible idea; a webpage can mess around with what's on the screen, but it can't stop the user pressing the physical menu button and choosing Refresh from there.

Soft buttons can't be covered by a normal web page either, though.

Re: The inception bar: a new phishing method

#74
There was a similar thing reported a few months ago relating to a fake Facebook social login popup.

https://myki.com/blog/facebook-login-phishing-campaign/

It adds the browser elements to make it appear like a verified popup.

The only reason it was discovered was due to users complaining that the password manager did not auto-populate the form.

https://news.ycombinator.com/item?id=19188386

Re: The inception bar: a new phishing method

#75

"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…

In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.

In office, adding screenshot visual studio startup splash screen to the wallpaper and watch the dev. Best moment is when they see visual studio being first thing to start after system reboot.

Re: The inception bar: a new phishing method

#76

With a little polishing this would be quite the "exploit" - trap the user in your fake browser, actually load pages that are entered into the fake URL bar, replace content only on certain patterns... The only solution here is a proper line of death [0]. It defeats the purpose of the LoD when it dynamically shrinks from user action. [0]: https://textslashplain.com/2017/01/14/the-line-of-death/

Thanks for pointing me to this post - an amazing reference. I'm going to include it in my post.

Re: The inception bar: a new phishing method

#77

"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…

In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.

ha I did a similar thing too. Except it was fake error messagebox and on Windows 3.1 (or might have even been 3.0?)

It worked quite effectively on 3.x because you could just minimize progman.exe

Re: The inception bar: a new phishing method

#80

Earlier quoted context omitted.

I have an unquantified theory that the number of users that can distinguish between a Windows 7/8/10 dialog box that is presented directly by the operating system, versus as an image inside a browser coming from external http/https server, is diminishing greatly every year.

Except all the colorblind people who have altered their system defaults enough that anything internal to the browser will look very out of place.

Or Linux users.
Post reply on HN