Earlier quoted context omitted.
Older school even -- instead of logging out of (real hardware) terminal sessions, exec a program which prints `login: ` and disables keyboard interrupts. Read peoples creds and store somewhere, then issue a 'wrong password' msg and exit, resulting in the real login message. People will just assume they made a typo and continue as if nothing happened. I've argued before for a genuine out-of-band independent display on…
We did just that with our Novell Network school computers. Show a fake login prompt. Write down what gets entered, show wrong password and exit to real prompt.
The inception bar: a new phishing method
191–200 of 238 posts
Re: The inception bar: a new phishing method
#192Earlier quoted context omitted.
The company where I first worked out of university had a custom which the CEO named ‘shemaling’. The company had quite strict security standards. It was encouraged that anyone who found an unlocked screen in the office would ‘shemale’ the wallpaper. It did the job. I never forgot again after being ’shemaled’ the first time.
I gay porned an entire company's computers after they refused to crack down on employees watching people being murdered all day. They threatened to fire me so I explained exactly why I had done this and that I would happily explain this at length in any subsequent employment tribunal. I kept my job and the management finally told everyone to stop watching people getting killed on company time.
Re: The inception bar: a new phishing method
#193Earlier quoted context omitted.
By "hard refresh" I took that to mean using the keyboard to forcibly reload the page and all assets, e.g. CTRL-F5 on Windows. Of course, the average user probably doesn't use keyboard commands, or even know this one exists.
Your phone has a keyboard?
Re: The inception bar: a new phishing method
#194Earlier quoted context omitted.
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.
Older school even -- instead of logging out of (real hardware) terminal sessions, exec a program which prints `login: ` and disables keyboard interrupts. Read peoples creds and store somewhere, then issue a 'wrong password' msg and exit, resulting in the real login message. People will just assume they made a typo and continue as if nothing happened. I've argued before for a genuine out-of-band independent display on…
Re: The inception bar: a new phishing method
#195Re: The inception bar: a new phishing method
#196Earlier quoted context omitted.
I gay porned an entire company's computers after they refused to crack down on employees watching people being murdered all day. They threatened to fire me so I explained exactly why I had done this and that I would happily explain this at length in any subsequent employment tribunal. I kept my job and the management finally told everyone to stop watching people getting killed on company time.
WTF.... Who the hell would watch murder clips at work and how would management be okay with this, let alone on company time?? Unbelievable....
Re: The inception bar: a new phishing method
#197Re: The inception bar: a new phishing method
#198Earlier quoted context omitted.
Machine learning-style image recognition tends to work extremely poorly with adversarial inputs.
While this is true, it's usually referring to algorithmically chosen adversarial inputs. On the other hand, it's a lot harder to trick both the browser's image recognition and the human operator's visual senses with the same UI.
Re: The inception bar: a new phishing method
#199Earlier quoted context omitted.
HTTPS everywhere is a good thing. HTTPS was never about protecting against phishing, and has never protected you against phishing. There is no way to educate people about phishing, only way to protect against it is U2F. Education against phishing is not very effective, and only works short term.
Right, but it was pushed as "lock icon means secure" and end users don't distinguish threat models.
HTTPS is a part of a whole and pushing so hard make people (even tech savvy ones) focus too much on it. How many CTOs are happy with just putting HTTPS on their website so they can check the security checkbox ?
Re: The inception bar: a new phishing method
#200Earlier quoted context omitted.
Similarly, the iPhone X requires double-pressing the power button to complete a purchase using Face ID. Previously, with Touch ID, the authentication action itself was also sufficient to establish intent (placing the finger on the sensor). But with Face ID, any app could just pop up the purchase window and Face ID would see your face. Incidentally, this is why Face ID is strictly worse than Touch ID in my opinion.
how is it worse? touch id’s serving as authentication and approval for payment was actually exploited as a scam. I don’t see how this could be done with face id. https://www.wired.com/story/iphone-touch-id-scam-apps/