Using the HTML5 Fullscreen API for Phishing Attacks
1–10 of 133 posts
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#2Re: Using the HTML5 Fullscreen API for Phishing Attacks
#3Re: Using the HTML5 Fullscreen API for Phishing Attacks
#4This is not a rhetorical question; do you think people would ignore the warning and continue to use the site?
An easier phishing technique would be to manipulate the address to appear legitimate using pushState.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#5Re: Using the HTML5 Fullscreen API for Phishing Attacks
#6Brilliant, terrifying, wonderfully crafted and well-communicated work. Where do we go from here?
I certainly wouldn't be tricked by this, but someone less technically savvy could be.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#7It doesn't go full screen at all, it just stays in the window normally.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#8Brilliant, terrifying, wonderfully crafted and well-communicated work. Where do we go from here?
Chrome 23 just makes it full screen with a small notice.
Re: Using the HTML5 Fullscreen API for Phishing Attacks
#9Re: Using the HTML5 Fullscreen API for Phishing Attacks
#10Full-screen mode can be useful, but it and other HTML5 features can be used for phishing or to generally annoy users. I'm wondering how soon it will be before someone makes the HTML5-equivalent of ClickToFlash.