Half of All Phishing Sites Now Have the Padlock
krebsonsecurity.com
Half of All Phishing Sites Now Have the Padlock
1–10 of 79 posts
Re: Half of All Phishing Sites Now Have the Padlock
#2Sites who use lots of nonsensical malware-ish url redirects (Google, Microsoft are guilty) train people to accept random urls.
I guess the chief culprits are email tracking links. Everyone including banks use them. Often tracking domains have nothing in common with the destination URL. This teaches people to disable or ignore email provider warnings and click any link in official sounding emails.
Re: Half of All Phishing Sites Now Have the Padlock
#3Re: Half of All Phishing Sites Now Have the Padlock
#4But well worth skimming through for the excellent Firefox about.config tweak "network.IDN_show_punycode".
Re: Half of All Phishing Sites Now Have the Padlock
#5The many mobile browsers which hide the address bar are training people to ignore website urls. Sites who use lots of nonsensical malware-ish url redirects (Google, Microsoft are guilty) train people to accept random urls. I guess the chief culprits are email tracking links. Everyone including banks use them. Often tracking domains have nothing in common with the destination URL. This teaches people to disable or ign…
Re: Half of All Phishing Sites Now Have the Padlock
#6The many mobile browsers which hide the address bar are training people to ignore website urls. Sites who use lots of nonsensical malware-ish url redirects (Google, Microsoft are guilty) train people to accept random urls. I guess the chief culprits are email tracking links. Everyone including banks use them. Often tracking domains have nothing in common with the destination URL. This teaches people to disable or ign…
The tradeoff has been CNAME-ing your own subdomain to your Email Service Provider’s tracking domain, which gets you a recognizable(-ish) URL, but has historically prevented https links, or using the ESP’s tracking domain directly, which allows https but makes sketchy-looking URLs.
I’d think Let’s Encrypt would make it possible to offer https on white-labeled (CNAME’d) tracking domains. Seems like an opportunity for some enterprising ESP.
(Yes, two other options are not tracking email links, or running your own tracking. I’m going to assume these are not realistic for most marketing departments.)
Re: Half of All Phishing Sites Now Have the Padlock
#7The many mobile browsers which hide the address bar are training people to ignore website urls. Sites who use lots of nonsensical malware-ish url redirects (Google, Microsoft are guilty) train people to accept random urls. I guess the chief culprits are email tracking links. Everyone including banks use them. Often tracking domains have nothing in common with the destination URL. This teaches people to disable or ign…
This is my biggest complaint about forcing users to use apps to browse a website-- it hides everything. I have no idea if any given app is actually using SSL. Oversights have happened before to Credit Karma, Fandango and others.
Re: Half of All Phishing Sites Now Have the Padlock
#8Re: Half of All Phishing Sites Now Have the Padlock
#9On the bright side, at least your data won't get stolen by a fourth party while it's being stolen by a third party.