We Got Phished
11–20 of 156 posts
Re: We Got Phished
#12Many people won't check the url when signing in if everything looks to be on the up and up. This is why I really liked one of the things Yahoo did which was create a sign-in seal. Every time you signed in Yahoo would display a custom image that you set and if that image wasn't there then something was probably wrong.
Re: We Got Phished
#13Re: We Got Phished
#14Many people won't check the url when signing in if everything looks to be on the up and up. This is why I really liked one of the things Yahoo did which was create a sign-in seal. Every time you signed in Yahoo would display a custom image that you set and if that image wasn't there then something was probably wrong.
Here's some more info on that: http://security.stackexchange.com/questions/19155/effectiven...
Re: We Got Phished
#15Re: We Got Phished
#162-factor would have prevented this - no ?
Re: We Got Phished
#17It's worth nothing the new user-image-before-password-input for Google is an anti-phishing feature. Of course, most people won't think that deeply when prompted with a password request and a similar UI.
Re: We Got Phished
#182-factor would have prevented this - no ?
Re: We Got Phished
#19Did PZ trust a mailing list where anyone could post? Or did the attackers spoof the "from" field? The former may have been prevented by employee training, the latter by SPF or similar technologies.