Live data from Hacker News

Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

wordfence.com

11–20 of 49 posts

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#11
post #6

I think most "technical" users would have two-factor authentication enabled which would prevent this type of attack.

No - because the phishing page can act as a MITM attack - where they display the 2-factor login on the phishing page - and post the entered code to Google, confirm they are in (and receive the cookie enabling access) - while displaying the page back to you. So 2-factor actually provides a false sense of security here. Edit: unless you have U2F as per @makomk comment below

Unless the second factor is U2F, because the actual domain is handed to the U2F dongle by the browser and the authentication is tied to that.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#12
post #11

Earlier quoted context omitted.

No - because the phishing page can act as a MITM attack - where they display the 2-factor login on the phishing page - and post the entered code to Google, confirm they are in (and receive the cookie enabling access) - while displaying the page back to you. So 2-factor actually provides a false sense of security here. Edit: unless you have U2F as per @makomk comment below

Unless the second factor is U2F, because the actual domain is handed to the U2F dongle by the browser and the authentication is tied to that.

Thanks - good point :)

But for the Google Authenticator and SMS - it would still be vulnerable.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#13
post #3

Are any advanced users on HN that would've overlooked the obvious signs in the address bar? I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different. IMHO only inexperienced users will fall for this. If you regularly look at the address…

But for the attackers it is an odds game.

While you probably wont fall for this 99.9% of the time - the 0.1% that someone "technical" does means the attacker will gain access.

All it takes is a moment of distraction, or you are tired, or in a rush etc...

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#14

Are there legitimate use cases for 'data:...' URIs as clickable links? I understand these URIs can be useful for embedding resources directly into the HTML, e.g. images and icons. But as clickable links, I have only ever encountered them as a means to circumvent popup-blockers. Would it be reasonable for web browsers to offer an option for ignoring clicks on such links?

I used them for client-side generated file-downloads in the past.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#15
post #3

Are any advanced users on HN that would've overlooked the obvious signs in the address bar? I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different. IMHO only inexperienced users will fall for this. If you regularly look at the address…

Pssh, I'll say it - I'd fall for this, more than 0% of the time. Am I an advanced user? I can try to give you an example of some client side TLS thing I have implemented and we can haggle over where the bar is for "advanced", but give me a Saturday night beer-riddled netflix binge and a midnight email check, I'm clicking this link.

I'd hope my 2FA would freak out, around that point, and save me from myself. I guess it would depend on the type of 2FA.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#17
This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea.

Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things that look like URLs.

Sorry if this sounds like victim blaming, but at some point, after enough time, you have to eventually go from "victim" to "culpable".

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#18

This is crazy. It's 2017. Why are people STILL clicking links in their E-mail? Have people learned nothing? You don't have to be a "technical user" anymore know know that's a bad idea. Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things th…

I click the "unsubscribe" link all the time! Not to mention confirmation email links (much more convenient than entering a code they email me), package tracking links, and a whole slew of others.

Re: Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

#20

"Changing your password every few months is good practice in general." Stop saying that! https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...

Anybody else seeing a certificate error on ftc.gov?

are you under chrome? https://knowledge.geotrust.com/support/knowledge-base/index?...
Post reply on HN