Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

101–103 of 103 posts

Re: Google Phishing Quiz

#101
post #83
post #32

Earlier quoted context omitted.

...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

AFAIK they don't have any pages there that allow account login, for that and other security reasons.

That doesn't help the situation much, even if it were true. If a phisher creates a fake Google domain, how many users will go, "Aha! I was about to login using my Google credentials, but then I remembered Google only asks users to login to *.google.com domains, so I know this is an attempted phish!"

Re: Google Phishing Quiz

#102
post #43

Earlier quoted context omitted.

I agree that it doesn't have to be single-sided, and we need multiple angles to protect against phishing. This quiz isn't it, though. You and I know what domains are; we know what's possible; we can sense when somethings off. It's our bread and butter. The average user knows none of these things, and giving them a dozen rules to follow that will work a lot of the time is in the end confusing. A better set of rules to…

I’m not even convinced “don’t click links” is the best guidance. That message has been pushed so hard that people immediately think their machine has been compromised once they have clicked a shady link. That is nearly never the case. Clicking links isn’t something that should cause fear. Nobody is burning a modern browser vuln in a spam email. I think the message should be more focused on not manually entering crede…

Clicking links can be a problem in corporate environments where automatic login has been enabled on Internet Explorer and outbound SMB not blocked.

The phishing site immediately gets their domain ntlm hash, which can often be cracked to gain a password.

This can also be a problem in PDF and Word docs without the need to employ a 0 day. https://resources.infosecinstitute.com/steal-windows-login-c...

Also to note that password managers can help mitigate phishing, as they will not offer to complete passwords if the domain does not match.

Re: Google Phishing Quiz

#103
post #2

I had no idea google allows arbitrary redirects through its own https://google.com domain. Why?

Actually, it looks like navigating to the link you're talking about https://google.com/amp/tinyurl.com/y7u8ewlr , or any link beginning with https://google.com/amp/ , will first bring you to a redirect confirmation, not immediately redirect you. (The shortlink above is actually safe - it redirects to https://jigsaw.google.com/ )

does anyone know where google documents this?
Post reply on HN