Live data from Hacker News

Half of All Phishing Sites Now Have the Padlock

krebsonsecurity.com

31–40 of 79 posts

Re: Half of All Phishing Sites Now Have the Padlock

#31

Earlier quoted context omitted.

RIP Microsoft. IMO this is a big reason why their phones/app store died. Try finding the real VLC player in the store - last I checked they dont even have a app store version (but you'll find tons of results for it).

There's real vlc app in both Windows and WP app store. In fact there were two official VlC apps for Windows Phone. One was written with c/c++ and the other UWP version

^ Though, it should be noted that the fact that there's two official versions speaks to a somewhat parallel issue.

Re: Half of All Phishing Sites Now Have the Padlock

#33
post #14

Earlier quoted context omitted.

> The many mobile browsers which hide the address bar are training people to ignore website urls. This is my biggest complaint about forcing users to use apps to browse a website-- it hides everything . I have no idea if any given app is actually using SSL. Oversights have happened before to Credit Karma, Fandango and others.

https://techcrunch.com/2016/06/14/apple-will-require-https-c...

IIRC you can still submit an app with exemptions to this rule; you will just have to provide a justification for it that Apple deems reasonable.

Re: Half of All Phishing Sites Now Have the Padlock

#34
Great so every 3 months when I have to manually renew all the LetsEncrypt certs I manage for clients I know it's giving them zero protection. Kinda reminds me of the British Government's decision to insert road humps into all the roads in the towns and cities of the land just to deter speeding drivers. All it produced was more work for garages mending damaged exhaust pipes.

Re: Half of All Phishing Sites Now Have the Padlock

#35
post #34

Great so every 3 months when I have to manually renew all the LetsEncrypt certs I manage for clients I know it's giving them zero protection. Kinda reminds me of the British Government's decision to insert road humps into all the roads in the towns and cities of the land just to deter speeding drivers. All it produced was more work for garages mending damaged exhaust pipes.

[deleted]

Re: Half of All Phishing Sites Now Have the Padlock

#37

I remember that people were warned to avoid doing sensitive stuff on websites without the padlock. I don't remember any attempt to suggest that the padlock implied some sort of validity.

Most users do not understand the “necessary but not sufficient” condition. They need a “if (condition) { SAFE; } else { NOT SAFE; }” test, not an endless checklist, and the security community has continuously failed to deliver on this.

Re: Half of All Phishing Sites Now Have the Padlock

#38
post #5
post #2

The many mobile browsers which hide the address bar are training people to ignore website urls. Sites who use lots of nonsensical malware-ish url redirects (Google, Microsoft are guilty) train people to accept random urls. I guess the chief culprits are email tracking links. Everyone including banks use them. Often tracking domains have nothing in common with the destination URL. This teaches people to disable or ign…

Banks and credit card companies have always been the absolute worst offenders for this, requiring people to use hidden iframes from all sorts of acmegenericsecure.net domains, and all the while professing to be the high priests of good practice with their absurd PCI racket, not to mention asking people to install random third party software just to use their websites because browsers apparently aren't good enough.

>not to mention asking people to install random third party software just to use their websites because browsers apparently aren't good enough.

is this still a thing? maybe this was true back in the days when activeX was still common, but not now.

Re: Half of All Phishing Sites Now Have the Padlock

#39
post #38
post #5

Earlier quoted context omitted.

Banks and credit card companies have always been the absolute worst offenders for this, requiring people to use hidden iframes from all sorts of acmegenericsecure.net domains, and all the while professing to be the high priests of good practice with their absurd PCI racket, not to mention asking people to install random third party software just to use their websites because browsers apparently aren't good enough.

>not to mention asking people to install random third party software just to use their websites because browsers apparently aren't good enough. is this still a thing? maybe this was true back in the days when activeX was still common, but not now.

Check out Rapport, big banks prompt you to install it everytime you visit their login page.
Post reply on HN