Live data from Hacker News

Google Phishing Quiz

phishingquiz.withgoogle.com

81–90 of 103 posts

Re: Google Phishing Quiz

#81
Wait. So why didn't google just put this on a subdomain? It's a phishing quiz at a phishy domain, and the first thing that happens on iphone is it asks for your name and email (instructions are covered up)

Re: Google Phishing Quiz

#82
The Tripit one is very problematic. They don’t say that you installed TripIt. I’m supposed to allow any Google third-party access to my email? Even if I didn’t initiate that?

Hovering over the “allow” button doesn’t show anything. They need to reword that one.

Re: Google Phishing Quiz

#83
post #32
post #24

Earlier quoted context omitted.

withgoogle.com is more of a 'sandbox' for Google one-off programs, labs, events, etc. which don't need to have the same branding guidelines as on google.com domain.

...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

AFAIK they don't have any pages there that allow account login, for that and other security reasons.

Re: Google Phishing Quiz

#84
post #7

Earlier quoted context omitted.

The inclusion of that one kinda baffled me. No way for me to tell whether the app that's connecting would be one I'd want reading emails (I wasn't familiar with it) and without an address bar, hard to tell if it's a spoof or the real thing.

Yeah, I mean it doesn't say the context very well, so I assumed it I clicked on a link. Like if it said you signed up for a service and clicked on a link to do something very specific. If I accidentally clicked on a link in my email and it brought that page up, could you call it phishing? Also the email from the person with the PDF. Like, why is that phishing? What if I trusted the sender? People send pdfs all the ti…

I think it was mostly due to the fact that it was from a different TLD.

The TLD of the context was .EDU and the one from the email was a .ORG.

Re: Google Phishing Quiz

#85
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

I got that answer wrong too. But I guess they were asking specifically about phishing. I think the rationale is that the page has to be a real permissions page to give the attacker access to your data. A fake page won't have any power in that regard. And on a real permissions page, an attacker won't be able to fake the requesting app's link. So: legit page + legit link = no phishing ... even though it is by no means…

The barrier to setting up a "legit" request for permissions for my phishy app is not that high. Yes, you can't phish for Google passwords that way, but you can get access to all other accounts of a person that are not protected by 2FA and can reset passwords via email.

Re: Google Phishing Quiz

#86

Earlier quoted context omitted.

It's because google.com contains very valuable cookies which could be leaked if there was an XSS or something anywhere on the google.com domain. Thats why things like this (which are often developed by third party contractors, and might not go through the same level of review), are hosted on another domain. It's a flaw in the web though. A domain should have the ability to host content without that content gaining fu…

If they mark the cookies as http only then that wouldn't be a concern though, for xss attacks anyway. Subdomains would also solve that issue. https://www.owasp.org/index.php/HttpOnly Personally I think they separate them out for branding. Things that are on google.com are flagship products, and getting your thing under google.com means you and/or you're project has a lot of clot at Google.

Httponly wouldnt solve the issue - the serverside code also shouldn't be trusted with such cookies. Cookies aren't the only permission either - Google wouldn't want webcam or audio recording permission to be given to a 'withgoogle' site without the users consent either.

Re: Google Phishing Quiz

#87
post #3

Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now

They should have proposed three answers for this one :-

[_] phishing

[_] legit

[X] legit, but there's no chance I will accept that!

Re: Google Phishing Quiz

#88
post #9

I missed two: the "allow some random person to read your email" which I would never click on, and the one that had a PDF, even though they don't allow you to do anything with it. Just because someone sends you a PDF doesn't mean it's an attack vector. It would have been more helpful to say something like "this is someone you do business with as well, or someone you've never heard of." (which I find to be more useful…

On the PDF one, it tells you in the "intro" blurb that the sender's email address is wrong. Should be .edu and it's .org.

That's a very US-centric view.

Re: Google Phishing Quiz

#90
post #83
post #32

Earlier quoted context omitted.

...so? It's still a phishing vector. Teaching users that sometimes Google throws together half-assed domains encourages them to trust any domain with "google" in it.

AFAIK they don't have any pages there that allow account login, for that and other security reasons.

Yes, but:

> Create a name and email — neither need to be real — to make this quiz seem more realistic. Don’t worry, this information won’t leave your device.

I'd trust this notice if I knew it came from Google, but since it was placed on a phishy-looking website, it really gave me pause.

Post reply on HN