Live data from Hacker News

The inception bar: a new phishing method

jameshfisher.com

81–90 of 238 posts

Re: The inception bar: a new phishing method

#83

Earlier quoted context omitted.

Prolly need some sort of ml to parse every image used on device and tag potentially dangerous ones. Wouldn’t be too expensive on devices with tensor units... Apparently Apple already reports your offensive photos already, can’t imagine why browsing should be treated differently.

> potentially dangerous ones How do you define this? > Apple already reports your offensive photos already What?

> How do you define this?

Same as every tech company do with tons of other spam types.

> What?

https://techcrunch.com/2017/10/30/no-iphones-dont-have-a-spe...

>> This analysis generally happens inside a sandbox, and very little of what the systems determine makes it outside of that sandbox. There are special exceptions, of course, for things like child pornography, for which very special classifiers have been created and which are specifically permitted to reach outside that sandbox.

Unsure what is Techcrunch's source for this but it kinda makes sense.

Re: The inception bar: a new phishing method

#85
post #74

There was a similar thing reported a few months ago relating to a fake Facebook social login popup. https://myki.com/blog/facebook-login-phishing-campaign/ It adds the browser elements to make it appear like a verified popup. The only reason it was discovered was due to users complaining that the password manager did not auto-populate the form. https://news.ycombinator.com/item?id=19188386

Back in the day you used to be able to get people to click a series of sharing dialogs with fake iframe overlays. People were abusing it to get insanely viral posts shared by millions.

Re: The inception bar: a new phishing method

#87

"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…

In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.

As popularized in "webdude vs. sales guy"

Re: The inception bar: a new phishing method

#88
post #73

Whenever I’m looking at an iPhone screenshot someone posted on social media on my iPhone, I try to navigate using the buttons in the image. There ought to be a long German word for that experience.

Klickbarernavigationselementeillusion?

Benutzeroberflächenabbildungsverwechslungsgefahr

(user interface image confusion danger)

Re: The inception bar: a new phishing method

#90

"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…

Prolly need some sort of ml to parse every image used on device and tag potentially dangerous ones. Wouldn’t be too expensive on devices with tensor units... Apparently Apple already reports your offensive photos already, can’t imagine why browsing should be treated differently.

This is not new, antivirus software already shows reactive methods do not work.
Post reply on HN