Progressive Web Apps (PWAs) Phishing
mrd0x.com
Progressive Web Apps (PWAs) Phishing
1–10 of 44 posts
Re: Progressive Web Apps (PWAs) Phishing
#2Re: Progressive Web Apps (PWAs) Phishing
#3I think you could do the same in native apps? So yeah, not much you can do about uncareful users. I suppose you could use something like an App store to provide some checks and a little more security. But then you're likely to run into monopolies again..
But since the trick requires the user to go to a malicious website to install this app, it seems to me that the user might similarly be tricked into entering credentials on that website.
Re: Progressive Web Apps (PWAs) Phishing
#4Re: Progressive Web Apps (PWAs) Phishing
#5What's the difference between this and just having a button on your website that redirects to a spoof microsoft login page?
Re: Progressive Web Apps (PWAs) Phishing
#6I think you could do the same in native apps? So yeah, not much you can do about uncareful users. I suppose you could use something like an App store to provide some checks and a little more security. But then you're likely to run into monopolies again..
I guess the argument would be that a screened app store would block such a malicious app. But since the trick requires the user to go to a malicious website to install this app, it seems to me that the user might similarly be tricked into entering credentials on that website.
Re: Progressive Web Apps (PWAs) Phishing
#7Re: Progressive Web Apps (PWAs) Phishing
#8Does this fool tools like 1Password?
Re: Progressive Web Apps (PWAs) Phishing
#9I think you could do the same in native apps? So yeah, not much you can do about uncareful users. I suppose you could use something like an App store to provide some checks and a little more security. But then you're likely to run into monopolies again..
I guess the argument would be that a screened app store would block such a malicious app. But since the trick requires the user to go to a malicious website to install this app, it seems to me that the user might similarly be tricked into entering credentials on that website.
Re: Progressive Web Apps (PWAs) Phishing
#10What's the difference between this and just having a button on your website that redirects to a spoof microsoft login page?