Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are any advanced users on HN that would've overlooked the obvious signs in the address bar?

I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different.

IMHO only inexperienced users will fall for this. If you regularly look at the address bar before entering critical data into a website, you will get used to the overall look and most likely notice that something is out of order.



Pssh, I'll say it - I'd fall for this, more than 0% of the time. Am I an advanced user? I can try to give you an example of some client side TLS thing I have implemented and we can haggle over where the bar is for "advanced", but give me a Saturday night beer-riddled netflix binge and a midnight email check, I'm clicking this link.

I'd hope my 2FA would freak out, around that point, and save me from myself. I guess it would depend on the type of 2FA.


You'd probably notice because that page would not ask about the 2FA.


By default, Google remembers your device for a number of weeks and does not ask for 2FA multiple times on it.


I recently switched from Chrome to Firefox, and might have fallen for it since I'm not used to the address bar.

Heck, sometimes browsers come with an update that changes it's appearance.


But for the attackers it is an odds game.

While you probably wont fall for this 99.9% of the time - the 0.1% that someone "technical" does means the attacker will gain access.

All it takes is a moment of distraction, or you are tired, or in a rush etc...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: