Are any advanced users on HN that would've overlooked the obvious signs in the address bar?
I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different.
IMHO only inexperienced users will fall for this. If you regularly look at the address bar before entering critical data into a website, you will get used to the overall look and most likely notice that something is out of order.
Pssh, I'll say it - I'd fall for this, more than 0% of the time. Am I an advanced user? I can try to give you an example of some client side TLS thing I have implemented and we can haggle over where the bar is for "advanced", but give me a Saturday night beer-riddled netflix binge and a midnight email check, I'm clicking this link.
I'd hope my 2FA would freak out, around that point, and save me from myself. I guess it would depend on the type of 2FA.
I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different.
IMHO only inexperienced users will fall for this. If you regularly look at the address bar before entering critical data into a website, you will get used to the overall look and most likely notice that something is out of order.