Is My Credit Card Stolen? (A ruse to educate people about phishing)
ismycreditcardstolen.com
ismycreditcardstolen.com
I'd remove the negativity from the start. Putting "This is a test, you have failed it" right in front of folks is an instant turn-off, and might lead people away from your page instead of to the helpful content below.
More bullet points. There's not a whole lot of text there now, but anything you can do to get the message across with fewer words is a win, especially when dealing with non-technical folks.
Under "look at the address bar", you have: A common phishing trick is to have a domain like amazon.com.not.ru, which steals your credentials when you try to log in. The actual domain in this example is "not.ru," but people often only check to see if the string "amazon.com" is anywhere in the address bar.
I'd change that to not use the word "string" since non-tech-folks don't parse that very well, and maybe include screenshots of an address bar containing the real Amazon.com and a phishing site disguised as Amazon.
Still though, good idea!
Edit: I used the "you fail" message because I think it makes people more likely to remember it. I wanted to say something like "your credit card has been stolen. kthxbye." but that would have caused some false alarms.
It's hard to have a memorable message without it causing offense or panic.
Also on my TODO: add a counter for those who put 16 digits in the credit card field.
Extra edit: nfriendly: Thanks for the styling suggestion.
li { margin:12px 0; }This is confusing, in my opinion. It's hard to explain the difference between a login form and a page asking for your password, so it's probably worth just leaving this out. Any phisher worth his salt makes the page asking for a password look like a login form anyway.
2) Get a bunch of educated people to review it for 3-5 days and approve of it.
3) Wait until the educated people send links of this to their non-internet literate friends, for education, shits and harmless giggles.
4) Switch to a live form that captures data.
6) Profit
they are both 'pending', since apparently, having 'credit card' in your domain is suspicious: http://ismycreditcardstolen.com/anti-phishing.jpg
Security is a strange beast.
"This web page at ismycreditcardstolen.com has been reported as a web forgery and has been blocked based on your security preferences."
I guess paypal and a small number of verified payment processors, (or real online banking) are about the only option.
I do like the convenience of being able to memorize a password or CC number though.
Laziness, of course, is a problem also.
During its three-hour run, nearly 6000 people (20%) tried to give me their google account credentials.
http://www.reddit.com/r/programming/comments/bpy7h/think_you...
So anti-phishing folks got accused for phishing. Looks it was technically nice idea but terrible user experience.
Unless of course there WAS a hidden agenda here.
Edit: yeah I would normally never use JS for validation.
Edit: although I suppose you can have an exception in this case :-)