Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited
wordfence.com
wordfence.com
This is pretty much a win-win Chrome hot-fix that could be rolled out asap.
What an excellent analysis of the user perception involved and its obvious remedy.
[0] > What Google needs to do in this case is change the way ‘data:text/html’ is displayed in the browser. There may be scenarios where this is safe, so they could use an amber color with a unique icon. That would alert our perception to a difference and we would examine it more closely.
And presumably also Microsoft, Apple, Mozilla, Opera...
It's a bit weird from a security point of view that self-XSS is protected in Firefox & Chrome (https://bugzilla.mozilla.org/show_bug.cgi?id=994134 & https://bugs.chromium.org/p/chromium/issues/detail?id=345205), but navigation data-uris are not.
As a PoC, I bought the domain https.is, and now I can construct urls like https.is//accounts.google.com - which can look convincing when glimpsed over.
> The data: URL part here is not that important as you could have a phishing on any http[s] page just as well.”
Calling out the use of data URIs doesn't solve the issue at all. I could just as easily register abc.xyz, pick up an SSL certificate, and send users to `https://abc.xyz//accounts.google.com/ServiceLogin?service=ma... or `https://abc.xyz/https://accounts.google.com/ServiceLogin?ser...
They get a green lock, and that certainly doesn't seem to require the user to overlook any more than the URI in question: `data:text/html,https://accounts.google.com/ServiceLogin?service=mail`
Anyone who treats the URI as an opaque string and simply scans for keywords (which is someone falling for the data: trick) is going to be vulnerable to a large variety of attacks, almost none of which the proposed solution solves.
Stop saying that!
https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
A quick search displays many info on the bug, you need to upgrade chromium.
You never know when somebody has access to your accounts. I learned the hard way that someone had access to my Facebook because they watched me type on the keyboard. Had I changed my password monthly, I would have kicked him out after 30 days. As it stand, that person had access to my account for at least a year if not more.
If anything, I'd say your comment hardened my position against password rotation given how many mainstream sites with sensitive data expose extra security measures to their users. Take advantage of all of them!
1. https://chrome.google.com/webstore/detail/password-alert/noo...
https://bugs.chromium.org/p/chromium/issues/detail?id=594215...
Email is a skeleton key for every other account you own. 2-factor auth can be a pain to use, but at the very least you should always use it to protect your email.
I updated it after my initial upload to enable links (defaults to no links but can click a button to enable links). I just haven't gotten around to re-uploading the plugin. After some thought I definitely feel that just removing links altogether was too much. I will update the plugin after work.
PhishBlock Chrome plugin: https://chrome.google.com/webstore/detail/phishblock/mfigocg...
Depends. See the discussion in the previous post about this: https://news.ycombinator.com/item?id=13372985
So 2-factor actually provides a false sense of security here.
Edit: unless you have U2F as per @makomk comment below
But for the Google Authenticator and SMS - it would still be vulnerable.
I mean, you don't have to know what the string 'data:text/html' means, because Google Chrome highlights the 'https' by coloring it green and they even show a 'secure' button right next to it, so the whole area looks fundamentally different.
IMHO only inexperienced users will fall for this. If you regularly look at the address bar before entering critical data into a website, you will get used to the overall look and most likely notice that something is out of order.
Heck, sometimes browsers come with an update that changes it's appearance.
While you probably wont fall for this 99.9% of the time - the 0.1% that someone "technical" does means the attacker will gain access.
All it takes is a moment of distraction, or you are tired, or in a rush etc...
I'd hope my 2FA would freak out, around that point, and save me from myself. I guess it would depend on the type of 2FA.
Hell, why do major E-mail clients even allow functional hyperlinks in E-mail? The major E-mail clients could 80% solve phishing overnight by just disabling links. They could probably solve a further 10% by disallowing copying things that look like URLs.
Sorry if this sounds like victim blaming, but at some point, after enough time, you have to eventually go from "victim" to "culpable".
"Design for default-secure" ought to be UX rule #1.