Clever social engineering. A malicious web page that tells you it's malicious.
f-secure.com
f-secure.com
And before you scoff at that, think of the economic cost of letting folks get "trojan'd" -- this helps build botnets, which have a measurable negative social impact on the Internet -- more spam, financial fraud, DDoS attacks, etc. Obviously not as severe as drunk driving deaths, but worthy of prevention nonetheless.
I know I'm trained -- I look at that "OK" button on the install dialog and my stomach churns. But others don't have this geek instinct, and that should be corrected.
So many security related interactions have backfired already, like this one. Is there one simple, straightforward principle that users could follow that will always work, and will keep working long into the future? I doubt it.
I have always wondered how the Mac OS password screen works (you know, the one where you are supposed to enter your system password). What if an app spoofs it? How would the user know the difference visually?
Most people (still!) don't question authority and there is a picture of a policeman right on the page, for gosh sakes!
The problem with making users afraid is that attackers will find a way to use that fear against them. You can't scare people into thinking critically.
(... which were easy to spot for me, because I'm using a completely different system)
It's a pretty cool feature, but it means that on Firefox, attackers should be able to emulate basically any chrome they want to.
"ironic"