Browser in the Browser (BITB) Attack
mrd0x.com
mrd0x.com
My browser always shows the URL scheme, and my UI looks nothing like that, so I guess this is another point in favour of people customising their UI and a point against browsers letting websites modify the appearance of things like scrollbars and form controls, or --- and I really don't understand why no one thought this was a really bad idea to even implement at all --- allowing popups with no browser controls.
I don't think this is such a novel idea either --- remember the fake "your computer is infected click here" popups that tried to look like the OS's? I've always used something other than the defaults for UI appearance, so besides the more obvious clues like having browser controls, they really looked off with things like their different titlebar colour and font.
>“It’s a picture of an IE7 browser running on Windows Vista in the transparent Aero Glass theme with a page containing a JPEG of an IE7 browser running on Windows XP in the Luna aka Fisher Price theme?” I pointed out.
>“Oh. Huh.” they noted.
This is one of the primary methods Discord scammers phish for accounts nowadays, and it still seems to be extremely effective.
The sad thing is that even with a real popup the only defense you have is the URI, and most of the time its incomprehensible tech-speak so realistically speaking normal everyday users don't stand a chance.
The fake popup would be the only window that doesn't look like an Atari ST. :D
What's that Ultra-privacy oriented Linux distro which is TOR-centric, with a locked-down-by-default browser config? That beast might be your best bet.
That would defeat this attack, assuming it was random/undetectable. Maybe time to go the other way and never lock down the config...
Or just disable anything resembling a box in the browser, make html strictly hyper text media again, no programming or js.
Also.. setting a custom UI background image sounds like browser configuration to me :p
Seriously though, the difference with and genius in your idea is essentially applying the "Send my bank a custom secret they then present to me so I know if I'm really speaking with them", except with new twists in:
1. Know if a window belongs to my FF client / OS / whatever needs securing.
2. The absence of further concerns about what OS details get inevitably leaked, at least for protecting against this one class of threat.
You're probably thinking of TAILS.
QubesOS never allows true full screen mode to prevent spoofing attacks, the titlebar and taskbar are always visible. It also forces all windows to display a colored border, the color represents the application's security domain. A window in an untrusted VM cannot pretend to be a trusted VM window. A spoofed browser screen won't show the correct titlebar and (user-defined) color.
But what makes this attack frightening is that even such kind of extreme measures only provide limited protections. Spoofing is still possible, you can bet on the default theme with a red border - this is the default for untrusted, disposable VM. I'd say I would totally fall for this.
The only thing that makes it somewhat safe is the impossibility to detect QubesOS reliably. Some heuristics exist: you can detect CPU cores, a low number indicates a potential VM. You can also detect the GPU model, a LLVM software renderer or disabled WebGL is a strong indication of VM or Tor Browser. But none is reliable.
I wish the browsers would just open everything in new tabs.
For this particular attack, a fun 'solution' may be to incorporate some sort of AI-based detection system to warn the user if anything resembling a browser is shown on the site.
WebAuthn is already being deployed. There will be a decade of consumer education ahead.
The elliptic curve private keys used to sign the authentication message are actually different for every site you use the authenticator with, they're chosen at random and cheap authenticators aren't even storing them anywhere, which is part of how fiendishly clever WebAuthn / FIDO is.
Because the authenticators aren't storing the identifier, if you sign into GitHub as asiachick, after having previously enrolled your authenticator as southamericandude even that authenticator has no idea you're asiachick, and so it won't give the game away, and you can even enroll the same authenticator for both these users and it will work, correctly, and GitHub can only even prove anything is going on by deliberating asking asiachick to authenticate as southamericandude or vice versa, which they've got no reason to try.
Now, if you are using WebAuthn to do usernameless authentication (no password, not even a username, just WebAuthn and one touch to log in) this can't work without the authenticator knowing the credentials. But in that case your local device gives you a menu saying like, asiachick or southamericandude ?
Hell no. Do NOT want. No no no no no, never.
A password is a simple concept. That stuff seems more aligned with incentives to create complexity, and thus increase possibility of things going wrong. Not to mention the overall dystopian nature of it all.
Password managers are a perfectly reasonable answer, but they need to hide the text entry field, to make sure everybody actually uses the password manager instead of entering a password by hand.
Also, I resent the comparison between advocating a defensive design, and being opposed to literacy. It’s not as if I’m advocating for locked bootloaders, or anything else that would prevent a determined user from doing whatever they want. I’m arguing that manual password management should not be the obvious default.
Perhaps you shouldn't - this is like Conways law, systems tend to mimic the communication systems of their organizations.
When you design a system which encourages a certain philosophy, you create "positive" potential in that direction. By designing and promoting systems which reduce user control, you further the communication model of top down hierarchical control.
Why should I trust Webauthn? What stops it from itself being hacked? People with password managers, no control over authentication, end up less, not more secure. The only way to increase security is modularization - if you don't want phishing attacks to occur, you should isolate the process. You should have more than one password, and you should absolutely not store them all in one place.
There have been several indications in this thread how you can isolate the process, none of them require overly complex, big brotheresque solutions.
Something you have AND something you know.
I don't want someone to lift my HSM and joyride with it all weekend before I notice it's gone.
At the cheapest end, something like a Yubico Security Key 2 does two factors with one being the physical key you have and the other being a PIN (such as "180479" or indeed "FkR0Mpg"). An adversary who steals the physical device needs to guess the PIN correctly before it locks out after a few wrong guesses.
Something like a decent Android phone uses a fingerprint as its second factor, Yubico make a physical device that does this if you've got cash burning a hole in your pocket.
In WebAuthn terms the remote site ("relying party") just asks for User Verification and checks that the UV bit is set on the signed message from the authenticator (all WebAuthn signatures will have UP (User Present) set, but UV is a separate bit)
The fake website can ask for two-factor input and man-in-the-middle proxy this to the attacked website. These techniques have been used by the phishers for the last decade or so. Asking more two-factor codes e.g. Once at login and once at withdrawal helps, but the impact is not significant and also brings down the overall UX.
The real browser knows you are looking at phishing.example and so if asked for credentials it will try to get credentials for phishing.example, meanwhile the fake browser which insists this is facebook.com can't talk to the physical Security Key.
The presence of alternative “back up” Authentication mechanisms on nearly every site and service prevents WebAuthn from being truly effective.
And most people won't think of enrolling a secondary 2FA module, not to mention there are a lot of sites that don't allow enrolment of more than one authenticator and the fact that the backup has to be stored somewhere offsite opens up new potential for theft
For example, C2 was pretty keen on only allowing a single admin connection at a time. We actually had to build a mechanism on top of SSH to guarantee that! It wouldn't surprise me if they required SAK to kick out remote users. "Bring this system fully into my control" kind of thinking.
I think there's literally no difference between the phishing and real pictures.
Things that would make me notice this: My auto password is not popping up (yes I use that). I could drag the window to top or make it full screen and that won't work. I could check if another window is actually open in the taskbar
On macOS with 1password, there are numerous occasions where this is the case, from SSBs and electron apps, to random other things that 1P just doesn't see. I have to copy/paste my password just often enough that I'd probably fall for this in-browser if I weren't paying much attention.
On my Windows 10 work systems, I turn off the default "hide and collapse" behavior so I can read the window titles.
I know normal users cannot read, but the titles are useful for me.
The attack would have to be very well targeted, to fool the user.
I only ever fool myself with my own desktop screenshots. :D
Seems like web browsers aren't really secure enough for anything that needs a password anymore.
I was thinking that with a WASM port of a browser engine you could do the rendering on the client side as well, but you'd have to use a host modern enough to run WASM in the first place so... not a great idea on my part
https://textslashplain.com/2017/01/14/the-line-of-death/
Now, if you got put into fullscreen mode without realizing it, that's another problem.
While the attack might work, I doubt the most of accounts collected would be very valuable for the attacker. It would be mostly people looking for free porn or broke people trying to pirate some movie.
Random phishing attacks via e-mail? Someone posing as a colleague or whatever, telling people to use this new thing for whatever reason, like a dubious OneDrive link.
Bonus credibility points: it uses login with MS, so it must be legit, since we're all using Office365!
Plus, random-non-tech-literate person won't be tipped off by MS requiring another login, especially since they've been trained by IT to log in very often thanks to ridiculously short session durations.
My idea used the same modus operandi: sniff the victim's OS and browser, and present to them a UI custom tailored to fool them.
I always thought the ability to open a browser window without a navigation bar was a terrible idea. Not just because of this attack: I always want to see the URL I'm visiting.
Tangent: I was using the Minecraft Launcher GDLauncher, and it pops a nav-bar-less browser window for the purpose of logging into my Microsoft account [1]. It felt so suspicious, not being able to confirm I wasn't being phished. To make matters worse, if you click the "I can't use my Authentication app right now" button on the nav-bar-less browser window, it triggers a password reset email, not an I-can-indeed-access-this-email-account confirmation email.
[1] You need to present a Microsoft token to play Minecraft online.
You could trick so many users just by randomly popping up one of these that pretends to be an MS365 login. Users are accustomed to the prompts and will blindly enter their credentials. Then the box will disappear and nothing will happen, just like OneDrive.
https://web.archive.org/web/20160213213455/http://blog.mailc... - MailChimp, "social login buttons aren't worth it", 2012
1. If identity providers start offering a dynamic, trusted element within the critical pages (login, password prompt, 2FA/OTP verification etc)
2. if such dynamic element is from a known range/set of customer/trusted-party supplied identity elements.
Ex. During my account creation, say I am prompted to select some "secret identity themes", and I choose { batman, bike, carrots }
At the login/password/OTP prompt, I am shown a 3x3 grid of pics / words / hints, which have at least 3 (or whatever configurable number, in my account preferences) that are somehow connected to my "secret identity theme". This way, I know I can trust this page. The grid also has many unrelated ones acting as decoys elements, so that any malicious spoofing party cannot really figure them out.
I believe you get the general idea.
Do y'all feel this can possibly help, in mitigating this very serious & very harmful threat?
I intend to write a short post on this soon.
I feel BITB mostly gets used by those who may not really be having access to lob a proxy attack at the intended target as well, which filters a good set, among potential victims.
I was trying to say that the dynamic security element helps in filtering at least the most common kind of attack, which otherwise leaves consumers to bear a very large risk.
All this does is lower the effort an attacker needs to invest to replicate it. It's pointing out bike locks are callable and then handing out free bolt cutters to whoever walks by.
And if it's been in the wild for decades then people are already going around with bolt cutters, it's probably good people without bolt cutters understand that.
As is 2FA, e.g. when I'm using a tablet in bed and the smartphone for the 2nd factor is on the table in the living room ... I'd like to see 2FA devices which could be easily duplicated, just as physical keys can.
Many can - what phone based 2fa are you using that can’t sync to your iPad?
While I could duplicate 2FA credentials onto another device, even onto my wife's device (if needed, e.g. for online banking), the attractive feature of a _physical_ key is that I can control the number of copies and "revoke" one after handing it over for a short time and then recollect the device again. That's not as easy with virtual "keys" like authentication apps.
At work, we use smartcards to store credentials (i.e. X.509 certificates). And you are allowed to get a second and even third card, if needed. So I can have one in the office, and one at home. All are protected by their respective PINs. And we do have bluetooth based card readers for smartphones. That (possibly miniaturized like a yubikey) is my preferred model of a "physical" device to use as a key.
BTW, if you're using TOPT 2FA, that typically gets phished too.
Of course, these protect against more than just malicious behavior, they also provide safeguards against human error. However, in a world where malicious behavior didn't exist, many of their designs could have probably been far simplified..
In a trusted world, you still need to worry about order of operations, resource exhaustion, and redundant resiliency...as these are forms of addl complexity perhaps we should get rid of the internet itself...
Distributed systems localize all complexity and don't suffer the same sorts of security issues... The answer to "who is this" is still a problem if only we could program based upon how they behave versus who they are...
In a world where components themselves acted independently of their masters intentions, you might be able to make this work. Computers would have to act very differently, almost self computing systems.
Perhaps what I'm describing is a world run by robots, and so in the absence of proof they would treat us better than we do ourselves, perhaps a bit of consistent pain is worthwhile.
i was more about the insane consequences of today's web's abilities: it wants to do anything and everything with user's computer, it's basically an independent OS. there is no Line Of Death anymore, no clear boundary what user can trust as he trust the OS vendor and locally installed and audited software vendors, and on the other side, trust as an unknown 3rd party on the web.
see "paypal.com" vs "paypaI.com", unicode look-alike chars, public suffix list, etc type of tricks; domain names were invented to be consumable by end users, but as they are sold and used, it's not the case anymore. so users nowadays should not be pressured to watch domain names with bleeding eyes. see "url bar padlock" issue; several survey demonstrated that users do not understand and do not care how the padlock feels.
users can not confidently Ctrl-C anything on any website anymore. using "clever" JS APIs web devs mine bitcoin by visitor's CPU, DDoS other online resource by visitor, store CSAM on visitor's computer, trigger epilepsy in visitors.
then in top of all these, engineers want to solve complexity problems by putting more complexity in it (like solving civilaztional problem with more technology). some suggest to build in an AI which watches if something appears on the screen which looks like a window but is not?! come on! why not just don't let untrusted code do anything on your screen and computer?
I understand client-side scriptng is made very powerful and enables many wonders for the entertaining of the masses. It may be a maintainable path to provide a general-purpose language to the "App Web", where users can run programms with on-click installation (ie. loading a web app on a web site in the web browser). in this case browser vendors and users should prepare for the possible abuses what the general purpose in-browser computing environment enables.
but on the other hand, many users with reasonable usecases expect there should be a "Docu Web" just as the WWW was born to be (with neccessary improvements and modernizations of course - i don't advocate for "Mosaic 1.0 experience") with no accidental transition to the "App Web". this other web, the "Docu Web", should be free of any complexity which may lead to become "App Web" again: i imagine a library/bookstore/newspaper store/journal/shared notes/etc network but online.
so that you don't need to worry that: a jumpscare pops out of a book when turn to page 123; or other library visitors inserts pages in the book you read; or the last week newspaper shows you different articles than to your neighbour; or someone read your mails because you watched his audiovisual report before; or the librarian pushes certain authors and suppresses others based on bribe. sorry for the seemingly absourd analogies, but there were (and are) times when these were possible on the "All-in Web" due to inconsiderate government and adaptation of standards.
"This article explores a phishing technique that simulates a browser window within the browser to spoof a legitimate domain."
For example have a <login> element , browsers will style it the same for all websites and prevent developer to misled the user.
more importantly, display to the user in such a way that no website can spoof it. For instance, it can dim the entire window (eg. like UAC on windows).
You do the login in a native popup, similar on how you give say camera permissions.
Folks who browse in an edge-to-edge maximized window will still be at least somewhat-to-quite vulnerable, especially if less tech-savvy or vision impaired. I generally don't browse this way, mostly due to the relatively insane* width of displays in general these days.
Would mobile users still be vulnerable? Due to:
1. Tiny screen dimensions.
2. No option for "window" resizing. It's not even a thing.
* OT: Displays today are wide to such an extreme they tend to be too wide for my needs and tastes. Eventually it's too much like staring at the bottom 1/5th of a full-sized 4k display, which work sent me but turns out is mostly good for watching Batman, The Matrix, and other ultra-wide theatrical film releases. Granted, at this task, a 34" 1440p widescreen excels marvelously.
Surely you've heard the joke (or is it an adage?):
"With that 34" display, it can [finally] render a Java Class Name and fit it within a single line. But after the IDE and debugger open, you can only see the one line.
(here's a real one http://httpbin.org/basic-auth/foo/bar )
- the login popup could integrate with your OS so depending on your options it could pre-fill the username and password or only the username, a faked one will be forced to guess your username.
- the fake stuff always failled for me, I am using Kubuntu and all those fake popups were using a XP theme.
- because some OSs don't give you the option to customize shit anymore , in this case they would make an exception and ask you to personalize the login popup, like ask you to use an avatar img from a big list that is sorted randomly and maybe a color, anyway Apple and Google have the money to pay someone to think more then 5 minutes about this so there could be even more solutions for this permissions popups.
>With that 34" display, it can [finally] render a Java Class Name and fit it within a single line. But after the IDE and debugger open, you can only see the one line.
Don't hate long names, hate bad names.
I found a bug in our project caused by such bad short names, a good,clear name is always clear then some missleading short one or a random short string.