The Line of Death (2017)
textslashplain.com
textslashplain.com
We discussed about how most browser warnings currently fill the page below the line of death in a way that is easy for phishing sites to impersonate. The user can click "Back to Safety" only to be taken to the real phishing page.
One of the experiments we conducted was presenting browser warnings above the line of death by replacing security indicators with risk indicators, and even popping-out a warning explanation upon a risky interaction.
Overall, subjects reported that they felt safer when the browser alerted them to abnormalities, rather than simply showing them when they were "secure" or having the browser making absolute trust decisions for them by blocking access to a page with a big warning.
https://news.ycombinator.com/item?id=30697329
The trusted UI battle has been effectively lost. Or it was not much of a battle in the first place, as an average consumer trusts anything with a lock icon on it, as UX researchers found out in 00s - 10s. WebAuthn and passwordless trust flows are our best hope to stop phishcalypse.
Pop-up login windows shouldn't be a thing. First because browsers have some hard rules about pop-ups, but also because inter-window communication isn't reliable so doing everything on the same window is easier in every way.
Browsers shouldn't let the site open windows as they wish. That's incredibly user-hostile. Take the example from Firefox: if the user allows pop-ups, by default they can only open on tabs, without the focus, and with full chrome. (It took a while for Firefox to get over the usual web culture and restrict the sites, but it seems that other browsers aren't there yet.)
And finally, there is the issue with passwords. We just shouldn't be using them on random sites anymore. But browsers just can't innovate.
By the way, this is the standard OAuth flow.
There are a number of reasons why we can basically expect everything to converge on all computers behaving exactly the same, even if the interop standard notionally says they don't have to:
* Any observable behavior will eventually be relied upon. You know, Hyrum's Law.
* Extending a protocol means that someone, somewhere is behaving differently in response to that protocol extension. This means extending a protocol changes its semantics, and that people will either rely on the extension being supported [1], or they will (accidentally or maliciously) create crap data in the extended namespace and penalize anyone who actually tries to use it [2].
* In other words, there is no such thing as optional features in standards. Either the feature works, and implementations that do not support it get fucked*, or it doesn't work, because the implementations that do not support it had enough clout to make it unusable.
* If vendor-locked-in solutions provide a better UX, a lot of people will just use that [3]. Especially if the locked-in version is a superset of the standard, and everyone gradually just moves to the version with proprietary extensions because fixing the interop hazards is more important than whatever feature ties them to a niche implementation. Consider how Linux EEE'ed POSIX. Was there a conspiracy, like with ActiveDirectory and LDAP? Or did it just sort of happen?
[1]: https://acko.net/blog/on-variance-and-extensibility/
[2]: https://web.archive.org/web/20070508200721/http://www.well.c...
[3]: https://signal.org/blog/the-ecosystem-is-moving/
* By "get fucked", I mean "not interoperable." It might still be usable in a limited context, but that means network effects are working against it instead of for it. I need very, very good reason to use two different web browsers.
If anywhere on that comment I gave the impression that it is how I believe things are, it is due to a bad choice of words.
That means that you can end up with a lot of tabs open, but it really helps to unmask these types of attacks.
Ultimately, I think browser vendors should implement better patterns to discern actual windows from mimicked windows. For example, showing a personal secret signature in the UI above the "line of death".
The attacker won't be able to figure out the secret signature so only a legit browser window will be able to display it. Here is a quick wireframe of how it could work: https://cln.sh/0GbV3A
Those same developers seem to heavily overlap with the group that loves to shit on FTP and DNS etc., because they were designed for a less adversarial internet. I'm not sure what to make of that cognitive dissonance.
But, maybe browsers as we know them should die and be replaced with something better.
Sometimes I wonder how things would have turned out if Java plugins hadn't been security Swiss cheese.
The browser actually gives us more security.
What's missing is clear attribution of which "app" created the window.
Internet Explorer should definitely be renamed "Application Runtime Engine for ActiveX" though.
It combines a lot of different aspects that make UI (which is always hard) more difficult:
* Catastrophic implications, but rare (in the typical user's experience). How often does the average user get phished or have their account taken over, compared to how often do they have to log in to Random App X to do their job?
* Can impede user's job, even when done right.
* Competes with functional features, sometimes directly. Why is there now a full window API? Because it is useful.
* People who work in the space are experts and will notice things that typical users will not (the example the author gives about Vista/XP)
There is far too much marketing/designer pressure for appearance over function, appearance over convenience, appearance over <any actual useful metric>. All the extra complication brought onto the web protocols just so designers could control appearance of a page to a pixel (even though the original intent of web protocols was that appearance and content be disassociated).
Stuff may look prettier (debatable), but much has also been lost.
Really, the only thing missing is "all popups must have browser Chrome until the user chooses to hide it for that site (or whatever the latest subset of "site" is for Origin security)
A "line of death" sounds like something only technical users would notice
It bugs me further that browsers don't let me decide whether the top bars get shown. Sometimes it'd be really nice to toggle off all the browser chrome and just have a true full-window view of a page (Full-window, not full-screen: in particular if I'm opening multiple pages and tiling them vertically, all that browser chrome starts taking up a lot of space really quickly).
Dear browsers: this is hopelessly backwards! Websites should never be allowed control my browserchrome. I should always be in control my browserchrome. Given that this is already configurable per-window, put that switch solidly in my hands!
I thought everyone just googled and looked for links they'd previously visited...
One way is to ban an entire color region around a particular color you choose for fields requesting passwords or doing other sensitive data. The problem with it is of course that it's too big of a limitation.
But how about a pattern like yellow/black checkerboard or stripes? This would require the parent to be able to analyze the child's look, and whenever the security pattern would be detected, it would display some kind of a warning about the content being similar to a secured input without actually being the secured input...
The Netscape Security Team was worried about UI spoofing, the browser-in-a-browser attack. - https://news.ycombinator.com/item?id=30722033
Alas, they need not have bothered. Users didn't notice fakes, and got mad if a web application was blocked. The whole apparatus to support public-key certification of web elements was pulled in later versions of Netscape.
25 years later, and essentially no one thinks about bad guys before dutifully typing their password.
Microsoft Windows tried. Windows shows a distinctive, full screen alert if you want to do something with elevated priveleges. Windows supports custom security policies and signed PowerShell scripts.
But the only way to prevent users from leaking authentication is to require auth that can't pass over a network. 2FA with local (not remote) physical token.
https://news.ycombinator.com/item?id=13400291 - Jan 2017 (106 comments)
I think this likely less affects me as I use Linux and Firefox. The window manager on my distro supersedes Firefox's, so if window in widow happened it would look weird because no window manager.