Besides the obvious schadenfreude at AMP being abused, this stood out to me. It's just so delicious, malicious actors thwarting automated analysis of their shady links by including CAPTCHAs...
Besides the obvious schadenfreude at AMP being abused, this stood out to me. It's just so delicious, malicious actors thwarting automated analysis of their shady links by including CAPTCHAs...
Many scraping products and the internal scraping systems of companies (especially retailers) implement such mechanisms.
It's honestly a frustrating problem as we're effectively in an arms race with the likes of Cloudflare, Google et al, and we're in the same boat with less reputable services like scrapers and bots. The recent developments around Web Environment Integrity are concerning to us for the same reasons. Feel free to reach out with any questions or suggestions you might have!
A captcha might serve as a strong negative signal.
Disclaimer: I work at CF
https://nvd.nist.gov/vuln/detail/CVE-2023-3079
Edit: even better, every tab is a separate container instance, i close tab, it nukes the container
As for improving on tab isolation over what existing browser sandboxes already offer, lightweight virtualization a la Firecracker seems like a more useful increment than containerization, and, assuming each tab has a similar VNC-like connection to its browser VM, virtualization would also make the whole "throwaway computer" setup less necessary to provide a meaningful security improvement.
1. To bypass your corporate proxy (ok, not the best reason);
2. urlscan also allows you to pivot easily and find the same phishing kit as they have a nice database of scans;
3. urlscan also allows you to see the website from different proxies, which can be useful if there is geofencing.
It isn't that simple and threat actors are far from being dumb :)
Disclaimer: I'm the CEO of urlscan.io
[0] https://blog.cloudflare.com/eliminating-captchas-on-iphones-...
* Applies to any other walled garden megacorp.