3 ms·
Both links are broken.
by peternicky 10y ago
Both links are broken.
- mutagen 10y agoSorry, in hindsight my comment is rather opaque. Those links are incomplete links of the phishing links contained in the emails. I wanted to highlight the difference in the screenshots in the vice.com article between seeing a clear www.google.com (due to the AMP cache) and a google.com-user-security.tk or whatever spoofed domain that got used. Point being Google is making it easy for phishers to spoof links with the AMP cache. I'm guessing Google is relying on their existing malware detection and site reporting process to weed out pages that take advantage of this. This approach mostly works for mass spammed links and sites trying to pass on malware but won't work for targetted phishing attacks against all but the savviest of security conscious users.
- tmzt 10y agoIs it possible the article writer got served the AMP page and the redirect was to the .com-* subdomain? Are the bit.ly targets known?