4 ms·
This is smart but nothing new in the sense that people have used fake antivirus warnings, fake windows error messages, etc for years now to push you to click on
by danielnicollet 16y ago
This is smart but nothing new in the sense that people have used fake antivirus warnings, fake windows error messages, etc for years now to push you to click on some sort of buttons which would then lead you to a binary install with spyware.
- larsu 16y agoFirefox's html warnings in the browser's content window seem to make this particularly easy, though.
- thorax 16y agoYeah, I'd like to see these warnings move out of the HTML space and into the chrome in some difficult to mimic fashion.
- vog 16y agoThis is already happening for a long time. I remember some ad banners which looked like message boxes or download dialogs in Windows XP style. (... which were easy to spot for me, because I'm using a completely different system)
- larsu 16y agoYou're right. But something like this would be harder to fake: http://www.mozilla.com/en-US/img/tignish/features/security-id.png http://www.mozilla.com/en-US/img/tignish/features/security-i...
- frio 16y agoYes and no. Mozilla's a bit screwed on this front, because they use XUL to render their interface - and, critically, the browser can render XUL pages. I don't have FF installed on this machine, but you should still be able to check it out at http://www.faser.net/mab/remote.cfm http://www.faser.net/mab/remote.cfm to see a demo of the feature. It's a pretty cool feature, but it means that on Firefox, attackers should be able to emulate basically any chrome they want to.
- LordLandon 16y agoTo demonstrate, go to chrome://browser/content/browser.xul in firefox
- sid0 16y agoRemote XUL is disabled in Firefox 4.