3 ms·
It's possible to do "trusted UI" on iOS/Android by opening a browser window that shows you're actually logging into facebook-dot-com. That still wouldn't preven
by gridlockd 6y ago
It's possible to do "trusted UI" on iOS/Android by opening a browser window that shows you're actually logging into facebook-dot-com. That still wouldn't prevent these scams from working because users don't necessarily know how to tell the difference between "trusted UI" and "scam UI".
- londons_explore 6y agoExcept it isn't... Because the app can just show a UI that looks like a browser window, and there's no way for the user to know.
- danielhua 6y agohttps://news.ycombinator.com/item?id=24470530 https://news.ycombinator.com/item?id=24470530 Looks like it was a real Facebook login webview.
- gridlockd 6y ago...which is different from a browser window, running inside the actual system browser. The difference may of course be subtle, but even obviously fake logins can work on the untrained eye.
- gridlockd 6y agoIf you open a browser window, there is going to be some things that can't be faked 100% accurately, e.g. on iOS there will be a link back to the app at the top left, there is going to be an animation, and so on. It could be faked 95% accurately, but that's moot, because like I said, the user hasn't necessarily learned what "trusted UI" is in the first place.
- donmcronald 6y agoLike this old trick. https://news.ycombinator.com/item?id=4629906 https://news.ycombinator.com/item?id=4629906