5 ms·
the last form in question is a valid google form created by google for the purpose it stated. i have used that form. you have to be pretty naive to enter your
by ditojim 15y ago
the last form in question is a valid google form created by google for the purpose it stated. i have used that form. you have to be pretty naive to enter your password data into a google form. if you have ever used google forms, you will know that the data is stored in a spreadsheet.
any person could exploit forms created in salesforce or any other form creation applications on the web with similar results.
- zitterbewegung 15y agoI think the average web user might be more naive than you think though.
- ditojim 15y agoI agree. However, is it a stretch to say that those same web users who would put their passwords into a google form are not looking to see if a site is secure, either?
- bdhe 15y agoI think there's a subtle difference. Think of a parent who has been told to never enter sensitive information unless the URL has a little green lock. Unfortunately, as shown in the article, these phishing attempts are over SSL and might trick people into believing that the security here is same as connecting to a BoA website over SSL. I think the difference is, this is not a legitimate website, or even if it were, people must know explicitly using Google Docs, data is stored in plaintext in a spreadsheet. There should be a way to inform users that these forms are different from the forms they normally interact with in other websites.
- ditojim 15y agohow are google forms different than other forms on a website?
- bdhe 15y agohow are google forms different than other forms on a website? That was poorly phrased. In "normal" websites, a form sends information to the web server and SSL ensures that no passive or active adversary listening to the wire can compromise our information. What the company does with the information is entirely unknown but hopefully they store it in a secure manner (cc no.s, for eg.) In the case of Google Docs, all you know from SSL is that your information is securely going to a Google spreadsheet, which is information in the clear. This is different from securely connecting to a BoA server, for eg. I guess, to avoid this phishing, people must also learn to never trust forms that are hosted on Google Docs for sensitive information because the standard use case for Google docs is not to securely store information.