4 ms·
I agree. However, is it a stretch to say that those same web users who would put their passwords into a google form are not looking to see if a site is secure,
by ditojim 15y ago
I agree. However, is it a stretch to say that those same web users who would put their passwords into a google form are not looking to see if a site is secure, either?
- bdhe 15y agoI think there's a subtle difference. Think of a parent who has been told to never enter sensitive information unless the URL has a little green lock. Unfortunately, as shown in the article, these phishing attempts are over SSL and might trick people into believing that the security here is same as connecting to a BoA website over SSL. I think the difference is, this is not a legitimate website, or even if it were, people must know explicitly using Google Docs, data is stored in plaintext in a spreadsheet. There should be a way to inform users that these forms are different from the forms they normally interact with in other websites.
- ditojim 15y agohow are google forms different than other forms on a website?
- bdhe 15y agohow are google forms different than other forms on a website? That was poorly phrased. In "normal" websites, a form sends information to the web server and SSL ensures that no passive or active adversary listening to the wire can compromise our information. What the company does with the information is entirely unknown but hopefully they store it in a secure manner (cc no.s, for eg.) In the case of Google Docs, all you know from SSL is that your information is securely going to a Google spreadsheet, which is information in the clear. This is different from securely connecting to a BoA server, for eg. I guess, to avoid this phishing, people must also learn to never trust forms that are hosted on Google Docs for sensitive information because the standard use case for Google docs is not to securely store information.