4 ms·
To add to that https I think is one part of the puzzle. This weekend I watched a bunch of scam bait calls. Very amusing to watch them get taken down. But the
by sumtechguy 6y ago
To add to that https I think is one part of the puzzle.
This weekend I watched a bunch of scam bait calls. Very amusing to watch them get taken down. But there are people out there mailing 20k in fedex boxes to scammers. All because their browser said 'your balance is 20000 and I transferred too much to the account, could you mail that back to me so I do not get in trouble?'. It is a very human attack using a combination manipulation, fear and compassion. The bottom line is these people unknowingly allowed people to open the debug console in their browser to change things.
What I have been trying to figure out in my head is how do we do a digital watermark on data presented to the user? How do we at a minimum tell the user their data has been manipulated? You can have all the TLS on every level but at one of the most important ones there is nothing. A scammer can open a debug console on a https presented page just as much as a http page.