2 ms·
I foresaw this attack years ago. It makes me feel a bit smug to see it implemented. My idea used the same modus operandi: sniff the victim's OS and browser, an
by DrBoring 5y ago
I foresaw this attack years ago. It makes me feel a bit smug to see it implemented.
My idea used the same modus operandi: sniff the victim's OS and browser, and present to them a UI custom tailored to fool them.
I always thought the ability to open a browser window without a navigation bar was a terrible idea. Not just because of this attack: I always want to see the URL I'm visiting.
Tangent: I was using the Minecraft Launcher GDLauncher, and it pops a nav-bar-less browser window for the purpose of logging into my Microsoft account [1]. It felt so suspicious, not being able to confirm I wasn't being phished. To make matters worse, if you click the "I can't use my Authentication app right now" button on the nav-bar-less browser window, it triggers a password reset email, not an I-can-indeed-access-this-email-account confirmation email.
[1] You need to present a Microsoft token to play Minecraft online.