4 ms·
Don't trust any text that a malicious adversary could change. This is the email version of the Line of Death https://textslashplain.com/2017/01/14/the-line-of-d
by TakeBlaster16 4y ago
Don't trust any text that a malicious adversary could change. This is the email version of the Line of Death https://textslashplain.com/2017/01/14/the-line-of-death/ https://textslashplain.com/2017/01/14/the-line-of-death/
- __derek__ 4y agoI'd never seen that Line of Death article, but it seems like a useful heuristic. Thanks for sharing.
- mholt 4y agoYeah. That was also roughly the conclusion of my masters thesis: https://scholarsarchive.byu.edu/etd/7403/ https://scholarsarchive.byu.edu/etd/7403/ ("After HTTPS: Indicating Risk Instead of Security") -- we examined the flaws of current browser warnings and security messages and one of the big ones is that attackers can use those UIs against you. (Hence our proposed solutions all involved UI above the LoD.)
- EGreg 4y agoI once wrote an email to Steve Jobs, saying that operating systems like MacOS and iOS should have a secret phrase or icon that they show to you whenever they show a system-level security dialog. (And of course implement the same restrictions on screenshots of that dialog as they do for movies.) Because otherwise, an app can totally fake the interface of a security dialog. The only way you know, these days, is that password managers and cookie jars work with the "approved" sites, but they can simply show you a site that doesn't require those, and then fool you into entering your passwords! Steve never replied to me. And Apple never implemented it.
- Animats 4y agoSecure paths are a big issue. Windows used to have a "secure attention sequence", CNTL-ALT-DEL, which you had to push when you really wanted to talk to the security functions of the operating system. That stopped being mandatory in Windows 10, due to "customer confusion", although some enterprise configurations turn it back on. The concept comes from some DoD security projects from around 1980. Microsoft picked it up when Windows NT was being developed. Some DoD systems have also used a brightly colored screen border to indicate the degree of classification of the content. But that's too intrusive for consumer use. There are so many layers now that it's hard to provide a secure path that can't be compromised.
- dfox 4y agoSAK is controlled by group policy since Windows 2000 and is disabled by default on client SKUs that are not domain member. On the other hand all current iOS devices have some hardware level SAK-like gesture that directly confirms the user intent to the secure enclave. The overall UX design is such that it is not especially noticeable unless you know that there is such a thing.
- datavirtue 4y agoThe only company I have seen use the secret icon was a bank...and that was quite a few years ago. I forget which bank. Maybe Wells Fargo?
- dylan604 4y agoThey probably showed you the secret icon to indicate that they had opened a secret account in your name where the secret was kept from you
- sentientslug 4y agoIt was Bank of America actually, if we're talking about the same thing. Essentially you chose an avatar photo from a pool of several and then when you typed your username it would display that photo alongside your name to prove to you that you were logging into the real BofA site. I can't remember the exact name they used for this feature and Google is failing me. EDIT: BofA called it SiteKeys. And it looks like they were "useless" according to this article [0]. Someone even wrote a paper on it [1]. Seems several banks actually implemented this concept and then phased it out. [0] https://www.marketwatch.com/story/banks-find-online-security-images-offer-little-protection-2015-11-05 https://www.marketwatch.com/story/banks-find-online-security... [1] https://users.ece.cmu.edu/~lbauer/papers/2014/w2sp2014-securityimages.pdf https://users.ece.cmu.edu/~lbauer/papers/2014/w2sp2014-secur...
- mdaniel 4y ago> And it looks like they were "useless" according to this article [0]. Someone even wrote a paper on it [1]. Seems several banks actually implemented this concept and then phased it out. Okta still does that same trick on their login screens. Since I have several Okta logins, there's no way I would be able to remember which of the 9(?) icons matched with which domain, so I hear you about them being useless. I would be able to spot one of the "wrong" ones, as there are a class of those icons that I would never choose so ... security? :-/
- joveian 4y agoWorse than useless, even if you do check the image they can be MITMed and in no way indicate that you are actually on the site you think you are on (they only help against the lowest effort static phishing sites). US banks decided that they would rather address the perception of insecurity rather than improving security. It isn't their money if someone gets scammed. These days I think the best way to be sure you are on the correct site is to have the browser store at least the username/email used for a login and never login if the browser won't fill in that info (often saving the password is a good idea too depending on your situation). I've thought it would be helpful if browsers had a "site bookmark" feature that would show you are on a site you had previously labeled while visiting any page on the site, however I'm not aware of any browser actually doing that. At the OS level a phrase could potentially work since there isn't the same MITM risk, although graphics drivers are complex and there could easily be a bunch of ways the phrase could leak. I wish there was a second small and simple display with at least a couple of buttons for security purposes. Maybe rough for phones but larger devices could do that. Or even two of them, one for communication with the OS and one for accessing credentials. The second could be removable for use with multiple devices. Of course, this comes with accessibility challenges that need to be considered.
- gnicholas 4y agoThis is especially troublesome when you upgrade your OS and all of a sudden a bunch of applications are asking for permissions, with a different UI than you're used to. Even as a seasoned MacOS user (back to System 3!), I can't be sure that the UI I'm seeing is legit.
- trasz 4y agoI wonder if you could do that with a simple LED to indicate the secure mode?
- SilasX 4y agoHeh, I did a version of this as the attacker in early Second Life. In SL, you can create objects and have them speak (via the onscreen text chat window). You were allowed to give them any name, so I would name them after another player, letting me "throw my voice" and impersonate them. The devs apparently realized this problem early on, and their fix was: objects speak with green text, human players speak with white text. But this isn't disclosed anywhere, and there weren't many speaking objects at the time. So my workaround was to name an object after another player, wait for them to go afk, and then have the object say, "Hey guys, guys, check this out! I can make my text green! Woo hoo!" And then say all the malicious stuff I wanted them to say.