4 ms·
I’m usually not interested in social engineering which I think is boring stuff, but I think that (1) this is a weakness on my part as a developer with something
by avg_dev 4y ago
I’m usually not interested in social engineering which I think is boring stuff, but I think that (1) this is a weakness on my part as a developer with something of a security focus, and (2) this is perhaps the perfect sweet spot of social engineering and programming.
It is an utterly fascinating takedown of the back button hijack. Totally unethical but also very eye-opening for me.
Is this kind of back button hijack and history rewriting still possible in modern browsers? Edit: this link leads me to believe this may still be possible: https://developer.mozilla.org/en-US/docs/Web/API/History https://developer.mozilla.org/en-US/docs/Web/API/History - would love a confirmation.
- tomcam 4y agoIs it “totally unethical” when published like this? (Not a security expert so I honestly don’t know the answer)
- avg_dev 4y agoi believe that is a fair question and i believe that ethics are personal and each individual must find/define their own ethics based on their own values and life experiences. here is where i am coming from: 1. the end user is on a google search engine results page (SERP) and sees the blog post author's website as one of the search results 2. the end user clicks the link to the blog post author's website 3. the end user is now on the blog post author's website 4. the end user hits the back button - i believe the end user has a reasonable expectation that they will be back on the google search engine results page... but *they are not*. they are on a mockup that looks like the google SERP but is in fact controlled by the blog post author. 5. the end user clicks on a "link" to a competitor's website - but the "link" is actually yet another mockup created and hosted by the blog post author. i believe this is highly unethical! they are fooling an unsuspecting end-user into thinking they are visiting a brand new site, but they most definitely are not doing so. ultimately, i think that google and other browser authors should remove the possibility for this sort of trickery. i do admire the blog post author for posting the social engineering/programming trickery while still viewing it as unethical. edit: at the bottom of the blog post the author links this previous HN comment which i find interesting: https://news.ycombinator.com/item?id=17826106 https://news.ycombinator.com/item?id=17826106 - and this one is as well https://news.ycombinator.com/item?id=17823886#17826206 https://news.ycombinator.com/item?id=17823886#17826206