3 ms·
Sites that involve credit cards or banking are in a whole different category. For those I think the best advice is to only use https bookmarks. In that vein, h
by rabidsnail 14y ago
Sites that involve credit cards or banking are in a whole different category. For those I think the best advice is to only use https bookmarks.
In that vein, here's an idea for a browser feature. When someone enters something into a form that looks like a credit card number, bank account number, or bank routing number, black out the entire browser (including the url bar) and require them to type in the domain they think they're submitting to. If they get it wrong they can't submit the form (at least for a few minutes).
- tedunangst 14y agoYes, let's cripple online shopping.
- rabidsnail 14y agoOnly for sites that you don't already have an account on, and which don't use a paypal-like service. Although since there are consumer protections on credit cards, it might make sense just to warn on bank account and routing numbers.
- untog 14y agoOnly for sites that you don't already have an account on, and which don't use a paypal-like service. How is a browser supposed to detect either?
- rabidsnail 14y agoIt doesn't have to. In both of those cases you're not entering your credit card number.
- Evbn 14y agoCookies to indicate previously visited sites.
- FaceKicker 14y agoCouldn't phishers just start having their fake forms send the current form content via ajax every time a new character is typed, rather than only on submit?
- aptwebapps 14y agoIf I was a phisher, or similar ilk, I'd be doing this already.