3 ms·
Yes, that's true. But for people who don't notice changes there isn't much help anyways. Even much more primitive phishing will still work on them (just think
by bd 12y ago
Yes, that's true. But for people who don't notice changes there isn't much help anyways.
Even much more primitive phishing will still work on them (just think about those "you have virus / clean your computer" ads from past, with images looking like Windows pop-ups, or remember how those "Nigerian prince" scams intentionally use broken English to selectively address more gullible folks).
These new proposed security measures will not help those people much, they can still be phished from within browser tab content rectangle.
Instead these changes will just basically kill whole class of web applications for a benefit of small subset of population phishable enough with fullscreen attacks but immune to content rectangle attacks.
-----
BTW recent Lenovo Superfish fiasco has shown us that in fact you can't even trust native browser security UI elements. Those real UI green locks on https pages can be as misleading as those JS/HTML generated ones.
I would much more prefer browsers to secure me from known rogue certificates attacks than from hypothetical hard-to-pull-off fullscreen phishing attacks.