Article 78CJM A Rant About Phishing: It's Not the User's Fault (and Not DNS Either)

A Rant About Phishing: It's Not the User's Fault (and Not DNS Either)

by
jelizondo
from SoylentNews on (#78CJM)

owl writes:

https://maurycyz.com/misc/domains/

"For safety, don't click suspicious links"

Meanwhile, most organization's login flow redirects through:

Neither the username, password nor 2FA prompts are hosted on the company's own domain. Combine that with token expiration triggering random authetication pop-ups, it becomes nearly impossible to notice phishing... because the real thing looks identical to a scam:

All an attacker has to do is write a website with a password box and the company logo. The URL doesn't matter because users have learned to ignore it.

Original Submission

Read more of this story at SoylentNews.

External Content
Source RSS or Atom Feed
Feed Location https://soylentnews.org/index.rss
Feed Title SoylentNews
Feed Link https://soylentnews.org/
Feed Copyright Copyright 2014, SoylentNews
Reply 0 comments