from Hacker News

Behold, a password phishing site that can trick even savvy users

by incomplete on 3/21/22, 7:47 PM with 9 comments

  • by soared on 3/21/22, 8:25 PM

    Creating fake dialogue boxes and windows is nothing new, that has been around forever. Maybe using css to determine the os/browser and mimic each one’s style is the new concept. I’ll believe it when someone can show me a webpage that proves it live.
  • by tcbawo on 3/21/22, 8:42 PM

    This is another reason I use a password manager. I will rarely ever manually type or paste my password anywhere.
  • by Zuider on 3/21/22, 11:56 PM

    The article does provide a test to distinguish authentic login pages from ones spoofed via CSS:

    >Genuine OAuth or payment windows are in fact separate browser instances that are distinct from the primary page. That means a user can resize them and move them anywhere on the monitor, including outside the primary window.

  • by riidom on 3/22/22, 12:59 AM

    Using an uncommon browser with non-default settings on an uncommon OS makes me a good target for finger-printing. Seems this kind of stuff is the upside now, where I would easily spot the differences (probably, would also like to interact with a working example).
  • by titaniumtown on 3/21/22, 9:00 PM

    I'll definitely see the difference with my gtk theme lol