Phishing Sites Going HTTPS

Talk about internet security, computer security, personal security, your social security number...
Post Reply
barbaz
Senior Member
Posts: 10847
Joined: Sat Aug 03, 2013 5:45 pm

Phishing Sites Going HTTPS

Post by barbaz »

Don't use HTTPS alone to tell whether the site you're on is legit or not.
https://www.thesslstore.com/blog/lets-encrypt-phishing/

(mozillaZine: http://forums.mozillazine.org/viewtopic ... &t=3030652)
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Phishing Sites Going HTTPS

Post by Thrawn »

So there is actually a point to Extended Validation now...although it's still rather a rip-off.

Should we consider it a positive thing that phishing sites are now letting themselves be recorded in a public ledger where they can be spotted and put on browser blacklists?
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
barbaz
Senior Member
Posts: 10847
Joined: Sat Aug 03, 2013 5:45 pm

Re: Phishing Sites Going HTTPS

Post by barbaz »

Thrawn wrote:Should we consider it a positive thing that phishing sites are now letting themselves be recorded in a public ledger where they can be spotted and put on browser blacklists?
This would make it possible to block some phishing sites before they go live, wouldn't it?

Doesn't sound like a bad thing to me.
*Always* check the changelogs BEFORE updating that important software!
-
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: Phishing Sites Going HTTPS

Post by Thrawn »

Seems to me that with the right setup, either phishers could be caught before they launch (or, at least, launch with HTTPS), or else they'd give up on Let's Encrypt - which would also be a win.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0
Post Reply