8 ms·
new tool for phishing. perfect.
by dododo 13y ago
new tool for phishing. perfect.
- patrickaljord 13y agoI guess that's the negativity Larry Page was talking about yesterday, sad indeed.
- bvdbijl 13y agoYeah. There are so many positive possibilities yet a large group of people still choose to focus on the negative side. I hope this can change one day
- 3825 13y agoJust like short sellers, we need these naysayers to keep us grounded. :) Yes, I choose to see the positive possibilities and the opportunities that show up thanks to our beloved naysayers.
- crdoconnor 13y agoSo many possibilities? There is nothing here that couldn't be achieved by having the user click on a link. And he's right, it does make phishing easier.
- dragonwriter 13y ago> So many possibilities? There is nothing here that couldn't be achieved by having the user click on a link. Because its machine parseable, it makes a lot of presentation options available that aren't available when you rely on a standard hyperlink without a data format with a standardized identification of the requested action. > And he's right, it does make phishing easier. Well, that depends on what the requirements are to have the client present the actions from the schemas: the current Google requirements, I would say, do not make phishing easier. You must register with Google for the schemas in the email you send to be recognized in Google products (e.g., Gmail) [1], and the registration is per-set-of-emails, and fairly specific as to the content, and appears to be manually reviewed [2]. [1] https://developers.google.com/gmail/schemas/registering-with-google https://developers.google.com/gmail/schemas/registering-with... [2] https://docs.google.com/forms/d/1PA-vjjk3yJF7MLPOVKbIz3MBfhyma2obS8NIZ0JYx8I/viewform?pli=1 https://docs.google.com/forms/d/1PA-vjjk3yJF7MLPOVKbIz3MBfhy...
- imissmyjuno 13y ago>Because its machine parseable, it makes a lot of presentation options available that aren't available when you rely on a standard hyperlink without a data format with a standardized identification of the requested action. You're right: this addition turns email into a data or event queue of sorts with standardized actions that can be performed on it. I like it. Given that email is one of the few non vendor-locked communication technologies we have and we already have a lot of infrastructure to deliver it reliably, this seems a promising evolution path. I'd like to see something similar for IM: currently SMS is the only open standard for instant messaging, and any other option locks you into either a platform or a specific client, which the other person will probably not use.
- dragonwriter 13y ago> currently SMS is the only open standard for instant messaging XMPP is an open standard (through IETF RFCs and related standards) for messaging and presence whose motivating use case was instant messaging: http://en.wikipedia.org/wiki/XMPP http://en.wikipedia.org/wiki/XMPP
- imissmyjuno 13y agoRight. My comment is more on the adoption rather than availability of open standards.
- pjscott 13y agoXMPP is also used, behind the scenes, with Google Chat and Facebook Chat. It has a fair amount of adoption; you just don't really hear about it much.
- deleted 13y ago[deleted]
- _pmf_ 13y ago> This thread is hilarious. Keep your heads in the sand. Does everyone need to get excited for features that existed in Outlook ca. 2000 A.D. just because they are wrapped in a shiny Web 2.0 veneer?
- icebraining 13y agoIt did? Using an open format? I've never heard of that. Do you know the name of the feature?
- sigzero 13y agoYou keep harping on the "open format". So what? That doesn't change any of the talking points here.
- deleted 13y ago[deleted]
- icebraining 13y agoBeing an open format that can be implemented by any other mail client is, in my opinion, an important part of the feature, especially for those of us who don't use Gmail.
- _pmf_ 13y ago> It did? Using an open format? As much as Web 2.0 enthusiasts loathe the fact, Microsoft actually invented XMLHTTPRequest. See http://stackoverflow.com/a/12067786/112125 http://stackoverflow.com/a/12067786/112125
- dubcanada 13y agoWhat does that have to do with anything? Netscape invented Javascript. Oh look another random point that seems to provide nothing to the conversation. I think it's pretty well aware Microsoft (or should I say a select few working on IE at Microsoft) invented "AJAX"
- deleted 13y ago[deleted]
- TeMPOraL 13y agoNo. It's more that there are so many positive possibilities yet a large group of people still choose to exploit them to make themselves money by harming others and end up breaking things for everyone else. The whole history of modern operating systems and the Web is the example of that. Think of all the amazing and useful things that could be (and have been) done had there was no Data Execution Prevention or Same-Origin Policy or any other limit introduced because of security.
- tonyedgecombe 13y agoI don't think so, it seems an obvious concern to me.
- sigmavirus24 13y agoBecause security really is never a good reason to be skeptical and skepticism, no matter how valid, is just a cloak for hating on Google. I love GMail and lots of Google's products. I even like that this feature will be limited to companies that register with Google. It doesn't change the fact that those partners could be broken into and used to send out malicious emails. Also, please don't try to insinuate that I'm against the feature. I'm not. I can stop using GMail if I ever want to. I just think everyone should consider their own security and decide how valuable it is to them based on reasonable possibilities.
- rdl 13y agoHopefully Google will get S/MIME built in.
- treahauet 13y agoHow many spam/phising emails do you actually get in your Gmail? And of those, how many are DKIM/SPF signed?
- Colliwinks 13y agoThe people targeted by phishing attacks have no idea what those terms mean.
- icebraining 13y agoIt doesn't matter. Gmail does, and they block the feature for any sender which doesn't sign their emails. https://developers.google.com/gmail/schemas/actions/securing-actions https://developers.google.com/gmail/schemas/actions/securing...
- eps 13y agoI routinely send emails through a mail server that doesn't sign them and they are delivered to Gmail recipients just fine.
- icebraining 13y agoSorry, I edited the post. They block that feature, not the whole mail.
- crucialfelix 13y agoa company that inserts this type of response hook in their emails needs to register with google. the response interface looks clearly separated—its not in the body of the email—so there is no way that a phisher could fake it. so it actually could help to SOLVE the phishing issue. especially if other mail providers sign on.