You are viewing a single comment's thread from:

RE: The What and Why of Phishing, and How to Avoid It

in #security8 years ago

That chrome-extension phish is a really nasty one and was probably super easy to do... chrome should totally be adding some builtin protection for things like that because it's particularly insidious. They should probably have a CA and associated cert generated by the browser in-memory on each startup to sign all local pages which will display a special padlock indicator so you at least have a visual prompt for when you're not on your actual settings pages.

Or something more sensible.

Sort:  

Agreed, thankfully LastPass has taken some steps to make it harder to pull off.