Skip to content

Comment on This is what Apple should tell you when you lose your iPhone

Comments

Unfortunately, I think a ton of people today still would not know the difference between a "green URL" and an unencrypted URL, or the fact that "find-iphone-location.com" is phishy.

I used to work at a large, competent tech company whose 401k plan was managed on a URL similar to "accessmy401k.com" -- it seemed similarly phishy to me but apparently enough people thought it was a good idea that this financial institution decided to make it their online portal to actual 401ks. I often see my less savvy friends going to places like "cheap-christmas-lights.net" when they want cheap Christmas lights.

I appreciate what the big browsers do when it comes to showing secure connections and highlighting the domain in certain cases, which is pretty much as far as we allow them to go in order to stay in control of our own browsing experiences, but part of me wishes it were a little bit more explicit. There are for sure potential drawbacks... when my Mom said she was booking tickets on "CheapOAir.com" I immediately thought it was a scammy site, but it's actually legit. But a browser (especially a browser on an iPhone?) should be able to see you're at "find-iphone-location.com" and maybe just assist the user a little bit by saying "Hey, just so you know, this is not a legitimate Apple/iPhone service" automatically.

Browsers do have mechanisms for filtering out known phishing (or malware) sites (e.g. Google's Safe Browsing (used by Chrome, Firefox and (IIRC) Safari), Microsoft's SmartScreen). Guessing based on the domain (without having any actual phishing reports or something like that) would probably lead to tons of false positives, which would both annoy users and desensitize them, so most people would click through the warning.

EV certificates can be a solution for some cases - knowing that "Apple, Inc. [US]" is actually operating the site you're looking at is worth something - but it isn't particularly meaningful in other cases - knowing that "CheapOAir, Ltd. [US]" actually operates "CheapOAir.com" doesn't mean much, they could still scam you.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.