Skip to content

Comment on Human study on AI spear phishing campaignsparent

Comments

I blame Microsoft. As a consumer OS its default stance should be no, the user does not intend to grant god permissions to this embedded or external script when they clicked it. Instead the user should have been challenged with a dialog, do you want to install this App and then execute?

To which everybody will click yes. They have been conditioned by too much half-baked crap out there that requires it and the need to go on with their lives instead of having tp start investigating things they anyway don't have a clue about (and don't want to, not being IT folks).

This is why you don't daily drive a local admin and leave UAC enabled. If you were using an unprivileged account, you'd be getting UAC prompts.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.