It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare.
Neat! I clicked through to the site and there it is:
And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it!
Since I’m already a long-time Cloudflare user, I just need to sign in. That makes sense, how else will they bind the handle to my account?
Easy peasy. I’m in. Looks like there’s just one more step, I gotta authorize the new feature?
But wait a sec!
This looks exactly like one of those Consent Phishing attacks that have been so popular over the last few years!
And wait, why is the entry point on cloudflare.pay , a site that doesn’t already have my credentials, rather than something within the cloudflare.com domain which does (e.g. cloudflare.com/pay )? There is no inherent technical relationship between a .com domain and a .pay domain. Domain names under the .pay sTLD are available to anyone with $20 (unlike, e.g. .bank which requires more vetting), so there’s nothing that would stop me from registering my own cloudflarepayments.pay domain name in just a few minutes.
And why doesn’t Cloudflare’s permission site recognize its own company’s feature? And that green checkmark looks suspicious as heck– an attacker could probably just shove that emoji inside their misleading display name, the same way that folks trying to phish Microsoft email accounts use misleading app names and icons:
... continue reading