Skip to content
Tech News
← Back to articles

Web Security is Too Hard

read original more articles
Why This Matters

This article highlights the increasing sophistication of phishing attacks targeting even tech-savvy users, emphasizing the importance of robust security practices and vigilant awareness. It underscores the need for companies to implement stronger security measures and user protections to prevent credential theft and fraud in an era where digital deception is becoming more convincing.

Key Takeaways

It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare.

Neat! I clicked through to the site and there it is:

And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it!

Since I’m already a long-time Cloudflare user, I just need to sign in. That makes sense, how else will they bind the handle to my account?

Easy peasy. I’m in. Looks like there’s just one more step, I gotta authorize the new feature?

But wait a sec!

This looks exactly like one of those Consent Phishing attacks that have been so popular over the last few years!

And wait, why is the entry point on cloudflare.pay , a site that doesn’t already have my credentials, rather than something within the cloudflare.com domain which does (e.g. cloudflare.com/pay )? There is no inherent technical relationship between a .com domain and a .pay domain. Domain names under the .pay sTLD are available to anyone with $20 (unlike, e.g. .bank which requires more vetting), so there’s nothing that would stop me from registering my own cloudflarepayments.pay domain name in just a few minutes.

And why doesn’t Cloudflare’s permission site recognize its own company’s feature? And that green checkmark looks suspicious as heck– an attacker could probably just shove that emoji inside their misleading display name, the same way that folks trying to phish Microsoft email accounts use misleading app names and icons:

... continue reading