Pangram verdict · v3.3
We believe that this entire text is human-written.
AI likelihood · overall
HumanArticle text · 564 words · 1 segments analyzed
It started innocently enough. I saw a tweet about a new product offering from one of my favorite companies, Cloudflare. Neat! I clicked through to the site and there it is: And huzzah!, my preferred handle, @ericlaw is still available. I’d better hurry to claim it before someone else gets it! Since I’m already a long-time Cloudflare user, I just need to sign in. That makes sense, how else will they bind the handle to my account? Easy peasy. I’m in. Looks like there’s just one more step, I gotta authorize the new feature: But wait a sec! This looks exactly like one of those Consent Phishing attacks that have been so popular over the last few years. And wait, why is the entry point on cloudflare.pay, a site that doesn’t have my credentials, rather than something within the cloudflare.com domain which does? There is no inherent technical relationship between a .com domain and a .pay domain. The .pay TLD is available for anybody with $20 to their name (unlike, e.g. .bank which requires more vetting), and there’s nothing that would stop me from getting cloudflarepayments.pay in just a few minutes. Why doesn’t Cloudflare’s permission site recognize its own company’s feature? And that green checkmark looks suspicious as heck– an attacker could probably just shove that emoji inside their misleading display name, the same way that folks trying to phish Microsoft email accounts use misleading app names and icons. Fake Outlook OAuth phishing request The guys at Cloudflare are geniuses who know their stuff. This has got to be an attack. It’s a clever one — I was feeling such a sense of urgency because I wanted to “win” the race to get my desired handle. Very very clever. Unfortunately, the Cloudflare permission page doesn’t follow best practices, so there’s no “Report suspicious request” link. Let me go back to my Cloudflare dashboard and try to get to the Wallet that way. Hrm. It’s not there. Now, it purports to be a “new” feature, so maybe the docs aren’t updated yet. Let’s ask in chat. Oh, wow. It really is an attack! Let’s report the phish right away! A few minutes later… womp womp… Oh dear. After a few minutes of further frantic searching, it turns out that this is, in fact, a legitimate new Cloudflare product and a legitimate site, despite giving every indication of being a clever phishing attack. It further turns out that that suspicious green checkmark is not part of the app’s untrustworthy display name but instead a (poorly placed) security UI element that a user is expected to hover over to get the security details: When legitimate websites sometimes act very very phishy, consider how hard it must be for URL Reputation services like Microsoft SmartScreen and Google SafeBrowsing to block malicious sites without false positives as millions of new sites are added to the web every week. Web Developers: Follow every best practice. I’m begging you. Users: Try to stay safe out there. Think before you click, and if all else fails, wait. Security Geeks: Never blame the victim– they’ve got an impossible job. -Eric Impatient optimist. Dad. Author/speaker. Created Fiddler & SlickRun. PM @ Microsoft 2001-2012, and 2018-, working on Office, IE, and Edge. Now working on Microsoft Defender. My words are my own, I do not speak for any other entity. View more posts Post navigation