Hacker News new | ask | show | jobs
by ktta 2818 days ago
https://gmail.com.inbox-redirect.pro

This will seem like a valid website, especially if the phishing site is done well. Not just non-technical users, I'd wager some tech familiar users would be fooled too.

The focus always being on the lock icon might not always cover it.

Safari will prevent this though.

1 comments

Isn't that why browsers visually distinguish the TLD and the part before it from the rest of the URL?