Hacker News new | ask | show | jobs
by ldoughty 601 days ago
I would argue you can't win either way...

If you use real link, your training people to trust what the text says is actually where you're going to go..

By making people do extra work to see where click here goes you might actually be training to protect themselves... Of course that doesn't work when Outlook goes and wraps the whole thing in a safety URL you can't see past... Or with shorteners.. but in all of those cases, I know to be more cautious.

2 comments

If you control the link text and destination, you probably want the user to trust it.

If you're designing software that displays links provided by untrusted third parties, that's beyond the scope of what this article is addressing.

> Outlook goes and wraps the whole thing in a safety URL you can't see past

That bullshit really needs to end. It's making people more likely to fall for phishing scams when they can't figure out the URL.