Hacker News new | ask | show | jobs
by docmars 3 days ago
Then maybe the best course of action is Google adding a warning before enabling certain settings that help normies avoid these attacks.

Along the lines of "Are you being asked to do this by someone else? Be cautious, as your device could become compromised."

2 comments

Nobody reads the warnings and getting to use ADB on a phone is already a quest of epic proportions, soon to become the next Monkey Island sequel.
I totally agree they're easy to dismiss and start to feel cumbersome, but if "protecting users" is their actual motive (I doubt it), this would be a reasonable way to handle it while giving power users the flexibility they want, and that there's high demand for.
Log in to Facebook.com and hit developer console. Can't totally idiot proof it, but people do read enough warnings if you yell loud enough. Which puts it on them.
its ridiculous how many people will ignore the warnings and relay the security challenge/solution to the attacker.

"we will never ask for this over the phone" takes second place to:

"we will send/save you money/time if you make it convenient"

dress it up to taste like developer needs, and you can hook the newbies.

> "we will never ask for this over the phone" takes second place to:

Doesn't help that the banks then do, in fact, call you, and ask for this over the phone.

those banks that do that are grooming customers for failure, they create a workflow that is close to an attack.

in my region AT&T has a very explicit statement not to reveal MFA codes to anyone who asks, is not part of thier system to do that.

there is 1 bank in my area that does voice call relay over the phone, the others keep it 10 fingers relayed from phone to authentication form.

guess who has the most problems with account compromise, and fraud claims? yes, that one bank. it has a phishing vector in its system.

Half the issue is, people need to acquire the same wisdom about cybersecurity hygiene as they do looking both ways before crossing the street, but even that's too much to ask for some people. They just don't do it.

At some point, it has to become the responsibility of the potential victim, if liability is such a concern from big tech companies.