The Inquirer-Home

Mozilla expert warns of tab napping

Beware the tabs that bite and the claws that rend
Wed May 26 2010, 13:30

AN INSECURITY EXPERT on Mozilla's Firefox web browser team has warned about a form of phishing attack dubbed 'tab napping'.

Aza Raskin said that while traditional phishing relies on getting users to click through on a URL and reveal their user credentials it is now well known that only the terminally dim fall for it.

Tab napping works on the user's assumption that a tabbed web page stays the same when other Internet services are being accessed.

Raskin said that if a fake page 'updates' when the user isn't looking, when they return to the tab they will simply presume they left a web page open, and log in as normal.

Whenever you log into a website, regardless of whether or not you have tabs open in the browser, you should check the URL to make sure it is using a secure https:// address. "If the URL doesn't look right, or there's no padlock, close the tab, open a new one and enter the URL again," he said.

There's more here. µ

 

 

Share this:

Comments
Get rid of tabs with Tab Killer extension.

I don't see why anyone wants their screen space reduced by the tab bar. And don't try to tell me you *need* dozens of tabs open when it's beyond human capacity to recall more than 8 or 9. -- But maybe you're not human; I try not to assume facts not in evidence. -- Anyhoo, since so far as known, this exploits only tabs not separate windows, again turns out that my inclinations keep me safe from future problems.

@Organthruster: does say it's a demonstration, so while your points are correct, there's no evidence of Apple types actually falling for it.

posted by : bigger_luddite, 26 May 2010 Complain about this comment
Fruit flavoured pheesh

Well fuck me backwards with a donkey's dangler if the video in the linked article shows an APPLE user being duped! Didn't I read somewhere that Macs were super secure and comparatively immune to attacks from internet ne'er-do-wells?

Oh yeah, I did, every-fucking-where on the web, by moron fruit-lickers not capable of understanding that the likelihood of getting shafted by fraudsters is directly linked to the idiocy of the user and not to whatever operating system he/she happens to be using at the time.

Modern phishing techniques to which Apple users are just as vulnerable as Windows users are a far, far bigger threat to the black ink in your bank account than some half-assed fucking virus or worm. But keep buying those Macs and keeping thinking you're safe because we're having a great time laughing at you behind your back.

posted by : Hieronymus P. Organthruster, 26 May 2010 Complain about this comment
@Just me

Perhaps it's more a play on "kid"napping than a typo.

posted by : Les, 26 May 2010 Complain about this comment
was it snorring?

napping = sleeping
nabbing ~= grabbing/taking over

so, since the article title says "napping", was the tab snoring loudly or what?

/lol@typo :p

posted by : Just me, 26 May 2010 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?