Mysk
Mysk
  • Видео 59
  • Просмотров 317 202
iPhone users in the EU: This is why you should stop using Safari, and why Brave is a better choice
To comply with the DMA regulations in the EU, Apple has introduced a new URI scheme to allow installing alternative marketplace apps from the browser. The way Safari has implemented the new scheme is insecure and can expose users to tracking.
At the moment, Safari invokes the new scheme "marketplace-kit" from any website. This results in sending a unique device identifier called client_id to the registered marketplace servers. A malicious alternative marketplace can use this trick to track users across different websites.
This video shows how invoking this scheme from different websites results in sending a unique device identifier to the registered marketplace. On the other hand, we demons...
Просмотров: 1 537

Видео

I have failed to install the AltStore app for iOS TWICE, this is the second attempt 😩
Просмотров 4,4 тыс.2 месяца назад
In the first attempt I wasted €1.79 when installing the AltStore app for iOS. I used Brave and I didn't know that only Safari supported that. Now I tried again with Safari, and I wasted €1.79 again. altstore.io
Cybersecurity: Can a Tesla stop phishing and social engineering attacks?
Просмотров 24 тыс.3 месяца назад
Phishing and social engineering attacks are not uncommon. However, an attacker who gets a hold of leaked or stolen credentials shouldn't have it all. This video shows you that Tesla doesn't protect its users, or vehicles, against stolen credentials. Unfortunately, an attacker who somehow gets the credentials of a vehicle's Tesla account can take control of the car and drive away with it. The ma...
For EU users: This is what happens to your PWAs after you upgrade to iOS 17.4
Просмотров 2,3 тыс.3 месяца назад
Apple has officially announced that Progressive Web Apps, or PWAs, will no longer be supported in the EU starting iOS 17.4. This video shows what happens to already installed PWAs when opened for the first time after upgrading to iOS 17.4 RC. This only affects iOS users. iPadOS will continue to support PWAs, for now. Let us know what you think about this behavior in the comments. We'll be happy...
Privacy: I requested a copy of my data from Apple, this is what the The App Store knows about me
Просмотров 3,2 тыс.4 месяца назад
The App Store is the only way to install app on your iPhone*. The App Store records every activity or impression you make while exploring apps in the app. Our previous work showed that there's no way to stop the app from collecting usage data and send it to Apple in near real-time. In this video, we show an example of what the App Store, or Apple, knows about you. We used a post by the App Stor...
iOS 17.4 beta 3: PWAs still don't work in the EU
Просмотров 1,2 тыс.4 месяца назад
The latest iOS 17.4 beta 3 still doesn't support PWAs in the EU. A change Apple may have introduced to comply with DMA regulations. This video also shows that multiple "bookmarks" share the same session as Safari, and clearing Safari data doesn't clear the session. Its state remains preserved. It is unclear whether Apple will remove PWA support in the final release of iOS 17.4 for EU users. UPD...
PWA support in the EU: iOS 17.3 vs iOS 17.4 beta 2 (side by side)
Просмотров 13 тыс.4 месяца назад
The latest iOS 17.4 beta 2 has disabled PWAs entirely in the EU. This video shows how PWA behaves on iOS 17.3 and 17.4 beta 2 side by side. iOS 17.3 opens the PWA full-screen and the app feels as an iOS app. On the other hand, iOS 17.4 beta 2 opens the PWA as a normal browser session. Because iOS 17.4 beta 2 does not support PWA, the PWA opens as a normal browser window with the search bar visi...
iOS 17.4 beta: Progressive Web Apps (PWAs) are entirely disabled in the EU
Просмотров 4 тыс.4 месяца назад
The latest iOS 17.4 beta ( 21E5184k) has disabled PWAs entirely in the EU. To comply with the #DMA rules, this beta has introduced a prompt to select a default browser when Safari is opened for the first time. It seems that this beta aims to treat Safari and third-party browsers equally. Previously, PWAs were only installable from Safari and then were run in a Safari worker service, regardless ...
#Privacy: Facebook, TikTok, and Other Apps Use Push Notifications to Send Data about Your iPhone
Просмотров 10 тыс.5 месяцев назад
This video sheds light on a growing practice among data-hungry apps where they use the background execution time allocated by iOS for the purpose of customizing notifications to send app analytics. Many apps do this. We just picked a few for this demo. Apps on iOS don't run in the background. iOS doesn't allow apps to run in the background for a variety of reasons, mostly related to privacy and...
Privacy: X for iOS keeps sending crash reports even if you opt out in the settings
Просмотров 6035 месяцев назад
The X app for iOS has an option in the settings for sharing crash reports with X. Crash reports collect information about failures that happen while the app is in use. While crash reports help developers improve their apps, they might include private information that you don't like to share with X. X provides an option to disable sending crash reports. This video shows that turning the setting ...
Privacy: This is what happens when you insert an unlocked SIM card into a locked iPhone (iOS 17.2)
Просмотров 2 тыс.5 месяцев назад
When inserting an unlocked SIM card into a locked iPhone, these actions take place in the background while the iPhone is still locked: - The iPhone accepts the SIM card and connects to the internet 😳 - Apple immediately adds the phone number of the SIM card to the Apple ID of the iPhone owner 😲 - Apple accepts the new phone number as a username to sign in with the Apple ID of the iPhone owner 😱...
Privacy: Upgrade to iOS 17.1 to prevent your iPhone from being tracked across Wi-Fi networks
Просмотров 5 тыс.7 месяцев назад
Privacy: Upgrade to iOS 17.1 to prevent your iPhone from being tracked across Wi-Fi networks
#Privacy: iOS 17 turns iCloud Keychain on without permission
Просмотров 5648 месяцев назад
#Privacy: iOS 17 turns iCloud Keychain on without permission
Privacy: iOS 16.5.1 still bypasses the VPN connection, also in Lockdown Mode
Просмотров 2,6 тыс.11 месяцев назад
Privacy: iOS 16.5.1 still bypasses the VPN connection, also in Lockdown Mode
macOS Sonoma new feature: click on desktop wallpaper to show desktop items
Просмотров 9 тыс.Год назад
macOS Sonoma new feature: click on desktop wallpaper to show desktop items
Privacy: photos sent through LinkedIn DM might expose your precise location, and more
Просмотров 333Год назад
Privacy: photos sent through LinkedIn DM might expose your precise location, and more
Why you shouldn't let Google Authenticator sync your accounts
Просмотров 8 тыс.Год назад
Why you shouldn't let Google Authenticator sync your accounts
Privacy: Microsoft Authenticator sends analytics even before accepting the privacy statement
Просмотров 1,8 тыс.Год назад
Privacy: Microsoft Authenticator sends analytics even before accepting the privacy statement
Twitter now prompts new users to follow Elon Musk
Просмотров 533Год назад
Twitter now prompts new users to follow Elon Musk
iOS 16: the App Store on your iPhone is watching your every move
Просмотров 1,4 тыс.Год назад
iOS 16: the App Store on your iPhone is watching your every move
The App Store on your iPhone is watching your every move
Просмотров 17 тыс.Год назад
The App Store on your iPhone is watching your every move
Privacy: if you sync your contacts with LinkedIn, this video is for you
Просмотров 1,2 тыс.Год назад
Privacy: if you sync your contacts with LinkedIn, this video is for you
Browser privacy: DuckDuckGo for Mac got much better at dismissing cookie pop-ups
Просмотров 751Год назад
Browser privacy: DuckDuckGo for Mac got much better at dismissing cookie pop-ups
iOS 16 bypasses VPN when connecting to Apple services
Просмотров 1,2 тыс.Год назад
iOS 16 bypasses VPN when connecting to Apple services
Browser privacy: DuckDuckGo for Mac automatically dismisses cookie pop-ups
Просмотров 346Год назад
Browser privacy: DuckDuckGo for Mac automatically dismisses cookie pop-ups
Privacy: Safari enables apps to track users through associated links, iOS 16 macOS 12
Просмотров 351Год назад
Privacy: Safari enables apps to track users through associated links, iOS 16 macOS 12
Android security: How to stop browsers from sharing motion sensors data with websites
Просмотров 768Год назад
Android security: How to stop browsers from sharing motion sensors data with websites
Access to motion sensors: A brief comparison between a few Android 13 and iOS 15 browsers
Просмотров 230Год назад
Access to motion sensors: A brief comparison between a few Android 13 and iOS 15 browsers
The new clipboard privacy feature in iOS 16 and iPadOS 16
Просмотров 8092 года назад
The new clipboard privacy feature in iOS 16 and iPadOS 16
Privacy: Here is how you find iOS apps that monitor accelerometer events, such as Facebook
Просмотров 18 тыс.2 года назад
Privacy: Here is how you find iOS apps that monitor accelerometer events, such as Facebook

Комментарии

  • @FromGamersToGamersLT
    @FromGamersToGamersLT 12 часов назад

    Well i tried everything. And it comed with error that is unable to install...

  • @bmtsp4568
    @bmtsp4568 21 день назад

    Logging failed not connected alstore server😅

  •  26 дней назад

    this synchronization problem still persists

  • @kide4796
    @kide4796 Месяц назад

    You have to go to the settings and there will be a message accept that and try it again and it will work then

  • @Boredom_Cure
    @Boredom_Cure Месяц назад

    Hahahahaha apple gets fucked

  • @reold
    @reold Месяц назад

    Imagine having spent months building such a robust PWA framework and then just removing it for no valid reason. From a developer stand point, duck apple

  • @techguy541
    @techguy541 Месяц назад

    What you have to do is got to purchase again and then enter ur email again and click continue. New link it works

  • @dogbreathmints
    @dogbreathmints Месяц назад

    I still can't believe nobody anywhere is talking about the fact that various individual websites STILL HAVE pop-ups or auto player ads or banners that you STILL GET on regular landing pages of many websites USING DUCK DUCK GO! Any way it's used-on android apps too. It... doesn't block individual webpage pop ups like FF Edge, Brave, extension options do. How is that private? Can't understand why nobody's talking about that anywhere! This is very informative yes and thoroughly but dealing only with back end info. I was looking for that info everywhere but can't find it yet.

  • @Naturnatu
    @Naturnatu Месяц назад

    same problem! I paid but I can't install :-(!!!

  • @thienthaichotchaicharin5626
    @thienthaichotchaicharin5626 Месяц назад

    to apple thankyou but no thankyou

  • @tdrg_
    @tdrg_ Месяц назад

    It’s not just Brave, it’s any other browser than Safari, because they can’t open MarketplaceKit. Mysk just likes Brave more 😂

  • @birn
    @birn 2 месяца назад

    Try bookmarking one of those sites, closing out all tabs, and then browse as normal until bookmarks "refresh" behind the scenes without being clicked.

  • @hl6903
    @hl6903 2 месяца назад

    What about Firefox

    • @mysk
      @mysk Месяц назад

      Firefox doesn't support the "marketplace-kit" URI scheme at the moment

    • @tdrg_
      @tdrg_ Месяц назад

      So it’s good

  • @mariogotkovski6609
    @mariogotkovski6609 2 месяца назад

    when you buy the product, you must allow it on the mobile but do not close the box that you download the first time. after you have allowed it on the mobile then go back to the same box as the first time and press download again and it will be installed as a normal app on your phone

    • @paulklundt9365
      @paulklundt9365 Месяц назад

      I made that steps but when i click the button after accepting it in the settings i get an error code that the app could not be installed. Do you know what i could do?

    • @OMNI_INFINITY
      @OMNI_INFINITY 16 дней назад

      @@paulklundt9365 *BOYCOTT Apple for assisting israel to attempt GENOCIDE!!!*

  •  2 месяца назад

    Same happening here

  • @TVart_foryourhome
    @TVart_foryourhome 2 месяца назад

    How do you fix this? Stuck in the same situation

    • @mysk
      @mysk 2 месяца назад

      Open a new browser tab and start over. When you enter the same email address, it will recognize that you have a subscription and will show a link to download the app again without entering your credit card details.

  • @valesow
    @valesow 2 месяца назад

    I clicked on remove developer and noe I cant even get the to ask for permission again

    • @poldeyyy6100
      @poldeyyy6100 Месяц назад

      Same any fix

    • @jymzyn79
      @jymzyn79 Месяц назад

      Do it again in a new tab. It worked for me.

  • @tdrg_
    @tdrg_ 2 месяца назад

    So you pay €1.5 and you can’t use the store?

    • @Naturnatu
      @Naturnatu Месяц назад

      exactly, at least for now :-(

    • @kide4796
      @kide4796 Месяц назад

      I can use it

  • @michalsykora9875
    @michalsykora9875 2 месяца назад

    Stuck right there too, frustrating. Looks like installation via PC is required.

    • @mysk
      @mysk 2 месяца назад

      No, you need to run all the steps on your iPhone.

    • @michalsykora9875
      @michalsykora9875 2 месяца назад

      I wish you were right… anyway, I only can try the PC Windows way now cos I closed that tab with the download button 😅 and I’m not willing to pay again. Good luck and let us know of youve managed it 👍

    • @michalsykora9875
      @michalsykora9875 2 месяца назад

      Got it, as you say on twitter, i was recognized after entering the email adress again and the download button responded this time 👌 tnx

    • @loopthecrook
      @loopthecrook 2 месяца назад

      @@michalsykora9875can you help me? I can’t download the damn thing 😅

    • @arthurmorgan6170
      @arthurmorgan6170 Месяц назад

      @@loopthecrook it's a bug with their servers, I can't install it either, 3 payments made with 3 different emails and still no app. There are two things 1 or it's a scam 2 or it's a bug with their servers

  • @user-pz2rp1iy7d
    @user-pz2rp1iy7d 2 месяца назад

    If you have a computer your best bet is installing AltServer and doing it that way. Might have to enable developer mode in privacy settings, but that’s what worked for me

  • @1vbAPiYk
    @1vbAPiYk 2 месяца назад

    Gotta love apple

  • @HACKTIONREPLAY
    @HACKTIONREPLAY 2 месяца назад

    So what's the statusquo now one month later, allowed or not ?

  • @McAlien
    @McAlien 2 месяца назад

    Ahora ya todos los saben. 😢😏🙄😅

  • @xoxkisaxox
    @xoxkisaxox 3 месяца назад

    Thank you, this has been driving me crazy and I couldn't figure out how to turn it off.

  • @jamesLG1
    @jamesLG1 3 месяца назад

    If SMS were used as the method of receiving OTP codes this attack would not work. Also, if the logged in Tesla app was generating the codes by alerting/offering code to the account holder when a login attempt was detected instead of an authenticator app would further close this loophole.

  • @hefwilliams5400
    @hefwilliams5400 3 месяца назад

    The One time code (OTP) should not work once the user has used it the first time, it should be exactly that - a one time code...

    • @mysk
      @mysk 3 месяца назад

      The first screen is the fake captive portal. The code wasn't entered on a Tesla website. The attacker took it from the captive portal and entered it in the app. It was only used once.

    • @jamesLG1
      @jamesLG1 3 месяца назад

      OTPs have an expiry time. The attacker just has to use the code before it expires. They might not always be able to do it in time depending on the length of credentials and the time the expiry clock started on the code

  • @joecarrillo1443
    @joecarrillo1443 3 месяца назад

    Tried adding a device yesterday. The car asked for my original key before the new device could be added

    • @mysk
      @mysk 3 месяца назад

      Can you say the software version your Tesla is running?

    • @hefwilliams5400
      @hefwilliams5400 3 месяца назад

      same for me

    • @mysk
      @mysk 3 месяца назад

      @@hefwilliams5400 Can you say the version of the app and Tesla firmware?

  • @nielagi5029
    @nielagi5029 3 месяца назад

    nice music

  • @abulka
    @abulka 3 месяца назад

    Didn’t apple backtrack on breaking pwa behaviour as long as you chose safari as the browser?

    • @mysk
      @mysk 3 месяца назад

      Yes!

  • @f_pie
    @f_pie 3 месяца назад

    This should be illegal

  • @frustyfrumpy9801
    @frustyfrumpy9801 3 месяца назад

    What happens if you install WhatsApp? That information is send to who's server?

  • @yeahbuddy92193911
    @yeahbuddy92193911 3 месяца назад

    So don't login to any Tesla public WiFi and you should be set. The bypassing PIN code had me a little shocked, I thought it was foolproof.

  • @ThatOneSnake
    @ThatOneSnake 3 месяца назад

    How does the evil twin network prompt Tesla to send the victim an MFA code?

    • @mysk
      @mysk 3 месяца назад

      Since the captive portal is under full control of the attacker, the attacker can be creative here. But for the sake of this demo, we showed a static 2FA prompt right after the email/password prompt. If the victim's account doesn't have 2FA, the attacker already has the email/password. If not, the 2FA prompt will do the job.

    • @ThatOneSnake
      @ThatOneSnake 3 месяца назад

      @@mysk Thanks for the response. I meant, how does Tesla know to send the victim a 2FA code if the website is fake and doesn't actually communicate with Tesla services? Or does it rely on the victim using an authenticator app?

    • @pinolero.
      @pinolero. 3 месяца назад

      @@ThatOneSnake It relies on the victim providing the code. The attacker is asking you for your 2FA code in order to proceed to connect to the bogus Wi-Fi network. Once the victim provides the code the attacker can then use it to login to your Tesla account.

    • @ThatOneSnake
      @ThatOneSnake 3 месяца назад

      @@pinolero. I get that, but how does the *victim* receive a 2FA code to input? Does the impostor page forward the username and password to the real Tesla page, promoting Tesla to send the Tesla owner a code?

    • @mysk
      @mysk 3 месяца назад

      @@ThatOneSnake It should go like this: the victim enters email/password on the fake captive portal ➡️ The attacker gets the email/password from the captive portal and enters them in the real Tesla app. Then, the Tesla app prompts for a 2FA code, so the attacker triggers the fake portal to prompt for a 2FA code. The victim enters the 2FA code ➡️ The attacker gets it and enters it in the real app and signs in. If the 2FA code is not valid, the attacker can prompt for a 2FA code again.

  • @M3NTALMAGIC
    @M3NTALMAGIC 3 месяца назад

    ULTRA WIDE BAND on phone

  • @M3NTALMAGIC
    @M3NTALMAGIC 3 месяца назад

    PIN TO DRIVE

    • @mysk
      @mysk 3 месяца назад

      Won't help. Check the pinned comment.

  • @sleepyforest_
    @sleepyforest_ 3 месяца назад

    You recommend brave over Firefox, the Main factor is privacy, I know firebox as plug-in you add a bit of layer for privacy and security

  • @Teqnyq
    @Teqnyq 3 месяца назад

    Well, it's a great tool for flipping Teslas.

  • @Danny-mz9br
    @Danny-mz9br 3 месяца назад

    It can be easier to improve, add option when you turning of PIN in app to prowodyr PIN before it can be done, and it’s hard to believe that this is not added, it lien basic

  • @tylwythteg
    @tylwythteg 3 месяца назад

    I'm wondering if physical mfa token implementation would help for Tesla token "key" reassignment. Im avoiding terms like passkey and key purposely to avoid confusion. If registered wouldn't it be more difficult to pull off this mitm? Of course then you can't lose your physical mfa token. Really a problem lol.

  • @omicron9012
    @omicron9012 3 месяца назад

    Apple decided to allow PWAs in the EU after all. It was a decision to allow PWAs. It was not a bug.

    • @HACKTIONREPLAY
      @HACKTIONREPLAY 2 месяца назад

      So what's the statusquo, allowed or not ?

    • @omicron9012
      @omicron9012 2 месяца назад

      @@HACKTIONREPLAY Yes, Apple backed away from disabling PWAs in the EU. So Yes it will be allowed after all!

  • @YourWizBlog
    @YourWizBlog 3 месяца назад

    I don't get the recommendation that tesla must make it mandatory to use the key card.... This is obviously a social engineering hack. You could just configure to use a pin code to start the tesla, that is built in already and then this attack won't work to drive the tesla. Also I get I notify when a card changes. Maybe it's a better recommendation to use a key card to add a new phone?

    • @mysk
      @mysk 3 месяца назад

      Yes, this is what was meant by the recommendations. To make it mandatory to scan the key card for a new key to be added. The PIN to Drive is useless as you can bypass it in the app. Refer to the pinned comment.

  • @Exau89
    @Exau89 3 месяца назад

    So, what about the part where the vehicle prompts you to tap the key card on the console to complete the phone key setup?

    • @mysk
      @mysk 3 месяца назад

      This prompt appears when you try to remove an already added key. You have to place the key card on the reader for a key to be removed.

    • @eugenes7799
      @eugenes7799 3 месяца назад

      ​@@mysk no. You need to tap a key card to add a phone.

    • @mysk
      @mysk 3 месяца назад

      @@eugenes7799 This is wrong. The demo above as well as the official response we got from Tesla confirm that a key card is not required to register a new phone key. It's only required if the GPS signal is too weak that both the smartphone and the Tesla vehicle cannot determine that they are physically close.

    • @Exau89
      @Exau89 3 месяца назад

      ​@mysk Adding a new phone as a key also requires the key card to be tapped. This might not be true for "previously" authenticated phones which could be the flaw you may have discovered. Try with a new phone (never used as a key before) and let us know!

    • @mysk
      @mysk 3 месяца назад

      @@Exau89 We tested with devices that have never been paired with the vehicle at all. Perhaps the key card is required when an account creates a phone key for the very first time. But this won't prevent this attack. Anyhow, Tesla's response denies this requirement entirely.

  • @stasoline
    @stasoline 3 месяца назад

    Choose your default browser, as long as they are all Safari!

  • @pinolero.
    @pinolero. 3 месяца назад

    I have been having issues when my MYP automatically connects to the super charger's Wi-Fi network when supercharging. It interrupts my viewing session and as such I disable Wi-Fi on the vehicle to force it to use the cellular network instead. Also, as a work-around if you have a hot spot option on your phone you could have the vehicle connect to your phone instead of a public network, thus avoiding this potential scenario.

  • @n2rj
    @n2rj 3 месяца назад

    I have unlimited 5G UW so I don’t use public WiFi now. Great reason not to.

  • @mysk
    @mysk 3 месяца назад

    Thanks a lot for watching and interacting with this video, a few remarks: 1️⃣ PIN to Drive won't prevent the attacker from driving away with the car: twitter.com/mysk_co/status/1766451258158682322 2️⃣ We used a Flipper Zero because it made recording the video much simpler. It has a nice compact display. Many other devices are capable of running a captive network, including laptops. 3️⃣ Two users reported in the comments that they received a push notification after adding a phone key. We weren't able to reproduce it. For the account and vehicle we have for testing, we never received a push notification after adding a new phone key. Thanks a lot again. Subscribe to the channel and Follow us or more content like this. ✌️

  • @birphborph
    @birphborph 3 месяца назад

    what about the 2FA Expiration? The code expires after 30 seconds afaik. So the owner AND attacker have to be VERY fast and the owner hast to use a new generated 2FA code which lasts for 30 seconds. It's unlikely to be this fast. But it shows how important 2FA is. Maybe it is a good Idea to enable Pin to Drive, but of course this can be disabled if the hacker disables it via app. This function should be more secured in the app. So the user has to enter the pin before he can disable it.

    • @mysk
      @mysk 3 месяца назад

      30 seconds should be enough. A sophisticated attacker wouldn't type all that manually, they would copy the text and send it to the phone, then paste it. Plus, the fake portal can prompt the user to enter a new passcode and repeat until it works. Agreed, the PIN to Drive is useless here because you can bypass it in the app.

    • @tylwythteg
      @tylwythteg 3 месяца назад

      30 seconds is plenty. You can get it done in 10. The last 20 you can use to check Tesla stock price.

    • @AndrewPiercy
      @AndrewPiercy 2 месяца назад

      @@mysk if the hacker is sitting around at a supercharger waiting eagerly, and you happen to want to use tesla guest wifi, and you fall for it, and the hacker has a full 30 seconds left in the OTP rotation, and you don't notice a shady person near the car, and you join the wifi then decides instead of using wifi you want to walk away from the car, and the hacker stops charging the car and you don't notice the charging stopped notification, and the hacker manages to drive away quickly, they'll have succeeded in stealing your car just in time for you to call the police and give them the exact location of the car which the owner will still have.

  • @psiklops71
    @psiklops71 3 месяца назад

    Finally get to use my flipper

  • @KL-og8gg
    @KL-og8gg 3 месяца назад

    they dont put the expiration on the MFA code?

    • @mysk
      @mysk 3 месяца назад

      They do. The 6-digit passcode expires in 30 seconds.

  • @XxDragonSharKxX
    @XxDragonSharKxX 3 месяца назад

    Use a password manager and then you have no issue besides you're an idiot when you put your passwords everywhere without checking the site. Another thing is that you could still track the vehicle the whole time, so the risk for stealing it is way too high

    • @mysk
      @mysk 3 месяца назад

      The password manager doesn't help here. Also, the captive portal doesn't show the URL. Your answer implies that you haven't used a captive portal before. One can easily be fooled and that doesn't mean that the person is an idiot. Some social engineering attacks are very sophisticated.

    • @XxDragonSharKxX
      @XxDragonSharKxX 3 месяца назад

      @@mysk On Android I have the option to open the site in a browser. And sure does a password manager help as it wouldn't offer you to fill in the data.

    • @mavrc
      @mavrc 3 месяца назад

      phishing is the number one attack vector... pretty much everywhere, and if your answer is "you're an idiot," then you're part of the problem and the reason why security people have such a hard time being taken seriously. Also, if you've never been fooled by a social engineering attack, you've just not gotten the right one yet.

    • @fran8a
      @fran8a 3 месяца назад

      on iOS too, you can close the window and a prompt will be displayed to you: use it without internet OR choose another network. Choose the first and open safari. I use to do that not for security but for checking if internet is working without logging in (or at least some protocols...) @@XxDragonSharKxX