Skip to content
This repository has been archived by the owner on Jul 6, 2022. It is now read-only.

Authentication process provides no basis of trust #53

Closed
Ziraya opened this issue Mar 31, 2017 · 1 comment
Closed

Authentication process provides no basis of trust #53

Ziraya opened this issue Mar 31, 2017 · 1 comment

Comments

@Ziraya
Copy link

Ziraya commented Mar 31, 2017

When going through the authentication process for google the user is presented with a sparse window with a black header stating authorization required, displaying what appears to be the google login form; this apparent web view is sandboxed so the user must enter their credentials. This page is devoid of any means by which the user could reasonably ascertain that this is an authentic google form, or connected over a secure connection.

Therefore the only reasonable position for the user to take is to assume that this is a phishing attempt and refuse to enter anything.

because this is sandboxed the user is unable to make use of an already established login such as can be performed by going directly to pushbullet's website for the first time after having signed into google directly.

@jariz
Copy link
Owner

jariz commented Mar 31, 2017

Duplicate of #44.

@jariz jariz closed this as completed Mar 31, 2017
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants