this post was submitted on 27 Mar 2025
690 points (99.0% liked)

Technology

68130 readers
3701 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
 
  • A jetlagged Troy Hunt accidentally clicked a link and logged into an account only to realise he had been phished.
  • Despite reacting quickly, attackers were able to export a mailing list for Hunt’s personal blog.
  • Hunt has detailed the attack and warned his subscribers in a timely fashion.
you are viewing a single comment's thread
view the rest of the comments
[–] xigoi@lemmy.sdf.org 3 points 5 days ago (2 children)

Is there anything bad that can happen if you just click a link without logging in or anything? How is it different from opening up a random search result?

[–] _synack@sh.itjust.works 5 points 5 days ago (1 children)

Not all phishing links are related to credential theft or trying to get you to download something malicious. Zero-day vulnerabilities in web browsers are revealed constantly. A malicious website (or malicious content embedded into an otherwise benign website) can leverage these or other unpatched vulnerabilities when visited.

You should never follow a known or suspected phishing link unless it's your job and you are using the appropriate tools and techniques. Just report it to the security department or delete it and move on with your day.

[–] xigoi@lemmy.sdf.org 1 points 5 days ago (1 children)

Does that also mean I should not browse any websites I don’t already know? That’s very limiting.

[–] _synack@sh.itjust.works 4 points 4 days ago* (last edited 4 days ago)

I never said that. I said do not follow known or suspected phishing links. It takes practice and skill, and it is not always simple. But if you know if it is a risk, you should consider avoiding the risk.

"This looks like it might be phishing. Let me check it out and see what's on the other side." <--- That's what I am suggesting to avoid.

Security is an onion: layered. Patched software. Good, unique passwords. MFA. Various security defense tools. But technology can have gaps, flaws, or be circumvented. It's important to keep in mind that us as individuals are also a security layer, and are often the first or last line of defense.

[–] zerofk@lemm.ee 3 points 5 days ago (1 children)

I’m no expert, but as I understand it, there are several things that can go wrong just by clicking. This depends somewhat on your browser settings and how you use it.

Visiting a compromised site may allow the attacker to access data from other tabs and windows in the same browser session. Some sites warn you to close the whole browser when logging out because of this.

Sometimes bugs in a browser can allow a site to run arbitrary code on your machine. These hopefully get patched quickly.

[–] Forbo@lemmy.ml 3 points 5 days ago

If the link was unique to the email, then it could be a signal to the phisher that is a valid address for further targeting.