tab kidnapping - A new ID theft technique
The idea is simple, if a site senses that you are using a targeted site like Chase.com then it secretly switches that tab to a fake login page. You think you are logging into a site that you already assure yourself is legit but you are actually giving your credentials away to criminals.
This scheme was unveiled by Aza Raskin at Mozilla. He is the creative leader of Firefox. Since this is only a Proof-Of-Concept as of this writing (May 2010), we surfers have a chance to change our ways before it becomes popular in the criminal world.
The solution is simple: Do not use multiple tabs when you are surfing to an important site (like your bank), even if you are not logged in.
This also show the benefits of early disclosure. Yes, it will give criminals an idea, but they probably would get the same idea from the various "hacking" sites around. It also gives us a heads-up on what can be done to us and what we can do to avoid it.
Details:
http://www.itworld.com/security/109172/how-foil-web-browser-tabnapping?source=ITWNLE_nlt_security_2010-05-27

Comments
Post new comment