tab kidnapping - A new ID theft technique

The idea is simple, if a site senses that you are using a targeted site like Chase.com then it secretly switches that tab to a fake login page. You think you are logging into a site that you already assure yourself is legit but you are actually giving your credentials away to criminals.

This scheme was unveiled by Aza Raskin at Mozilla. He is the creative leader of Firefox. Since this is only a Proof-Of-Concept as of this writing (May 2010), we surfers have a chance to change our ways before it becomes popular in the criminal world.

The solution is simple: Do not use multiple tabs when you are surfing to an important site (like your bank), even if you are not logged in.

This also show the benefits of early disclosure. Yes, it will give criminals an idea, but they probably would get the same idea from the various "hacking" sites around. It also gives us a heads-up on what can be done to us and what we can do to avoid it.

Details:
http://www.itworld.com/security/109172/how-foil-web-browser-tabnapping?source=ITWNLE_nlt_security_2010-05-27

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
  • Image links from G2 are formatted for use with Lightbox2

More information about formatting options