Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Thoughts on NSS Test of Socially Engineered Malware (SEM) and Phishing Attacks

40 views
Skip to first unread message

Alan Jones

unread,
Oct 17, 2017, 12:07:07 PM10/17/17
to mozilla-de...@lists.mozilla.org
I could not find any comments on other forums so thought I would ask here first. I was curious what what others thought of the NSS Labs Test of Socially Engineered Malware (SEM) and Phishing Attacks.

Firefox 55 did not do too well, are there improvements in 56/57 that will help out. On the other hand did others think the tests were not valid?

https://www.nsslabs.com/company/news/press-releases/nss-labs-conducts-first-cross-platform-test-of-leading-web-browsers/


R0b0t1

unread,
Oct 19, 2017, 12:15:03 AM10/19/17
to Alan Jones, mozilla-de...@lists.mozilla.org
That link is kind of dense. Can you direct me to the content?

One thing I will say, is security researchers who do nothing else tend
to make suggestions that are completely divorced from reality. Even
some of the security efforts undertaken by Mozilla seem to be
misguided.

One example that comes to mind were some resource changes to prevent
users from being misled. The problem was that if users could be misled
in the way that was being defended against, an attacker could simply
write an executable to disk and then have the user click it (or
something similar). I apologize for the lack of information - this
only came to my attention because it broke Vimperator.

However, since this article deals specifically with phishing, I am
slightly confused - phisability depends a great deal on each
individual website.

Cheers,
R0b0t1.
0 new messages