Summary

  • AMP is an open-source HTML framework that makes web content load faster on mobile devices.
  • Researchers have found a new phishing tactic that uses Google AMP to make URLs look trustworthy.
  • The tactic involves using the URL of a web page cached by the Google AMP Viewer. This URL looks similar to the original URL, but it is actually served from the google.com domain.
  • This gives the malicious website the legitimacy of the google.com domain, which can trick users into entering their personal information.
  • The researchers found that the Google AMP URLs have proven to be very successful at reaching users, even in environments protected by secure email gateways.
  • Along with using Google AMP URLs, the researchers also saw other techniques being used in phishing attacks, such as open redirects on trusted domains, chains of redirects linking the AMP URL to the malicious site, image-based phishing emails, and CAPTCHA services to disrupt automated analysis.
  • To avoid phishing attacks, it is important to not take things at face value for messages requiring urgent attention. It is also important to use a phishing-resistant password manager and a FIDO2 2FA device.
    • Virkkunen@kbin.social
      link
      fedilink
      arrow-up
      24
      ·
      1 year ago

      There’s manifest V3 and WEI though.

      In the end, Google just keeps one upping themselves in creating a worse web for everyone but them.

      • traveler01@lemdro.id
        link
        fedilink
        English
        arrow-up
        24
        arrow-down
        5
        ·
        1 year ago

        Sorry, I’ll rephrase it.

        AMP is the biggest cancer ever created in the web… yet!

    • SmashingSquid@notyour.rodeo
      link
      fedilink
      English
      arrow-up
      10
      arrow-down
      1
      ·
      edit-2
      1 year ago

      AMP is so terrible I paid for a safari extension (amplosion by the dev of Apollo) just to get rid of it.