home | tags


Low-tech ways to avoid phishing

tags: #intro #authN #stay-safe

There are many ways to avoid phishing. Before we get to the easier ways, let’s look at the more complex methods that people use if they have sufficient expertise to manage them.

The most complicated one is to use passkeys. (See my other blogposts for more on this). I really don’t recommend this for normal people, it is still a little complicated and there are chances you might lose access if you are not careful.

The second best method is to use a password manager with a browser agent. We’ll see how this works later, but this is the one that I use. It still requires a certain amount of setup and care and feeding. So for an absolute beginner, even this is not such a great idea, although it is the ideal solution to my mind.

how phishing works

the fake URL that looks real

First, let’s see how phishing actually works. Phishing works by giving you a link and expecting you to click on it. When you click on it, you will find a login screen that looks very similar to something that you are already familiar with: Gmail, Facebook, Linkedin, or whatever.

The URL may look very similar to the correct one, but it will not actually be the same; it belongs to the attacker. Most normal people will miss this. So when you type in your user ID and password in there, that information gets snatched by the attacker.

This is also how a password manager that has a connection to the browser can protect you. What happens is that the browser sends the password manager the URL it sees on the URL bar. The password manager already has the correct URL in the password manager database – you would have put it in when you added the password entry. So, even if the URL in the browser looks like, say, gmail.com to a human, but is actually something else, the computer is not fooled. The password manager detects the mismatch and refuses to autofill the password. And when the autofill fails you know there is a problem and that you were protected.

the “social engineering” aspect

The social engineering aspect of phishing is also important to remember. There will usually be a sense of urgency conveyed by the message, whether it is a threat of real harm, or the possibility of losing some money, or something else.

Sadly there’s no technical solution to this :-( You just have to be aware. It helps to call a friend or someone and talk it out with them; that may help reduce the artifical urgency.

The safest method of course is to never click on a link that you receive from a stranger.

This is easier said than done.

It is easier when you are not actually expecting such a message. For example, if you get an email that looks like it came from FedEx but you don’t have any memory of sending something or expecting to receive something from FedEx, well, it’s easy for you to ignore.

It becomes a lot harder if you were expecting something. And that’s when this advice fails.

prevention method 2: pre-login

This method is very simple.

First, add all your important URLs to your bookmarks. (This is a one-time activity; just do it).

When you get what you suspect is a phishing message that is asking you to login to, say, google, you do the following:

If the mail was genuine and went to the right URL, then, because you’ve already logged into the site that it wants you to go to, the URL will simply work and everything is good.

On the other hand, if it is a phishing message, it goes to the attacker’s website, which then sends you the login page again. And since you’ve already logged in, you know that this is a phishing attempt.

At that point you just close the window and delete the email. Not much more you can do.