Summary

  • AMP is an open-source HTML framework that makes web content load faster on mobile devices.
  • Researchers have found a new phishing tactic that uses Google AMP to make URLs look trustworthy.
  • The tactic involves using the URL of a web page cached by the Google AMP Viewer. This URL looks similar to the original URL, but it is actually served from the google.com domain.
  • This gives the malicious website the legitimacy of the google.com domain, which can trick users into entering their personal information.
  • The researchers found that the Google AMP URLs have proven to be very successful at reaching users, even in environments protected by secure email gateways.
  • Along with using Google AMP URLs, the researchers also saw other techniques being used in phishing attacks, such as open redirects on trusted domains, chains of redirects linking the AMP URL to the malicious site, image-based phishing emails, and CAPTCHA services to disrupt automated analysis.
  • To avoid phishing attacks, it is important to not take things at face value for messages requiring urgent attention. It is also important to use a phishing-resistant password manager and a FIDO2 2FA device.
  • @TheFunkyMonk
    link
    English
    61
    edit-2
    1 year ago

    Any incentive to stop supporting AMP sounds like a positive for the web to me.

  • @[email protected]
    link
    fedilink
    English
    36
    edit-2
    1 year ago

    What’s a “phishing-resistant password manager”? lol

    Also: fuck Google and AMP

    • @[email protected]OP
      link
      fedilink
      English
      28
      edit-2
      1 year ago

      PWM saves the URL with the password record. It doesn’t auto-fill username/password on a website that the user hasn’t already approved, so it provides some phishing-resistance when the URL is unknown, or is just similar to the originally saved URL.

    • Virkkunen
      link
      fedilink
      261 year ago

      There’s manifest V3 and WEI though.

      In the end, Google just keeps one upping themselves in creating a worse web for everyone but them.

    • @[email protected]
      link
      fedilink
      English
      9
      edit-2
      1 year ago

      AMP is so terrible I paid for a safari extension (amplosion by the dev of Apollo) just to get rid of it.

  • @chalupapocalypse
    link
    English
    151 year ago

    Is there a way to block amp links on my firewall?

  • resketreke
    link
    fedilink
    91 year ago

    Another new type of phishing I’ve been seeing in my junk mail uses links to Bing. Not sure what it does because, as you can understand, I haven’t clicked any of those.

    By the way, if you use Firefox, there’s this little add-on called “Redirect AMP to HTML” that might be useful to prevent this (or maybe not, I don’t know).

    • MaggiWuerze
      link
      fedilink
      English
      131 year ago

      Ooorrrrr… AMP is just a shit piece of technology that’s sole purpose is to shovel all your information into Googles gaping maw by obfuscating urls behind an AMP link and these phishers just took it to it’s logical conclusion.

      I the end Google needs to be broken up and Chrome AND Chromium each need to be their own thing like Firefox is

  • Kallioapina
    link
    English
    71 year ago

    Main reason I started using Kiwi browser on my mobile some years back (3-4?) was that it blocks AMP-sites. Ability to run many chrome extensions has been also a good plus, though interacting with some interfaces on them is sometimes difficult or downright impossible.