Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I feel I'm fairly immune to traditional phishing because I never click a URL in an email. If namecheap sends me an email saying one of my domain names is about to expire, I don't use their "Renew Now" link I go to "namecheap.com" (not hard to type), log in, and renew the name. Banks and other organizations that send long complicated links in emails and encourage people to click them are part of the reason phishing is possible. These emails should look like:

Dear John Doe,

An automatic payment has been made from your checking account:

04-May-2014 $125.00 to Big Energy Utility Corp

For more details, please log on to your online banking account and click the "Recent Transactions" tab.

There is no need for hyperlinks in any of that.



Yeah, part of me wonders how bad it would be / what would break if email clients banned outside links (e.g. beyond fragments in the email). My suspicion is that the only useful use of a link is a confirmation email which have other potential implementations...


It could be interesting if Gmail did the Chrome experiment in email links in a popover, by displaying the domain of a link...


This would effectively break email verification, which would be pretty bad.


    To verify your email, please login at SiteYouHaveJustRegisteredAt
    and enter the following information:

    User ID: 1234
    Verification code: 12345678


plus it forces web sites to be designed in such a way to easily locate what you need, e.g. "recent transactions" shouldn't be buried deeply in the navigation tree.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: