TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Color can prevent your users from getting phished

11 pointsby emeltzzabout 6 years ago

5 comments

Semiapiesabout 6 years ago
So, this system, if it ever got wide use, would rely on users remembering which &quot;unique&quot; colors were randomly assigned to them by whichever sites they use.<p>I was thinking, &quot;Gee, if a scanner put a random color bar at the top of the phishing emails, how often would the color look close enough that the user couldn&#x27;t distinguish between it and their own color, at least without comparing the colors side-by-side?&quot;, but I&#x27;m not convinced users would even <i>remember</i> their colors after the second or third one.<p>(And if course, this is very flawed for the color-blind and utterly useless for anyone using screen-readers.)
评论 #19257974 未加载
frosted-flakesabout 6 years ago
The power company where I used to live did something like this for it&#x27;s online dashboard, but with images (I think it was Delmarva Power). Every time you entered your username to log in, it would show you a simple image&#x2F;line-drawing and a message saying that if the image ever changes, you&#x27;re being scammed, so don&#x27;t enter your password. I&#x27;ve never seen anything like it since.<p>As far as colours on emails goes, if everyone starts doing it, nobody will remember which colour goes with which company. It needs to be something more distinctive than just a colour band.
评论 #19257963 未加载
retroboxabout 6 years ago
This seems great in theory but I can’t help but think the phishing scam would evolve in to “your account has been hacked and your secret color discovered. Click here to login and set a new secret color.”<p>Also, let’s suppose a database of users and their associated color is compromised but that the intrusion is not immediately detected. This allows scammers to craft emails with the right color of banner leading to “but the email has the right color at the top so it can’t be a phishing scam” logic.<p>It may just shift the problem.
cloud_thrasherabout 6 years ago
This is a long-standing issue and many solutions have been devised. Regardless of most solutions, it will probably always fail because people don&#x27;t want to be bothered with remembering colors, images, configuring PGP, etc. Case in point, ask anyone how much they are annoyed by reCAPTCHA.
wodenokotoabout 6 years ago
Yahoo had something similar, although all I remember was them bugging me to choose a color for security, and me trying to ignore it because I didn&#x27;t care.<p>I wanna say it was something about colouring the login box, but I can&#x27;t make that make sense.