It started innocently enough. I saw a tweet astir a caller merchandise offering from 1 of my favourite companies, Cloudflare.

Neat! I clicked done to the tract and location it is:

And huzzah!, my preferred handle, @ericlaw is still available. I’d amended hurry to declare it earlier personification other gets it!
Since I’m already a long-time Cloudflare user, I conscionable request to motion in. That makes sense, really other will they hindrance the grip to my account?

Easy peasy. I’m in. Looks for illustration there’s conscionable 1 much step, I gotta authorize the caller feature?

But hold a sec!
This looks exactly like 1 of those Consent Phishing attacks that person been truthful celebrated complete the past fewer years!
And wait, why is the introduction constituent connected cloudflare.pay, a tract that doesn’t already person my credentials, alternatively than thing wrong the cloudflare.com domain which does (e.g. cloudflare.com/pay)? There is nary inherent method narration betwixt a .com domain and a .pay domain. Domain names nether the.pay sTLD are disposable to anyone pinch $20 (unlike, e.g. .bank which requires much vetting), truthful there’s thing that would extremity maine from registering my ain cloudflarepayments.pay domain sanction successful conscionable a fewer minutes.
And why doesn’t Cloudflare’s support tract admit its ain company’s feature? And that greenish checkmark looks suspicious arsenic heck– an attacker could astir apt conscionable shove that emoji wrong their misleading show name, the aforesaid measurement that folks trying to phish Microsoft email accounts usage misleading app names and icons:
Fake Outlook OAuth phishing requestThe guys astatine Cloudflare are geniuses who cognize their stuff. This has got to beryllium an attack. It’s a clever 1 — I was emotion specified a sense of urgency because I wanted to “win” the title to get my desired handle. Very very clever!
Unfortunately, the Cloudflare support page doesn’t travel best practices, truthful there’s nary “Report suspicious request” nexus I tin usage to fto the Cloudflare folks cognize that their customers are nether attack.
Let maine spell backmost to my Cloudflare dashboard and effort to get to the Wallet characteristic from its sidebar. Hrm. It’s not there. Now, Wallet purports to beryllium “a caller feature”, truthful possibly the Dashboard conscionable isn’t updated yet. A hunt of the docs turns up nothing. Let’s inquire the AI supplier successful chat.

Oh, wow. It really is an attack! Let’s report the phish correct away!

A fewer minutes later… womp womp…

Oh dear.
After a fewer minutes of further frantic searching, it turns retired that this is, successful fact, a morganatic caller Cloudflare merchandise and a morganatic site, contempt giving each denotation of being a clever phishing attack.
It further turns out that that suspicious greenish checkmark is not portion of the app’s untrustworthy show sanction but alternatively a (poorly placed) information UI constituent that a personification is expected to hover complete to get the information details:

The Cloudflare folks apparently want information issues reported via HackerOne (which wouldn’t fto maine log successful because the Cloudflare CAPTCHA HackerOne uses seems to beryllium broken…).
When morganatic websites sometimes enactment very very phishy, see really difficult it must beryllium for URL Reputation services for illustration Microsoft SmartScreen and Google SafeBrowsing to artifact malicious sites without mendacious positives arsenic millions of caller sites are added to the web each week.
Lessons
Web Developers, please travel each champion practice, I’m begging you:
- Host apps and contented nether your trusted domain name. If you must add a caller name, nexus to it straight from your trusted domain name.
- Show applicable information accusation successful a trustworthy place erstwhile asking the personification to make information decisions.
- Make it trivial to study scams, successful context.
- Test your information reporting flows to guarantee they are monitored and usability correctly.
Users: Try to enactment safe retired there. Think earlier you click, and if each other fails, wait.
Security Geeks: Never blasted the victim– they’ve sewage an intolerable job.
-Eric
English (US) ·
Indonesian (ID) ·