• ReversalHatchery@beehaw.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Does this rely on the user typing in their password, or does somehow even the browser fall for it and autofill it?

    Because in that case, to respond to OP: Firefox is not vulnerable to this, but most users themselves are. Using a password manager like Bitwarden would help, because if you add the website’s real URL to your password entey (happens automatically for the current URL at password entry creation), bitwarden will simply just not show your password entry when the URL does not match.

    Also, install uBlock Origin and turn on it’s phising blocklists in the settings. It can be helpful.