Thursday, 19 January 2017

Wide Impact: Highly Effective Gmail Phishing Technique Being Exploited

There is a highly effective phishing technique stealing login credentials that is having a wide impact, even on experienced technical users.

The Phishing Attack: What you need to know

A new highly effective phishing technique targeting Gmail and other services has been gaining popularity during the past year among attackers. Over the past few weeks there have been reports of experienced technical users being hit by this.

This attack is currently being used to target Gmail customers and is also targeting other services.

The way the attack works is that an attacker will send an email to your Gmail account. That email may come from someone you know who has had their account hacked using this technique. It may also include something that looks like an image of an attachment you recognize from the sender.

You click on the image, expecting Gmail to give you a preview of the attachment. Instead, a new tab opens up and you are prompted by Gmail to sign in again. You glance at the location bar and you see accounts.google.com in there.

Once you complete sign-in, your account has been compromised. A commenter on Hacker News describes in clear terms what they experienced over the holiday break once they signed in to the fake page:

"The attackers log in to your account immediately once they get the credentials, and they use one of your actual attachments, along with one of your actual subject lines, and send it to people in your contact list.

For example, they went into one student's account, pulled an attachment with an athletic team practice schedule, generated the screenshot, and then paired that with a subject line that was tangentially related, and emailed it to the other members of the athletic team."

The attackers signing into your account happens very quickly. It may be automated or they may have a team standing by to process accounts as they are compromised.

Once they have access to your account, the attacker also has full access to all your emails including sent and received at this point and may download the whole lot.

Now that they control your email address, they could also compromise a wide variety of other services that you use by using the password reset mechanism including other email accounts, any SaaS services you use and much more.

Described above is a phishing attack that is used to steal usernames and passwords on Gmail. It is being used right now with a high success rate. However, this technique can be used to steal credentials from many other platforms with many variations in the basic technique.

How to protect yourself against this phishing attack

You have always been told: "Check the location bar in your browser to make sure you are on the correct website before signing in. That will avoid phishing attacks that steal your username and password."

In the attack above, you did exactly that and saw 'accounts.google.com' in the location bar, so you went ahead and signed in.

To protect yourself against this you need to change what you are checking in the location bar.

This phishing technique uses something called a 'data URI' to include a complete file in the browser location bar. When you glance up at the browser location bar and see 'data:text/html…..' that is actually a very long string of text. If you widen out the location bar it may appear to have html tags towards the end.

There is a lot of whitespace which I have removed. But on the far right you can see the beginning of what is a very large chunk of text. This is actually a file that opens in a new tab and creates a completely functional fake Gmail login page which sends your credentials to the attacker.

You might see on the far left of the browser location bar, instead of 'https' you have 'data:text/html,' followed by the usual 'https://accounts.google.com….'. If you aren't paying close attention you will ignore the 'data:text/html' preamble and assume the URL is safe.

You are probably thinking you're too smart to fall for this. It turns out that this attack has caught, or almost caught several technical users who have either tweeted, blogged or commented about it. There is a specific reason why this is so effective that has to do with human perception.

How to protect yourself

When you sign in to any service, check the browser location bar and verify the protocol, then verify the hostname. In Chrome this is usually a green padlock and green https text.

Make sure there is nothing before the hostname 'accounts.google.com' other than 'https://' and the lock symbol. You should also take special note of the green color and lock symbol that appears on the left. If you can't verify the protocol and verify the hostname, stop and consider what you just clicked on to get to that sign-in page.

Enable two factor authentication if it is available on every service that you use. GMail calls this "2- step verification" and you can find out how to enable it on this page.

Enabling two factor authentication makes it much more difficult for an attacker to sign into a service that you use, even if they manage to steal your password using this technique. I would like to note that there is some discussion that indicates even two factor authentication may not protect against this attack.

Official Statement from Google

This is an update at 11:30pm PST on Tuesday the 17th of January 2017. I was contacted by Aaron Stein from Google Communications. He has provided the following official statement from Google:

"We're aware of this issue and continue to strengthen our defenses against it. We help protect users from phishing attacks in a variety of ways, including: machine learning based detection of phishing messages, Safe Browsing warnings that notify users of dangerous links in emails and browsers, preventing suspicious account sign-ins, and more. Users can also activate two-step verification for additional account protection."






[https://www.wordfence.com/blog/2017/01/gmail-phishing-data-uri/]

Friday, 16 December 2016

Improve Brand Loyalty with Artificial Intelligence

Over a billion pounds was invested by start up companies in the first part of 2016 on AI.  Most of those companies were e-commerce and digital shopping, catering to retailers that are using AI to improve customer shopping experiences. While retail applications of AI might not grab the headlines like self driving cars, it will be just as impactful, affecting almost every retail purchase decision that a consumer makes.

AI will allow retailers to build an incredible level of customer loyalty. The three most common ways will be through individual segmentation, real time communication, and personalisation. Used tactfully, these techniques can help brands transform shoppers into lifetime consumers.

Individual Segmentation


Amazon and Google use a simple form of AI to curate product recommendations without needing human intervention. This is called collaborative filtering. A more advanced form of this is individual segmentation, where brands create profiles based off of behavioural shopping habits that can be maintained at scale.

Here a brand will use AI to collect and maintain the data from customer decisions over the span of a few years and make recommendations based on that information. The more data a brand has on a customer, the better it can predict his or her wants and needs. Over time, brands using this AI will have so much information about a customer, their recommendations will be nearly perfect.

Kevin Kelly, Author of The Inevitable, writes on the above topic, stating: “The longer you are with a service, the better a brand gets to know you; and the better it knows you, the harder it is to leave and start over again. It’s like being in a committed relationship. Naturally, the producer strives for this kind of loyalty, but the customer gets many advantages for continuing as well: uninterrupted quality, continuous improvements, and attentive personalization”.

Real Time Communication


Brands will use AI to communicate with customers in real time. Our appetite for speed is insatiable. The cost of real-time engagement requires massive coordination and degrees of collaboration that were impossible a few years ago. Now that most people are equipped with a smart phone, entirely new economic forces are being unleashed.

Many companies are planning to use geolocation services that will alert customers, inside or nearby a store, about sales or discounts on products based on previous shopping decisions. This real time outreach could help guide customers throughout the shopping journey, making a store visit highly personalised.

Some large stores in America have already experimented with real time in-store communication.  Opening text services where customers can ask an AI bot questions while they shop. The bot can tell you where the closest restroom is or what floor a certain department is on, making it easier for customers to find products and navigate their way through a store.

Personalisation


Brands intend to use AI to help personalise the shopping experience for customers online and in store. Because AI is great at collecting data and working in real time, it will soon be possible for a completely personalised, connected shopping experience.

Online retailers that sell many products will be able to identify what a shopper is looking for and tailor the website to fit his or her needs. The online store will constantly adapt, making the shopping experience near effortless.

The North Face is already using this technology. Powered by IBM’s Watson, the expert shopper prompts you to answer questions about an article of clothing like “where and when will you be using the jacket?”. After answering a few questions, the AI program makes smart suggestions based off the information you submitted.

The ability for a brand to narrow down product options to customers in an intelligent way could help improve brand loyalty. Often, the the biggest obstacle in purchasing something is having too many options. If AI can alleviate burdensome decision making, both the customers and brands win.

Embrace Change


It seems the future vitality of brands will weigh heavily on a company’s willingness to adopt AI. Used creatively, AI can win loyal customers, track their data, and personalise their shopping. These benefits, combined with human guidance, could make the difference between a timeless brand, and a one hit wonder.

Thursday, 25 February 2016

Design trends in ecommerce for 2016

ECommerce is now a daily part of our on-line lives.  During 2016 we predict to see an increase in eCommerce and on-line sales across mobile devices while people move away from traditional desktop and laptop PC's.

Some of these design trends include:

1. Material Design
Now being adopted by eCommerce companies, the vibrant and content focused design style continues to make waves since its launch in 2014.  It's unified experience across platforms makes it a great for developing an engaging eCommerce.  This has been utilised very well by sites such as PA Design and Bewakoof.

2. Hidden Menus
Popular for cleaning up cluttered eCommerce designs, these menus used to be used mainly on mobile versions of sites where space was limited, however are now making their way into desktop sites to allow a bigger canvas for more creativity.  These are in use on many desktop sites and should continue well into 2016, on sites such as House of Fraser.

3.  Upwardly Responsive
Responsive sites are all the rage these days, with everyone thinking about their site being usable on mobile devices.  It is worth bearing in mind upwardly responsiveness though, as going through 2016, more and more customers will use TV's and larger devices for browsing the web and eCommerce purchases. An example is Firebox.

4. Rich Animations
These are a great way to engage customers and make them feel confident about your brand.  Animations at the right time can make your customers feel like you care and add some play-ability and enjoy-ability to a design.

5. Storytelling
In an every growing competitive arena of on-line retailers, it is important to capture your visitors attention. Telling the story of your brand or products is a great way to do this.  Story telling can bring your brand to life and build loyalty with customers.



http://www.webdesignerdepot.com/2016/01/9-ecommerce-design-trends-to-embrace-in-2016/

Wednesday, 24 February 2016

Mixed reactions on Facebook today

Just in case you haven't noticed.  Facebook are rolling out a new feature across their platform called Reactions.


This appears to be off the back of the community requesting for a long time a Dislike button on posts.  It is clear to see however this is having mixed... well, reactions across the globe.


Facebook founder Mark Zuckerberg posted:

Today is our worldwide launch of Reactions -- the new Like button with more ways to express yourself.
Not every moment you want to share is happy. Sometimes you want to share something sad or frustrating. Our community has been asking for a dislike button for years, but not because people want to tell friends they don't like their posts. People wanted to express empathy and make it comfortable to share a wider range of emotions.
I've spent a lot of time thinking about the right way to do this with our team. One of my goals was to make it as simple as pressing and holding the Like button.
The result is Reactions, which allow you to express love, laughter, surprise, sadness or anger.
Love is the most popular reaction so far, which feels about right to me!

Try them out, by hovering over the Like button the desktop, or by holding down the Like button on your mobile to express your reactions to your friends posts and updates.  It is worth noting Facebook are doing a phased roll out over a short period of time, so it is likely you will see this already, but if not, check back in a few hours as may be it's not got your part of the world yet.

Wednesday, 20 January 2016

The Pros and Cons of One-Page Checkout

Shopping cart abandonment is an epidemic in online retailing, with some companies reporting that more than 60% of checkouts end without a conversion.

Preventing even a relatively small percentage of these abandoned carts would significantly improve revenues and profits.

While purchase price and shipping costs are the leading reported causes of shopping cart abandonment, ease of use is close behind.

One increasingly popular method used to slash cart abandonment rates is to introduce single-page, Ajax-driven checkout forms that combine the convenience of a single page format with asynchronous form validation.

Single-page checkout is faster and easier so that more customers convert.

When you’re trying to decide if your checkout process should be a single page or several pages, consider the analogy of a supermarket. When shopping, consumers always gravitate towards the shortest checkout lanes or fastest cashiers. By definition, a single-page checkout is faster than a multi-page checkout if for no reason other than there are no additional pages to load.

Single-page checkout forms, particularly those that use javascript to march shoppers through the process, also provide better step-by-step visibility. Shoppers know what they must do and where they are in the process.

If you have ever filled out a long online form, clicked submit, and then had the form erase everything they input and return a message like “address not valid,” “passwords don’t match,” or “please answer question #2,” you will understand the value of AJAX.

AJAX addresses this issue by validating the form while the shopper fills it out. Server calls - if needed - are made asynchronously without reloading the page or potentially erasing the form. Users get feedback as soon as a form field is complete (when they click into the next field), not once the form is submitted. In some cases, the javascript might be able to do the form validation without connecting to the server at all.


The PROS of Using a Single Page, AJAX Checkout Process
  • More conversions - Single-page checkouts have been proven to significantly improve sales conversions, boosting a merchant’s bottom line.
  • Better page performance - While dozens of factors contribute to page load times, using a single, AJAX-powered checkout form should improve user experience. This is important since many studies suggest consumers won’t tolerate slow loading pages.
  • Better customer satisfaction - With better performance and no annoying form validation issues, customers should enjoy a better overall shopping experience.
  • Advanced Interactivity  - Once a merchant has decided to add AJAX, it’s possible to make the page more interactive, which again, may improve customer experience.
The PROS to using an AJAX, one-page checkout process tend to focus on customers and profits. By contrast, the CONS tend to be development related.

The CONS of Using a Single-Page, Ajax Checkout Process
While there is generally no reason to use a multi-page checkout, there are things to consider when using Ajax.
  • It won’t work without javascript - AJAX depends on javascript, if a user has javascript disabled, the page will revert to server-side validation.
  • Some browser functions won’t necessarily behave as expected - Because AJAX does not reload a page to update content the browser's back button will not bring the user back to an early step in the checkout as might be expected. There is a work around, but it requires more development time.
  • AJAX requires more upfront investment - Because AJAX will increase development time, merchants may have to pay a little more or use more development hours.

Thursday, 26 November 2015

How not to write good product descriptions

As Christmas approaches, many ecommerce sites look to optimise their sites so they can be found in search engines, increase conversions and ultimately boost sales.  One of the most obvious ways to do this is update (or write) product descriptions across the site.  Usually if you're an ecommerce site, you sell products online, and the item or product page is where most customer decide to add that product to their cart.

Here are some ways not to write product descriptions.

1) Focus on features - Many retailers focus on the features of a particular product. This doesn't sell your product, you should instead focus on benefits.  Why do I need this 48" LCD TV?  You might be tempted to write on your product page, 'Amazing 48" LCD TV, Flatscreen, 4 HDMI ports, USB and flashing lights..".  Yes this is useful, but is it making me want to buy it? may be... but what if you focused on the benefits? 'Stunning 48" HD Flatscreen LCD Television, perfect for watching the FA Cup or catching up with your favourite soap'.  Straight away I can see the benefits of having this TV.  I can watch the football or Corrie in crystal clear Hi Def.

2) Use Manufacturers Text - Many people copy the manufacturers product descriptions directly from their site or brochure to populate their own item descriptions.  Great!  Now you have the same text every other person selling that product has.  Not too good, I would imagine for SEO if you and 26 other retailers all have the same text word for word.  Taking the time to reword standard copy lets your customers know you care about the product to make sure you know what you are selling.

3) Write for search engines - It's great to write friendly content for search engines, make sure you have keywords and important information in the descriptions, but don't over do it.  Many descriptions are written with search engines in mind and although SEF or SEO'd it just doesn't read well to customers.  Search engines don't buy your products, customers do, and if they can't read your description for all the bold HDMI, LCD and Samsung keywords that's not going to do anyone any good.

4) Go heavy on text - It's great writing descriptions and product information, but don't write War and Peace.  Customers don't like to read!  They want short, sharp sentences or even better bullet points.  Sell the benefits of your product as quickly as you can to your visitors. Don't waste their time or yours with long-winded and pointless reams of text.

5) Ignore grammar and punctuation - This just doesn't look good at all.  If I'm paying good money for a product online, I want to at least know the seller has taken the time to proof read what the material they are using to sell to me.  If I see a product description littered with punctuation, spelling or grammar errors I lose confidence quite quickly in the whole operation.


I hope these are of some use,

Thanks,

Thursday, 20 August 2015

3 Layers of Static Code Analysis in PHP

Every developer should be running some form of static code analysis on their code regularly. A recent article I read about how this is done at Etsy makes for what I believe should be a minimum standard of code analysis for any team of developers work on a shared codebase. We shall assume you are committing your codebase to some form of version control on a regular basis.

The 3 layers can be summarised as:
  1. Sanity Checks
  2. Formal Checks
  3. Security Checks


Sanity and Syntax Checks


In Stage 1 we perform basically a sanity check of the code. Are there any errors, missing semi-colon's or just plain stupid things being committed to our repository and code base. This is essentially a case of running php -l against all our files being checked in or changed to make sure we catch these before they are committed and let you fix them before they are picked up by the wider team.


Formal Checks


This stage involves a more global analysis of the source code files, checking for thing such as:
  • Too many or too few arguments in a function/method call
  • Undeclared global or local variables
  • Use of return value of a function that actually returns nothing
  • Functions that have a required argument after an optional one
  • Unknown functions, methods, or base classes
  • Constants declared twice
This can be accomplished by using tools such as PHPCodeSniffer. This allows us to ensure the above are picked up, and also that our code is in compliance with our agreed coding standard. Any issues, the commit is bounced back with the opportunity to resolve before being integrated into the repository.


Security Checks


The final layer of analysis, the security checks can be more thorough and use tools to scan our code for OWASP vulnerabilities, or as Etsy do - scan the repository with Antivirus and assess for dirty URLs.

Etsy claim they use ClamAV to check for any files or bad code which might make it's way into the repo, such as MSWord or PDF files that are suspicious.  ClamAV also scans URL's and checks these against Google's Safe Browsing List to pick up on suspected Phishing or malware sites.

It is also possible to check here to ensure things like passwords aren't committed to repositories or specific naughty functions or processes are used.  This can then trigger alerts for code reviews or ping back to the developer advising to fix ASAP.


Your Source Code Is Now an AI Data-Boundary Decision

On 21 September, Belgian security company Aikido released an open-weight model designed for cybersecurity work that can run locally, without...