{"id":3553,"date":"2020-08-23T22:03:59","date_gmt":"2020-08-23T16:33:59","guid":{"rendered":"https:\/\/www.suramya.com\/blog\/?p=3553"},"modified":"2022-06-16T15:19:05","modified_gmt":"2022-06-16T09:49:05","slug":"mozilla-thunderbird-has-a-link-mismatch-detection-feature-to-protect-from-phishing-scams","status":"publish","type":"post","link":"https:\/\/www.suramya.com\/blog\/2020\/08\/mozilla-thunderbird-has-a-link-mismatch-detection-feature-to-protect-from-phishing-scams\/","title":{"rendered":"Mozilla Thunderbird has a &#8216;Link Mismatch Detection&#8217; feature to protect from Phishing &#038; Scams"},"content":{"rendered":"<p>Yesterday I was trying to register for a new service and as always I had to share my email address and wait for the confirmation\/validation email to verify that the email address I had provided was a valid one. Once I finally got the email it had a clickable link to validate my email address that looked like the screenshot below:<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"46\" src=\"https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213414.png\" class=\"alignnone size-full wp-image-3555\" srcset=\"https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213414.png 640w, https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213414-300x22.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><br \/>\nClickable link for email address validation<\/center><\/p>\n<p>Since this was an email I was expecting and wanted to create an account, I clicked on the link and got a surprise. Instead of immediately taking me to the link I had clicked on Thunderbird popped up the following pop-up telling me that the link was taking me to another website than what the link text was indicating. This is new behavior that I believe was implemented in Thunderbird 68 but haven&#8217;t found the release notes confirming it. (I didn&#8217;t really spend a lot of time searching to be honest)<\/p>\n<p><center><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213116.png\" alt=\"\" width=\"556\" height=\"161\" class=\"alignnone size-full wp-image-3554\" srcset=\"https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213116.png 556w, https:\/\/www.suramya.com\/blog\/wp-content\/uploads\/2020\/08\/Screenshot_20200823_213116-300x87.png 300w\" sizes=\"auto, (max-width: 556px) 100vw, 556px\" \/><br \/>\nLink Mismatch Detected<\/center><\/p>\n<p>In this case it was a benign reason because the link was taking me to a tracking site before redirecting to the email confirmation page. But the benefits are immediately obvious as this would flag the links on the phishing\/scam emails that pretend to come from a bank\/email provider\/facebook but redirect users to a Phishing site and prompt users to verify if they are going to the correct site. <\/p>\n<p>Unfortunately the fix is not perfect and needs more work as this would include all links in newsletters etc that include tracking links (which is pretty much all of them). If users constantly get the popup then there is a high probability that they will get conditioned to click on the First button to go the site the link is taking you to without reading the text fully. <\/p>\n<p>Some of the users will find this to be annoying and want to disable it, so below are the steps to disable the Phishing checks in Thunderbird (<b>not recommended<\/b>). Only make this changes if you are absolutely sure of what you are doing and take full responsibility of the fact that you disabled the Phishing checks. I will not be responsible if you disable the checks and then end up with an empty bank account after having your account Phished. Also, I found the instructions on the <a href=\"http:\/\/forums.mozillazine.org\/viewtopic.php?f=39&#038;t=3059164\">Mozilla Forum<\/a> but haven&#8217;t tried them myself so like anything else you find on the internet please validate the steps and only follow if you are sure that they are safe :).<\/p>\n<blockquote><p>There are four phishing preferences.<\/p>\n<p>* mail.phishing.detection.enabled<\/p>\n<p>i.e. Tools > Options > Security > Email Scams > Tell me if the message I&#8217;m reading is a suspected email scam<\/p>\n<p>* mail.phishing.detection.ipaddresses<br \/>\n* mail.phishing.detection.mismatched_hosts<br \/>\n* mail.phishing.detection.disallow_form_actions<\/p>\n<p>Try setting the mail.phishing.detection.mismatched_hosts preference to false in the about:config window, then restart and test again.<\/p><\/blockquote>\n<p>It&#8217;s great that the Thunderbird team is adding more and more features to make email safer. Looking forward to more such features in TB. <\/p>\n<p>Well this is all for now. Will post more later.<\/p>\n<p>&#8211; Suramya<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yesterday I was trying to register for a new service and as always I had to share my email address and wait for the confirmation\/validation email to verify that the email address I had provided was a valid one. Once I finally got the email it had a clickable link to validate my email address [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"activitypub_content_warning":"","activitypub_content_visibility":"","activitypub_max_image_attachments":3,"activitypub_interaction_policy_quote":"anyone","activitypub_status":"","footnotes":""},"categories":[18,2],"tags":[],"class_list":["post-3553","post","type-post","status-publish","format-standard","hentry","category-computer-software","category-techie-stuff"],"_links":{"self":[{"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/posts\/3553","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/comments?post=3553"}],"version-history":[{"count":5,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/posts\/3553\/revisions"}],"predecessor-version":[{"id":3560,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/posts\/3553\/revisions\/3560"}],"wp:attachment":[{"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/media?parent=3553"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/categories?post=3553"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.suramya.com\/blog\/wp-json\/wp\/v2\/tags?post=3553"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}