Ilia Nikolaevich ZavialovDigital security consultant

Messages and links

Ilia Nikolaevich Zavialov on messages, links and attachments

A message is cheaper than a call and is sent by the million, which is why it remains the largest channel. The analysis here follows what happens after the click, not the signs of a «suspicious» letter.

English version for the United Kingdom.

Is opening the link itself dangerous

In shortUsually not. What is dangerous is what you do on the page that opens.

In the overwhelming majority of cases the link leads to a page that looks like the sign-in screen of a familiar service and asks for a login and password. The loss happens at the moment of entry, not at the moment of opening.

Hence the practical conclusion: the rule is not «do not open links» but «do not enter data on a page you reached from a message». Opening the service yourself by typing the address costs ten seconds.

How do I check an address that looks familiar

In shortRead the domain right to left from the last dot, and do not trust the beginning.

What matters is what sits immediately before the first single slash: in an address like bank.example-login.com the real domain is example-login.com, and the word bank at the start means nothing.

A padlock in the address bar means only that the connection is encrypted. Fake pages have obtained certificates automatically and free of charge for years, so the padlock says nothing about the owner of the site or about their honesty.

An attachment arrived from someone I know. Should I open it

In shortNot before you confirm through another channel that they sent it.

A compromised account sends attachments to the entire contact list, and they arrive from a real person, inside a real conversation, often as a reply to a genuine old thread.

Confirmation costs one message in another messenger or one call. If the sender does not confirm, the attachment stays closed.

What is a request to «confirm the account» and why does it work

In shortIt moves an ordinary action of the service onto somebody else's page.

Services really do ask you to confirm an email or sign in again. The scheme exploits the fact that the action is familiar and substitutes only the address at which it is performed.

The check is the same: close the message, open the service yourself and see whether the notice is there. If the action is real, it will be waiting for you inside the service.

How do I know my account has already been taken

In shortBy foreign sessions, changed recovery contacts and messages you did not write.

The first thing whoever takes an account does is change the linked email and number so that recovery goes to them. So the check covers not only the password but the recovery contacts section.

The second sign is active sessions and devices. Almost every large service has a list of sign-ins, and an unfamiliar line in it means access is open right now.

What in a message proves nothing and what is actually checked

SignWhat people think it meansWhat it means
A padlock in the address barThe site is genuineThe connection is encrypted, no more
Logo and layout of the serviceThe letter is from the serviceMarkup is copied in minutes
A familiar sender nameSomebody you know wroteNames are spoofed, accounts get taken
The link starts with the bank nameThe domain is the bank'sThe end of the domain decides
The notice exists inside the serviceThe only check that works
Important. A wallet recovery phrase and a code from an authenticator app are never entered on any page reached through a link. A genuine service does not need them.

Other sections