63% users fail to spot fake pop-ups


Recommended Posts

_45047901_popup226body.jpg

Internet users are unable to distinguish between genuine pop-up warnings messages and false ones, a study at North Carolina State University has found.

The study examined the responses of undergraduates to messages which popped up while they did other tasks on a PC.

Seeing the pop-ups as a mere annoyance the majority clicked 'OK'.

Fake pop-ups are a well-known vehicle for cyber-criminals to install harmful software on PCs.

"This study demonstrates how easy it is to fool people on the web," said co-author Michael Wogalter, professor of psychology at North Carolina State University.

"Be suspicious when things pop up. Don't click OK - close the box instead," said Dr Wogalter."

Legitimate message

Participants were fooled by the fake messages 63% of the time, even when warned that some of what they would be seeing would be false.

It suggests that the wording on genuine messages needs to be rethought, said Dr Wogalter.

"I don't know if you could develop a legitimate message that could not be duplicated and used illegitimately," he said.

Tony Neate, managing director of the UK's Get Safe Online campaign advised users to install a pop-up blocker.

"Browsers and most anti-virus software offers them. Pop-ups are either downloading something malicious or trying to sell me something so I just don't want them there at all," he said.

Source: BBC News

Link to comment
https://www.neowin.net/forum/topic/673478-63-users-fail-to-spot-fake-pop-ups/
Share on other sites

Have to say I agree with this. I can't tell you how many calls I get from people saying that a message popped up telling them that they had 1,500 viruses on their computer. Meanwhile, their virus scanner subscription expired a few years ago.

It's stupid ignorance of end users that causes this. People need to take the two seconds to actually read what is in front of their face instead of clicking the "X" or "OK". It's true, countless infections are caused by the end user being too ignorant to use a computer. It's quite sad.

Most of them have the XP Style if the user is a vista user then they might relise it is fake as your not really going to get an XP Style popup on a vista aero theme.

Not always true. Many pop-ups are ads prompted by the site you are visiting and use the GUI of your OS to display itself, so many pop-ups would look just the same as any window in Vista and XP.

Edited by lord_xenos

^^ Man that's just a bit OTT

As an experienced computer user these things stick out like a sore thumb, but with 63% of people clicking them by mistake kinda suggests that it's a common problem and not just a error of judgement.

It really is easy to fall for, unless you know how windows displays every single error message and that it won't be apart of the IE shell.

I find popup blockers out of date now in my opinion, it's time web browsers block these URL's by default. If sites like zedo.com want to be intrusive with Javascript then why should we allow it in the first place. Google doesn't do it with their advertisements, why should they?

If someone on the street came up to you saying "BUY THIS, BUY THIS" and started jumping up and down around you then something would be done about it. It should be the same with the Internet.

I can easily tell the difference between a popup and a legit message lol. Because most of them look more and more real I can see why people click them, but if your cursor changes while you are anywhere on the box don't click :| lol.

My mum used to fall for these :laugh:

Can someone actually tell me, are these kind of popups completely legal?

Some of them are pretty damn deceiving (fake virus scans that actually look like a running application, ect).

...

It's true, countless infections are caused by the end user being too ignorant to use a computer. It's quite sad.

...

Let me clarify that statement a bit. "to use a Windows computer".

Until such a time that Apple takes a significant enough share to warrant these spoofed popup assaults on naivete, it is a relatively safe computing platform for those who tend to be inexperienced (I prefer that over the term "ignorant" ) with computers in general.

If the up-front cost of buying an Apple computer is daunting or prohibitive, a knowledgeable family member can set up their inexperienced relative or friend with a handy limited user account, and withhold the admin password. This, obviously, has to be done with the computer user's permission (one does not have the right to essentially take over someone else's PC without their permission and understanding).

But those are examples of the types of steps needed to protect people from themselves.

It's stupid ignorance of end users that causes this. People need to take the two seconds to actually read what is in front of their face instead of clicking the "X" or "OK". It's true, countless infections are caused by the end user being too ignorant to use a computer. It's quite sad.

Not always true. Many pop-ups are ads prompted by the site you are visiting and use the GUI of your OS to display itself, so many pop-ups would look just the same as any window in Vista and XP.

i think you mean the oppisite, i would consider myself an end user, and i never read browser popups, because i dont get any, and if i do, i never click, i usally put my mouse over it though to see if its all flash, because flash ads = 100% crapware aomost always.

Theres hardly any legitimate posts, unless im on a forum or so,and think its maybe a new message, i dont click.

Source: BBC News

Most annoying popup's to me aren't these fake ones. but the ones where they have a fake X I hit the X to get rid of the window and off it goes to the site. Try to use Opera just for those, but even Opera can't fix all of those.

Let me clarify that statement a bit. "to use a Windows computer".

Until such a time that Apple takes a significant enough share to warrant these spoofed popup assaults on naivete, it is a relatively safe computing platform for those who tend to be inexperienced (I prefer that over the term "ignorant" ) with computers in general.

If the up-front cost of buying an Apple computer is daunting or prohibitive, a knowledgeable family member can set up their inexperienced relative or friend with a handy limited user account, and withhold the admin password. This, obviously, has to be done with the computer user's permission (one does not have the right to essentially take over someone else's PC without their permission and understanding).

But those are examples of the types of steps needed to protect people from themselves.

Call it what you want, be it ignorance, stupidity, uninformed, or inexperienced. It all results in infections on the user's PC. Yes I said PC. I know Macs are less likely to be targeted for the reasons you already stated. I've met many people from both sides of the spectrum. Some have enough common sense to decipher a false pop-up, others aren't so fortunate and constantly go to the wrong sites, and click the wrong things. I do call it ignorance when a user does not pursue knowledge of what they are actually doing and what they can do to prevent what they know happens to "inexperienced" users (ie. infections). As a user of a PC and being on the Internet, I believe it is a responsibility this day in age to be informed.

Edited by lord_xenos
lol @ the Antivirus 2009 popup

clicking that makes for a fun time trying to get it off afterwards

Very true. The trick is to catch it as soon as it happens. I've been lucky a few times when the user knew they screwed up as soon as they clicked on the pop-up. They call me and I fix it up quickly. I've also been not so lucky...having clients wait a week before finally noticing something's not right.

Seriously though. When confronted with a pop-up such as in my example below, what choice would most users have? Using simple javascript, it could be made to mimic whichever OS it was running on, and even appear in a modal way, not allowing access to the site behind it until Ok is pressed.

post-107175-1222286740.jpg

Of course you or I could prevent it, but we can't always be there to prevent the typical end user from clicking what shouldn't have been clicked.

That makes you point a finger at somebody else! Why are ISP's not looking at ways to cut off these websites? Why doesn't Microsoft implement such a thing to Windows Defender, why doesn't I.T repair guys do a proper job instead of just cleaning.

I just believe that a good 70% of infections could be prevented by URL filtering.

Why isn't something being done? Money.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft: Windows 11 could finally solve a major issue across AMD, Nvidia, and Intel GPUs by Sayan Sen While Microsoft has been trying to improve it, Windows 11 is definitely not flawless, as even today some issues are taking a year to publicly acknowledge. However, one area of trouble that may finally see much better results soon is graphics driver crashes. Work on graphics driver timeouts, also called Timeout and Detection Recovery (TDR), is not new as the latest WDDM 3.2 also has specific improvements regarding it. Windows Display Driver Model (WDDM) version 3.2 is supported on Windows 11 24H2 and 25H2. However, with the upcoming version 26H2, TDR crash diagnosis could go to the next level as Microsoft is introducing a new DirectX 12 API feature called "DirectX Dump Files". Similar to how system memory dump files work when a system crashes or freezes or encounters any such major issue, DirectX Dump Files (DDF) will essentially record a snapshot of the GPU execution right at the moment a graphics-related crash or hang or freeze occurs, so that developers can better understand and diagnoze these TDR and timeout detection errors. The dump will be available as a .dxdmp file for analysis and it will be a comprehensive dump file generated with detailed insights about the hardware, drivers, Windows, as well as the affected application. This should be another welcome change in this department. Earlier at GDC 2026, when the technology was first debuted, Microsoft had shared more details regarding it. The company had explained how DDF is designed to gather data from every layer of the graphics stack into a single file, eliminating the need for developers to manually correlate logs from multiple tools. As mentioned above, the dump can contain a lot of useful details like GPU hardware state information such as register values, shader program counters, page fault virtual addresses, shader memory data, and command buffers. Alongside that, it also captures DirectX runtime and kernel information, including D3D objects, pipeline state objects, device error data, adapter details, and CPU call stacks. Microsoft says the feature has been built around two primary use cases: retail device removals and local device removals. The former allows developers to collect crash information from end users' systems in the field, while the latter helps QA teams and developers investigate issues on test machines. Developers will also be able to include up to 2 MB of custom application data through new D3D12 APIs, providing additional context for troubleshooting. In addition, Microsoft is introducing three dump collection modes ranging from zero-overhead capture, which has no runtime performance impact on supported hardware, to higher-detail modes that collect more vendor-specific debugging data. On compatible Tier 2 hardware, zero-overhead dumps will be enabled by default, meaning developers may begin receiving useful crash diagnostics without making any code changes. The table below explains the three tiers: Tier Description NO_OVERHEAD Enables crash capture with no runtime cost and is suitable for broad deployment MEDIUM_OVERHEAD Provides a balance, capturing additional diagnostic data with moderate impact HIGH_OVERHEAD Collects the most detailed GPU and driver state available, enabling deeper investigation at the cost of higher runtime overhead In terms of availability, the company expects broader release to be around the fall of 2026, which should be right around the time when Windows 11 version 26H2 lands. Right now, DirectX Dump Files are available as a preview and currently, only AMD has the compatible AgilitySDK Developer Preview driver version 26.10.07.02. You can find the official announcement post here on Microsoft's website.
    • And with SO much better perf than the laggy mess that is Files.
    • BrowserOS 0.46.0 by Razvan Serea BrowserOS is a free, open-source Chromium-based browser that runs AI agents natively, offering a smarter, more productive browsing experience. It supports Chrome extensions and integrates AI agents to automate tasks, fill forms, and streamline workflows. Your data stays on your computer: you can use your own API keys or run local models via Ollama, making it a privacy-first alternative to tools like Perplexity, Comet, or Dia. With built-in productivity tools and app integrations, BrowserOS boosts efficiency while keeping control firmly in your hands. Being Chromium-based, BrowserOS lets you effortlessly import your bookmarks, passwords, and Chrome extensions in just a few clicks. BrowserOS works with OpenAI GPT models, Anthropic Claude, Google Gemini, and local AI models via Ollama or LMStudio. You can use your own API keys and effortlessly switch between providers. BrowserOS Agent Your AI productivity assistant that organizes and manages your browsing effortlessly Quickly list, group, or close tabs Save and resume browsing sessions Search your history and organize bookmarks Switch instantly to the tab you need BrowserOS Navigator – Automate web tasks with ease Navigate websites and search automatically Interact with pages without manual effort Handle repetitive tasks in seconds What makes BrowserOS special Feels like home - same familiar interface as Google Chrome, works with all your extensions AI agents that run on YOUR browser, not in the cloud Privacy first - bring your own keys or use local models with Ollama. Your browsing history stays on your computer Open source and community driven - see exactly what's happening under the hood MCP store to one-click install popular MCPs and use them directly in the browser bar (coming soon) Built-in AI ad blocker that works across more scenarios! BrowserOS 0.46.0 changelog: Run Claude Code & Codex right in your browser — We've extended the agent harness to bring full coding agents into BrowserOS. Claude Code and Codex now come bundled and plug straight into the assistant, so you can drive your browser with the agent — and the subscription — you already use. A brand new experience — A redesigned new tab, a calmer composer, and a rebuilt command center for switching between agents. The whole assistant is cleaner, faster to reach, and easier to live in. New MCP tools — We rebuilt the browser tool surface from the ground up — a tighter, more reliable set of tools for agents to drive the browser. Plus one-click install of BrowserOS as an MCP server into the agents you already run, with automatic URL sync. Chromium 148 — Updated to the latest Chromium base with all recent upstream fixes and security patches. Streamlined — We've pulled back a few features that weren't getting much use — Skills, Soul, and Memory — so we can focus and ship better versions of them soon. Download: BrowserOS 0.46.0 | 181.0 MB (Open Source) Download: BrowserOS for macOS | 485.0 MB Links: BrowserOS Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      590
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      67
  • Tell a friend

    Love Neowin? Tell a friend!