Pathwise

How the Internet Works · Lesson 12 of 12 · 12 min

Staying safe: look-alike sites and second steps

Turn everything from this course into one habit: read an address bar in three seconds, spot the pattern of a rushed login, and know which two habits catch what your eye misses.

READ THE ADDRESS

The real domain is right before the slash

In an address like https://bank.example/login, the domain is the part between https:// and the first single slash: bank.example. Everything after that slash is just a page on that domain, and it can say anything. A look-alike address is built to fool a quick glance at that one piece: swapping a letter for a similar one, an l for a 1, or bolting an extra word onto a name you trust.

https://bank-examp1e.co looks close to bank.example at a glance. Read it closely: a digit 1 stands in for the letter l, and it ends in .co instead of .example — a different domain entirely.

THE PADLOCK'S LIMIT

The padlock proves encryption, not honesty

A closed padlock means your connection to that exact domain is encrypted: nobody in between can read it. It says nothing about who owns that domain or whether they're trustworthy. Anyone, including a scammer, can get a padlock for a domain they registered themselves.

https://bank-examp1e.co can have a perfectly valid padlock. It just means the fake site talks to you privately — the theft still works.

Check yourself

Amir gets a link, opens it, and sees a closed padlock next to https://bank-examp1e.co. What should he conclude?

  1. The padlock proves it's the real bank, since a fake site could never get a certificate and a padlock of its own
  2. It's a look-alike domain; the padlock only says this connection is private, not that the site is genuine
  3. Since it starts with https://, it's automatically safe
  4. There's nothing to check further once a padlock is present
Show the answer

It's a look-alike domain; the padlock only says this connection is private, not that the site is genuine

Right. bank-examp1e.co is a different domain from bank.example, a letter-for-digit swap and all. The padlock only encrypts the connection; it doesn't vouch for who's on the other end.

THE PATTERN

Rushed logins are the real tell

The single strongest sign of a fake login page isn't a typo, it's the feeling of being rushed: "your account will be suspended", "verify within 10 minutes", "unusual activity, log in now". Real services rarely demand you log in immediately through a link. When a message pushes urgency at you, that pressure is the pattern to notice, before you even check the address.

A text claiming your parcel is stuck and asking you to "confirm your address" by logging in within the hour is built to make you skip the address bar entirely.

Check yourself

A message that tells you your account will be suspended in 10 minutes unless you log in right now is, by itself, a warning sign worth slowing down for.

Show the answer

True

True. Urgency is the pattern, not a side detail. Real services rarely force an immediate login through a link, so that pressure alone is a reason to stop and check the address before typing anything.

Step through it

  1. The real address

    This is the real address bar: a closed padlock and https://bank.example. Nothing else is on screen yet — this is the baseline to compare against.

  2. A look-alike, side by side

    A second address bar appears underneath with an open orange padlock: https://bank-examp1e.co. The "1e.co" part is highlighted: a digit 1 stands in for the letter l, and the address ends in .co instead of .example — a different domain.

  3. Where a stolen password goes

    Under the fake bar sits a login form: the username "sara" and a dotted-out password. An orange arrow runs straight from the password field to a hooded figure on the right: on the fake page, whatever you type is sent directly to whoever built it.

  4. A second step stops it

    A blue shield marked 2FA now blocks that same arrow, with an X right before it reaches the attacker. Even with the password in hand, the thief is stopped: a second step, a code from your phone, is something the fake page never had.

Check yourself

Match each part of the picture to what it means

Show the answer
  • The open orange padlock on the second bar → A valid connection, but to a fake domain — the padlock alone doesn't help
  • "1e.co" instead of ".example" → A digit swapped for a letter, and a different ending
  • The arrow from the password field to the hooded figure → A stolen password going straight to the attacker
  • The 2FA shield with an X → A second step that stops the password alone from working

Three habits that catch what your eye misses

  • A password manager only fills a password into the exact domain it was saved for; on bank-examp1e.co it simply offers nothing, even if you don't notice the swap.
  • A second step, 2FA, a code from an app or SMS, means a stolen password alone isn't enough to get in.
  • Public Wi-Fi is fine for sites you reach over HTTPS, the padlock; typing a password into a login page that isn't on HTTPS, on any network, is the real risk.

Check yourself

Sort each situation as safe or a warning sign

  • Reading your usual news site over HTTPS on café Wi-Fi
  • An SMS demanding you log in within 10 minutes or lose your account
  • Your password manager offers to fill your bank password on bank.example
  • A login page reached from an email link that has no padlock at all
  • Entering a 2FA code the app on your phone generated
  • Your password manager stays empty on a page that looks exactly like your bank
Show the answer

Safe to continue: Reading your usual news site over HTTPS on café Wi-Fi, Your password manager offers to fill your bank password on bank.example, Entering a 2FA code the app on your phone generated

Stop and check: An SMS demanding you log in within 10 minutes or lose your account, A login page reached from an email link that has no padlock at all, Your password manager stays empty on a page that looks exactly like your bank

Your checklist before you log in

  • Read the domain itself, before the first slash — not just the start of it.
  • A padlock means encrypted, not honest; check who owns the domain, not just that it's https://.
  • Being rushed to log in right now is the biggest warning sign there is.
  • Trust your password manager's silence: if it won't fill the field, stop.
  • Turn on a second step (2FA) everywhere it's offered, and keep public Wi-Fi logins to HTTPS pages only.

Keep it, don't just read it

Pathwise brings each idea back just before you'd forget it, with a quick question. Free on Android and on the web, in English and Persian.

Cafe Bazaar Myket Open the web app

All lessons in this course

  1. What happens when you open a website
  2. Addresses: how a device is found
  3. Packets: chopping a message into pieces
  4. DNS: the internet's phone book
  5. Routers: finding a path, and another one
  6. TCP: making sure everything arrives
  7. HTTP: asking for a page and getting an answer
  8. HTTPS: what the padlock protects
  9. Caches and CDNs: why the second visit is fast
  10. Wi-Fi, cables and the sea floor
  11. Why it feels slow: latency and bandwidth
  12. Staying safe: look-alike sites and second steps