During the user study, users were hesitant to click on the link provided in the standard greeting. However, once
they accepted that the study required them to click on links, they assumed any link presented by PFC was trustworthy. In
practice, an attacker can exploit users who trust PFC messages. For instance, a malicious service provider or an active attacker on an insecure link could inject a malicious link into the standard greeting (or any other PFC message) in order to
exploit an unsuspecting user that already trusts PFC messages.