There are many methods to ensure that a login prompt is legit, but a new phishing technique
discovered by researchers at password management company MyKi throws the usual precautions out the window. Phishing is a fraudulent attempt to gain sensitive personal information through posing as a legitimate entity, such as a company or a website. It is a form of social engineering and is very popular and successful due to the willingness of many to take things on the internet at face value.
Recent years have shown an increase in phishing attempts leading to serious data breaches, as was the case in the San Diego Unified School District breach involving social security numbers and other personal information of over 500,000 students and staff.
The only way to tell is to try to drag the window away from the browser. If it is fake then part of the window will disappear past the edge of the browser instead of moving as a separate entity. While harvesting Facebook login credentials may not seem like much of a threat beyond seeing what cat pictures were posted by friends, many people use the same or similar credentials across many sites and this gives attackers a jump ahead in trying to gain unauthorized access to other accounts. Also, this same technique could show up in other areas in the future, such as e-commerce sites asking for PayPal logins or something similar.