Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Browsers, phishing, and user interface design
Scott Granneman, 2006-06-05

Phishing works for so many reasons, we need to rethink browser and user interface design to provide some real-life security to the average user who doesn't see or understand the security cues.

Comments Mode:
Sure. Lots of ideas... 2006-06-05
Anonymous (2 replies)
Your First Statement Is Right 2006-06-06
Anonymous (1 replies)
Re: Your First Statement Is Right 2006-06-07
Anonymous (1 replies)
Re: Sure. Lots of ideas... 2006-06-24
Anonymous
Education & Two-factor authentication 2006-06-07
Wolfy
Need I say more? Well, probably yes.

The article successfully points out that educating users into the various security features present in the web browser is one thing, but when even experienced users fall for the 'vv = w' in a phishing URL, there is something that the legitimate site needs to do to authenticate themselves back to the user.

Alliance & Leicester's online banking has recently introduced such a two-factor authentication tool whereby when you first sign up to the service, you are requested to choose an image from a bank of thousands. When you next log in, the image is displayed before you are prompted for your password so that you know that you are logging into the legitimate site.

This works well alongside A&L's more complex digital fingerprint to authenticate the user to the site.

Will this sort of thing help the majority of users, though, especially those who reload a phishing site just to see an animated bear, and aren't even aware that criminals may want to even set up these fake sites?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/405/33702#33702
Send them to AOL 2006-06-07
Anonymous
Stop babying people 2006-06-09
Anonymous
Wrong end to start patching 2006-06-12
Thomas Nilsen (1 replies)
Re: Wrong end to start patching 2006-06-12
Anonymous
Ingredients of possible solutions 2006-06-16
S. Lo Presti
Users ignore alert messages... 2006-06-20
Anonymous
simple: 2006-06-24
ailaG







 

Privacy Statement
Copyright 2007, SecurityFocus