Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Universities study why phishing works
Kelly Martin, 2006-03-31
Comments Mode:
Universities study why phishing works 2006-04-02
TJ (1 replies)
Actually, they got the high-hanging fruit, too. 2006-04-05
Roger (1 replies)
Re: Actually, they got the high-hanging fruit, too. 2006-04-07
TJ (1 replies)
Re: Re: Actually, they got the high-hanging fruit, too. 2006-04-10
Roger (1 replies)
> It's not how smart you are, it's your critical thinking skills,

While critical thinking is important and admirable, I can't agree that this is the core of the problem. The core of the problem is that internet banking was foisted on us by banks to shave a few more pennies from their costs by sacking more tellers. It is badly thought out, badly implemented, and built on a half-baked infrastructure.

The infrastructure at present is so rickety that there are sites were it is really, really difficult, even for an expert, to be sure. The amount of effort in fact is so great that if you are really doing it properly, it would be much MORE convenient to walk a few blocks to the local branch and stand in line for a while.

And both the sophistication and intensity of phishing is rapidly increasing. For example, we have as yet seen only small scale use of DNS poisoning. When it becomes more common, the old standby advice of "never use a URL from email, login to the site's main page by typing in the URL" will no longer work. We can then expect the rate of victimisation to rise from the already shocking current level of 3% to perhaps 10 times that, which is a level sufficient to cause an economy to collapse.

Before that happens, we need to get the message out: in its current form, internet banking (often) is NOT safe. Refuse to use it until the banks get their house in order.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/newsbriefs/176/875#875
Universities study why phishing works 2006-04-05
Anonymous (1 replies)
Wrong 2006-04-07
Anonymous (1 replies)
No need for this 2006-04-07
TJ (1 replies)
Re: No need for this 2006-04-10
Anonymous (1 replies)
Re: Re: No need for this 2006-06-08
Gaz







 

Privacy Statement
Copyright 2009, SecurityFocus