phishing

Paypal says avoid Safari

by alec on February 29, 2008

Paypal is warning users to avoid Safari, and choose IE, Firefox or Opera instead.  Why?  Safari doesn't implement the modern anti-phishing systems that other browsers do.  It's good advice.  Over the past two years, with the emergence of strong anti-phishing technologies, fraud due to fishing is way down. 

Not many people use Safari any more, in any case.  In our own measurements, we've seen Safari use in the 1% range.  It seems that most Mac users prefer Firefox.  Moreover, Safari itself has trouble with web pages that IE and Firefox sail through.

The tragedy for users is that Safari is the browser on iPhone.  As iPhone gains popularity, expect more iPhone users to be caught in phishing scams if Apple doesn't choose to modernize the browser.

{ 0 comments }

Looking for a quick, easy speed-up for your Internet?  Try OpenDNS.  Simply log in to your router and substitute the IP addresses of their DNS servers for your ISP's DNS.  Reboot your PC's and Router.  Presto — internet pages which used to load slowly are now lickety split.

The brainchild of entrepreneur David Ulevitch, OpenDNS is a speedy, modern and secure DNS system.  Designed to be faster, outwit phishing schemes, and support applications as well, it's a clear and immediate improvement over the old system I was using.  For example:

  • it can automatically correct spelling errors in site names, taking you to the domain you wanted, rather than the one you typed. Type Yahoo.cmo, and it will automatically make it Yahoo.com.
  • it can be configured to block porn sites, and automatically blocks known phishing sites.
  • it has HUGE DNS caches, and they're distributed all over the world on their own network.  Fast, and reliable.
  • you can create shortcuts to your favorite sites or applications.  For instance, you can configure it so that when you type "call andy abramson" into your browser, it will launch Skype and call Andy.

The price?  It's all free, apparently subsidized by an advertising deal with Yahoo search. 

 

{ 1 comment }

VoIP Phishing Before Congress

October 19, 2006

There is an important post on O’Reilly’s ETel this morning by TalkPlus CTO John Todd.  It concerns the Truth in Caller ID Act currently before the United States Congress.  Specifically, the act seeks to amend the US Communications Act of 1934 to prohibit the provision of “deceptive” caller ID information.  It’s remarkably unclear on what “deceptive” [...]

Read the full article →

Phishing with VoIP

April 26, 2006

Here’s a fascinating new development.  Cloudmark has announced anti-phishing software for VoIP systems.  The latest new criminal scam is to clone a bank’s IVR using Asterisk, or some other inexpensive IVR system, and then send email to users asking them to call the bank’s (er scammers) number, and enter in account and PIN information.  Adam J. [...]

Read the full article →
Alec on LinkedIn Alec on Twitter Alec on Facebook Calliflower on Youtube RSS Feed Contact me