Roger Howorth
Roger Howorth

Trust proves elusive on the internet

As fraudsters become more sophisticated, users need an easy way to check the identity of web sites

Written by Roger Howorth

The trouble with the internet is that it’s unreliable, untrusted and insecure. We use some clever add-ons to the Internet Protocol (IP) to address two out of those three problems. But currently there is no widely accepted solution to the internet’s untrustworthiness.

The Transmission Control Protocol (TCP) can be used to make IP reliable and guarantees that if you send some data over the internet you will know that it has been received properly. Likewise, SSL and the closely related TLS encryption protocols can handle the security of data in transit.

But when we click on a link do we actually end up at the site we wanted? And when we get an email is it really from the person we think it’s from? We don’t have a bulletproof protocol for verifying the identity of a web site or of someone sending email, and so we have spam and phishing.

A recent report called Why Phishing Works, by Dr Rachna Dhamija et al, reveals some interesting research suggesting the problem won’t be solved by schooling users. “Neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vulnerability to phishing,” they wrote.

The researchers also found the overall quality of bogus material makes a difference. “Good phishing web sites fooled 90 percent of participants,” they added.

Many people took more notice of sites’ animations than they did their URL or SSL status. More worryingly, other research indicates that phishers could improve their success rate by using information about victims from social networks to personalise messages.

CA’s vice-president of security, Simon Perry, recently said we need to rethink this type of authentication. He argued that web sites should authenticate themselves to users just as users must authenticate themselves to some sites.

In a similar vein, I came across an interesting software development project called Cake, which attempts to sort out our untrustworthy internet by using public and private key pairs instead of email and web addresses.

Rather than typing URLs or email addresses, people would use public keys as addresses. New key servers could then look up the IP address associated with the public key to gets its related private key, and perhaps check that the sender details are correct.

The idea is sketchy and I’m not sure anyone has found the complete answer to spam or phishers just yet. It seems that at least one new protocol is required.

Tags:

reader comments

related articles

 

Industry lays into 3-D Secure

Verified by Visa and MasterCard SecureCode are flawed, say experts 11 Apr 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation