Tim Anderson

Flimsy filters won’t cut phishing lines

The phishing protection offered by the Internet Explorer 7 and Firefox 2.0 browsers may be all but worthless to users

Written by Tim Anderson

According to a test commissioned by Mozilla and carried out by SmartWare, Firefox 2.0 blocks around 80 percent of known phishing URLs and Internet Explorer 7 blocks around 65 percent as long as users enable automatic web site checking.

Phishing sites are normally promoted by unsolicited emails that try to trick users into entering their authentication details into a mock-up of a legitimate bank or auction site. I’m sceptical of the value of Mozilla’s test because there is no mention of that critical factor, the age of the phishing site. Typical phishing sites have a very short life, and are presumably most effective in the first few hours as the emails arrive and hapless users follow the links.

Shortly after the release of Explorer 7 and Firefox 2.0, I carried out my own test on the next phishing email I received. Although it was an obvious fraud, both browsers gave the phishing site a clean bill of health. I reported the site, and it took Firefox three hours to blacklist it and Explorer 22 hours. Firefox comes out on top, but even three hours is long enough for thousands of users to enter their details.

There is also a danger of false reassurance. “This is not a reported phishing web site,” said Explorer’s dialog when I asked it to check, even though I myself had reported it 12 hours earlier. Yet Digital Resolve, which supplies data for Microsoft’s phishing filter, stated in September that its technology offered users real-time, positive assurance that they were at a valid web site. Such declarations mean little. If my experience is typical, then the phishing filters in both browsers are nearly worthless.

The inherent problem is that the filters rely mainly on a blacklist for their effectiveness. This fails for the same reason that signature checking fails to eliminate virus infections. Blacklist-based security tells the user, “It’s OK unless I say it is not.” Whitelist-based protection, on the other hand, says, “It’s not OK unless I say it is,” which is vastly more effective. But whitelists are prone to false positives: legitimate sites that are branded as bad. Whitelisted sites can also be hijacked by fraudsters. The site I found was one such example. The phishing page had been inserted into another site without the owner’s knowledge.

I would like to see users offered a three-tier ranking: green for a web site with a valid SSL certificate, amber for an unknown site, and red for a known phishing or malware site.

The failure of anti-phishing filters highlights the silliness of relying on username/password combinations to protect financial information. The real advance in Explorer 7 is not its phishing filter but its InfoCard integration, which offers a route to strong authentication. And as phishing is a by-product of spam anyway, if we fix the spam email problem, the phishers will have no line.

Tags:

reader comments

related articles

PayPal fixes phishing flaw

Online payment service changes code to block phishing attack 19 Jun 2006

 

International phishing gang arrested

Seventeen members of gang arrested following FBI investigation 07 Nov 2006

Study blasts failing phishing toolbars

Carnegie Mellon report shows inability to identify sites across the board 22 Nov 2006

Sharp rise in phishing emails

Concern for online banks and customers as report shows increase of 81 per cent in just six months 28 Sep 2006

Phishing attacks against Europeans drop

US banking customers suffer worse, while overall the number of attacks steady 14 Jun 2006

Mozilla claims anti-phishing crown

Firefox catches 82 per cent of phishing sites 15 Nov 2006

Major phishing scam thwarted this week

SoftScan claims to have stopped 70,000-strong phishing email attack 05 Jul 2006

HSBC boosts e-banking security

Bank hopes to strengthen security for customers using internet services 25 Apr 2008

Hackers infiltrate legitimate websites

Six out of 10 popular sites infected in the past six months 30 Jul 2008

OFT highlights scammers tricks

Five ways fraudsters lighten your wallet 08 Feb 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation