Bugwatch: In cyberspace, nobody knows you're a phish

The latest social engineering scam uses phoney websites to lure unsuspecting users into divulging personal information

Written by Jay Heiser

Each week vnunet.com asks a different expert to give their views on recent security issues, with advice, warnings and information on the latest threats.

This week Jay Heiser, chief analyst at TruSecure, warns against the increasing threat from email 'phishing' scams designed to separate surfers from their hard earned cash.

The cartoon in which one dog explains to another that on the internet 'nobody knows you're a dog' is easily understood by anybody who has used the internet.

Everything is virtual and all content can potentially be copied, replayed and altered, providing a unique opportunity for hackers.

'Phishing' is a form of social engineering attack that exploits the means to mask an identity on the web. Victims are encouraged to visit phoney websites that spoof those of legitimate organisations, often through a spam email.

Lured to a phishing site, users are asked to enter some sort of exploitable personal information, such as a Pin, password or bank account number.

The majority of active web users have encountered some sort of phishing lure, and more are being trolled past their noses every day.

So far, the lures are not very attractive, and very few surfers have been caught. But the phishers are becoming more prevalent and more skilful, and real people are starting to lose real money.

Phoney websites are nothing new, but they are becoming more common and much more sophisticated. It is no longer just kids engaging in a bit of electronic graffiti or political protest; highly motivated criminals are using web spoofs in the hope of stealing personal information for financial gain.

This year, the fraudsters are honing their ability to deceive. Aiming squarely at the UK retail banking customer they've begun spoofing the sites of major high street banks.

No one can predict how big the problem will become, but it is fair to say that the publicity associated with fake sites is reducing customer confidence in doing business on the web.

Ironically, technical solutions for this problem are already built into web browsers and web servers. When that little padlock icon appears at the bottom of the browser, it means that a Secure Socket Layer session has been set up between the browser and the web server.

By itself, an SSL connection is not sufficient to ensure that a website is genuine. Surfers must take the initiative to verify manually its identity by clicking on the padlock icon, and following several additional steps.

Unfortunately, this process is not the least bit intuitive and is so inconvenient that even security professionals rarely bother to follow it through.

It is a smart, logical solution, but it is also a design that ignores human factors. Even worse, the lack of interest in SSL authentication has resulted in managerial sloppiness.

Many sites have digital certificates that have expired or contain the wrong URL, making it impossible correctly to verify the site's identity.

Hardware tokens have proved to be easier to use. Authentication tokens create a password that is only valid for a limited period of time and can only be used once. Although such devices are expensive to provide and administer, some banks have offered them to customers.

Tokens are a great way to protect passwords from theft, making them normal practice for high-end e-commerce situations.

These devices are not really designed to solve the problem of proving the identity of a server; they are only meant to prove the identity of the user.

They make it difficult or impossible to steal a useful password, so they do protect the user, but they still cannot prevent users from being fooled by spoofed sites.

The need to verify the identify of websites and web users was understood over a decade ago when the first web browsers were being designed. Verification technology was implemented, but unfortunately a practical human interface was never really completed.

It is amazing that we've been able to go for so long without this becoming a problem. But it is now becoming a serious issue, especially when it is putting into question the reputation of leading financial institutions.

Clearly the internet population must be taught how to properly evaluate the digital certificate information made available through SSL, but new technology has to be developed to protect users who can't protect themselves.

My educated guess is that we will live with this problem until the rate of successful phishing attacks becomes alarmingly high and jolts the IT community into action.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Bugwatch: Foiling phishers

Formulating an effective anti-phishing strategy is vital 07 Apr 2004

 

Online phishing uses new bait

One click sends unwary users to fake websites 06 Apr 2004

Phishing still on the increase

Finance, retail and ISP customers primary targets of attacks 17 Mar 2004

Xmas shoppers warned on rising card fraud

Consumers told to be extra vigilant when buying online 12 Nov 2003

Firms warned over scams

Simple steps can help defuse email scams designed to hoodwink users 05 Nov 2003

related white papers

today's top stories

Financial IT job market recovery continues

Recruitment growth suggests IT budgets are increasing 30 Jul 2010

Satellite broadband touted as digital divide clincher

KA-SAT launch promises 10Mbit/s service for hard-to-reach locations 29 Jul 2010

Ofcom slams ISPs for exaggerated broadband speed claims

New code of practice for ISPs planned by the regulator 27 Jul 2010

Aerohive offers traffic light Wi-Fi monitoring

Firm promises simple 'red, yellow or green' system with Client Health Score tool 27 Jul 2010

Flaw in top wireless security protocol WPA2 uncovered

Disgruntled insiders could hack corporate wireless LAN 26 Jul 2010

Advertisement

How to achieve business and financial-system implementation success
A look at how organisations - regardless of size - can work towards successful business software installations and factors that determine the outcome.

Case study: Specsavers put customer care into focus
How Specsavers captured customer feedback at point of sale and incorporated the results into its CRM system.

Advertisement

Citrix

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

ICO to lean more heavily on public sector bodies

ICO to lean more heavily on public sector bodies

The ICO has said it will lean more heavily on public sector bodies to secure timely FOI responses, do you think this is:

View poll results

Latest audio and video articles

picture of Jason HartVideo

Ethical hacker reveals the security secrets behind cloud computing

Jason Hart, Senior VP at Cryptocard, shows Computing just how easy it is to illegally gain access to corporate cloud services to wreak havoc and steal money. 29 Jun 2010

gartner logoVideo

Part 1: 2010 trends in SOA and Application Development and Integration

Gartner analyst Paolo Malinverno explores trends in SOA 29 Jun 2010

Latest in-depth articles

Map of 3G coverageComment

The risks of selling off the 800MHz radio spectrum at the wrong price

It's a choice between revenue now or universal broadband later 30 Jul 2010

Luton Borough Council officesAnalysis

Local authority leads the way in digital backup technology

Luton Borough Council tells of the benefits of early adopter of VTL, data deduplication and virtualisation 27 Jul 2010

Primary Navigation