Phishing
Technology will never provide a cure for phishing because it can always be subverted
R E L A T E D   C O N T E N T
ADVERTISEMENT

No quick tech fix for phishing

Education not much cop either, says security expert

Iain Thomson, vnunet.com 26 Jun 2007
ADVERTISEMENT

A senior researcher at RSA Security has told vnunet.com that there is no technological solution for phishing.

Uriel Maimon, senior researcher in the office of the chief technology officer at RSA, said that technology solutions could never provide a cure for phishing and online fraud because technical fixes could always be subverted.

Such measures also depend on the end user to operate and, as such, are vulnerable to error or incompetence.

The only cure is for phishing to move high enough up the political and social agenda that politicians would fund police to deal with the problem adequately.

It will also be necessary to resolve international legal differences to make sure that the perpetrators are locked away regardless of their location.

Users are far too accepting of online fraud, according to Maimon, and the problem will not be solved until this attitude changes.

"It is battered wife syndrome. People need to say 'enough' and insist that action be taken," he said.

"Governments must apply social pressure. It is done with the drugs trade and you can see in Thailand what can be done to cut the problems of underage sex in this way."

Maimon added that the UK's Serious Organised Crime Agency is doing a great job but needs more manpower and greater resources to catch online criminals.

Sentencing also needs to be looked at because criminals get a stiffer prison sentence for laundering the cash that has been stolen than for stealing it in the first place.

International action is also vital, according to Maimon, and countries should be pressured to enforce their own laws.

In some cases phishing gangs were known to be operating in certain towns, but corrupt local police do not step in because they are on the payroll of the phishers.

Education is not proving successful either, despite the efforts of some governments. "Education is possibly the least effective method of stopping phishing," Maimon told vnunet.com.

"Education does not deter fraud. All it does is strengthen consumer confidence and you cannot trust consumers to make the right choices all the time."

However, education does have a role in telling people about their rights and what they should expect in the way of protection. In this way pressure would grow for real change to be made in government.

See also:

PhishingFinancial services still primary target  30 May 2007
PhishingMore integrated approach needed to stop theft  27 Mar 2007
PhishingCarnegie Mellon report shows inability to identify sites across the board  22 Nov 2006
Mozilla FirefoxFirefox catches 82 per cent of phishing sites  15 Nov 2006
Antivirus firm SoftScan said this week that spam now accounts for 87.72 per cent of all emailPercentage of phishing emails increases dramatically  04 Sep 2006

All Hacking
Tags: Government

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities