Links
archives
- Dec 23, 2005
- Jan 15, 2006
- Jan 19, 2006
- Jan 20, 2006
- Jan 27, 2006
- Feb 2, 2006
- Feb 3, 2006
- Feb 10, 2006
- Feb 24, 2006
- Mar 2, 2006
- Mar 10, 2006
- Mar 17, 2006
- Apr 25, 2006
- Apr 28, 2006
- Apr 29, 2006
- May 26, 2006
- Jun 2, 2006
- Jun 9, 2006
- Jun 23, 2006
- Jun 30, 2006
- Jul 7, 2006
- Jul 17, 2006
- Jul 28, 2006
- Aug 11, 2006
- Aug 18, 2006
- Sep 1, 2006
- Sep 8, 2006
- Sep 16, 2006
- Sep 22, 2006
- Oct 23, 2006
- Oct 27, 2006
- Nov 3, 2006
- Nov 10, 2006
- Nov 17, 2006
- Dec 8, 2006
- Dec 21, 2006
- Dec 22, 2006
- Jan 19, 2007
- Jan 26, 2007
- Feb 6, 2007
- Feb 16, 2007
- Mar 2, 2007
- Mar 9, 2007
- Mar 14, 2007
- Mar 16, 2007
- Mar 21, 2007
- Mar 22, 2007
- Mar 23, 2007
- Apr 2, 2007
- Apr 3, 2007
- Apr 5, 2007
- Apr 6, 2007
- Apr 9, 2007
- Apr 11, 2007
- Apr 12, 2007
- Apr 13, 2007
- Apr 17, 2007
- Apr 18, 2007
- Apr 19, 2007
- Apr 20, 2007
- Apr 23, 2007
- Apr 25, 2007
- May 1, 2007
- May 2, 2007
- May 3, 2007
- May 7, 2007
- May 9, 2007
- May 10, 2007
- May 11, 2007
- May 15, 2007
- May 17, 2007
- May 21, 2007
- May 22, 2007
- May 24, 2007
- May 25, 2007
- Jun 1, 2007
- Jun 6, 2007
- Jun 7, 2007
- Jun 8, 2007
- Jun 12, 2007
- Jun 14, 2007
- Jun 15, 2007
- Jun 19, 2007
- Jun 21, 2007
- Jun 22, 2007
- Jun 27, 2007
- Jun 29, 2007
- Jul 10, 2007
- Jul 13, 2007
- Jul 17, 2007
- Jul 18, 2007
- Jul 19, 2007
- Jul 27, 2007
- Jul 31, 2007
- Aug 1, 2007
- Aug 3, 2007
- Aug 7, 2007
- Aug 8, 2007
- Aug 9, 2007
- Aug 10, 2007
- Aug 13, 2007
- Aug 14, 2007
- Aug 15, 2007
- Aug 17, 2007
- Aug 20, 2007
- Aug 21, 2007
- Aug 22, 2007
- Aug 24, 2007
- Aug 26, 2007
- Aug 28, 2007
- Aug 29, 2007
- Aug 30, 2007
- Aug 31, 2007
- Sep 6, 2007
- Sep 7, 2007
- Sep 10, 2007
- Sep 19, 2007
- Sep 20, 2007
- Sep 26, 2007
- Sep 27, 2007
- Oct 2, 2007
- Oct 11, 2007
- Oct 16, 2007
- Oct 18, 2007
- Oct 20, 2007
- Oct 22, 2007
- Oct 23, 2007
- Oct 24, 2007
- Oct 25, 2007
- Oct 26, 2007
- Oct 29, 2007
- Oct 30, 2007
- Nov 2, 2007
- Nov 5, 2007
- Nov 7, 2007
- Nov 9, 2007
- Nov 11, 2007
- Nov 13, 2007
- Nov 15, 2007
- Nov 18, 2007
- Nov 19, 2007
- Nov 20, 2007
- Nov 27, 2007
- Nov 30, 2007
- Dec 3, 2007
- Dec 4, 2007
- Dec 5, 2007
- Dec 6, 2007
- Dec 11, 2007
- Dec 12, 2007
- Dec 17, 2007
- Dec 18, 2007
- Dec 19, 2007
- Dec 23, 2007
- Dec 27, 2007
- Dec 28, 2007
- Jan 3, 2008
- Jan 10, 2008
- Jan 15, 2008
- Jan 17, 2008
- Jan 21, 2008
- Jan 23, 2008
- Jan 24, 2008
- Jan 25, 2008
- Jan 28, 2008
- Jan 31, 2008
- Feb 1, 2008
- Feb 4, 2008
- Feb 5, 2008
- Feb 6, 2008
- Feb 7, 2008
- Feb 8, 2008
- Feb 11, 2008
- Feb 14, 2008
- Feb 15, 2008
- Feb 20, 2008
- Feb 21, 2008
- Mar 5, 2008
- Mar 6, 2008
- Mar 7, 2008
- Mar 10, 2008
- Mar 11, 2008
- Mar 13, 2008
- Mar 20, 2008
- Mar 21, 2008
- Mar 27, 2008
- Mar 28, 2008
- Mar 31, 2008
- Apr 3, 2008
- Apr 4, 2008
- Apr 9, 2008
- Apr 10, 2008
- Apr 16, 2008
- Apr 17, 2008
- Apr 18, 2008
- Apr 23, 2008
- Apr 24, 2008
- Apr 25, 2008
- Apr 28, 2008
- May 1, 2008
- May 6, 2008
|
Friday, December 22, 2006
Go Phish!
One of the most interesting features of Microsoft's Internet Explorer 7.0 browser is a visual alert system to identify potential phishing sites (sites that look as if they are reputable, well-known companies, but which are designed for identity theft). It's pretty cool: when visiting a site verified as legitimate, the address bar area of the browser turns green to connote safety. Suspect sites turn the address bar yellow, and known phishing sites turns the address bar red. On the surface, it seems like an elegant solution to a growing problem. But to take the punch line from an old joke, "how do it know"? How does Microsoft determine that a site is legitimate, suspect or fraudulent? It doesn't. Microsoft isn't validating companies or websites directly. Instead, it is relying on a program developed by the CA/Browser Forum, an industry group that has created a standards process for verifying legitimacy. These standards are in turn applied by a number of private companies (called "certification authorities") that actually do the certification work. A key screening criteria is a check of state incorporation records, meaning that unincorporated businesses currently aren't eligible for verification. A fair amount of research on my part has not yet determined who identifies "suspicious" or "known" phishing sites, and who maintains this database of information. Good luck if you're ever accidentally included on this list, because there appears to be no appeal. We're very bullish on the power of "3R" (rating, ranking and recommendation) features to add value to data. They can be even more powerful when tightly integrated into software tools, as in this new system. Yet, in its rush to do good, Microsoft (non-Microsoft browsers will participate in this program as well I should add) has made four major blunders: - The program doesn't currently cover everyone, relegating a large number of companies to the status of "unknown." This angers the excluded companies while reducing the value of the 3R system to users.
- It has created a secretive blacklisting process that lacks any of the processes or safeguards you would expect of a system that has the power to put a company out of business virtually overnight.
- Its high certificate fees (reportedly, prices now range from $300 to $1,200) pose a barrier for smaller businesses. This works against a high participation rate, which is critical to success.
- It over-hypes the benefits of the system -- to qualify for "green" status, a company needs only to be legally incorporated somewhere, not exactly a demanding standard when you are vouching for the legitimacy of a business.
While the goal is laudable, this sloppily designed program has been rushed to market under pressure from the companies planning to become certification authorities. The lesson for information companies considering 3R systems of their own is don't rush to judgment, or ye yourself will be judged, and found wanting. Labels: IE7, Infocommerce, Microsoft, Phish
|