All the latest UK technology news, reviews and analysis

New browsers fail to curb phishing

by Shaun Nichols

20 Jun 2007

Be the first to comment

  • Tweet this
Phishing
Criminals have wised-up to blacklists by registering a new domain for each phishing run

Anti-phishing features inside popular browsers are failing to curb the onslaught of emails that attempt to steal confidential information.

Microsoft's Internet Explorer 7 and Mozilla's Firefox 2.0 incorporate blacklists that warn users when they attempt to visit known phishing websites. 

Both vendors claim to have been successful in stopping the attacks, but David Jevans, chairman of the Anti-Phishing Working Group (APWG), and chief executive at security firm IronKey, said at a meeting with reporters in San Francisco that this has not led to a decrease in the number of phishing emails. 

Criminals have wised-up to blacklists by registering a new domain for each phishing run. The result, according to Jevans, is an explosion in the number of unique phishing domains.

APWG records suggest that unique phishing domains rose from 11,976 a year ago to 37,438 last month. "The trend is not going in the right direction," Jevans said.

Registering a new domain for each phishing attack offers the criminal several hours to steal information between sending out the messages and the site being added to the blacklist.

In order to combat the practice in the short term, Jevans said that browser vendors should add heuristics systems that analyse the behaviour of a website and flag suspicious pages to the user.

But such systems can also mistakenly label many legitimate sites as phishing operations. 

The long term solution, according to Jevans, is a system that would allow for both websites and emails to be authenticated.

Such a system would require the cooperation of every major ISP, software vendor and hosting service, a monumentally expensive undertaking that Jevans admits is not likely to happen any time soon.

"Phishing emails are going to be with us for a while, unfortunately," he conceded.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

29%

1%

12%

58%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

PHP Software Developers/Programmers- Automated Trading - London

PHP Software Developers/Programmers- Automated Trading...

1st Level Application Support - Southampton, Hampshire - £20K

1st Level Application Support required to join a leading...

Helpdesk Adviser; Service desk Analyst; Northeast’s; £Neg on Experienc

Helpdesk adviser required for a major organisation in...

.NET Developer

.NET Developer is needed for a financial services...

To send to more than one email address, simply separate each address with a comma.