McAfee SiteAdvisor does not offer anti-phishing functionality, but the
company launched SiteAdvisor Plus earlier this month that offers real-time
anti-phishing protection.
The Carnegie Mellon researchers prepared a series of experiments that
included identifying recently discovered phishing sites, identifying phishing
sites over a period of 24 hours, and differentiating between phishing sites and
legitimate sites.
Even the top performers failed to catch nine to 15 per cent of the phishing
sites visited.
SpoofGuard,
which correctly identified 91 per cent of the phishing sites, also labeled 38
per cent of the legitimate sites as phishing operations.
"Overall we found that the anti-phishing toolbars examined in this study left
a lot to be desired," wrote the researchers. "Many of the toolbars we tested
were vulnerable to some simple exploits as well."
Aside from reliability, the study found the user interface on several
products ineffective. Many of the toolbars used warning dialogues to indicate
when a phishing site was found.
Because many users have been desensitised to pop-up ads and dialogue windows
in web browsers, they may simply dismiss the warnings and enter personal
information on the phishing site.
"When using an anti-phishing toolbar, poor usability could mean the
difference between correctly steering someone away from a phishing site and
having them ignore the warnings only to become a victim of identity theft,"
wrote the researchers.
Do you agree?
Have your say on this article