iTnews
  • Home
  • News
  • Technology
  • Security

Browsers fail to curb phishing

By Shaun Nichols
Jun 20 2007 2:56PM
Follow google news

Criminals skirting security measures, says anti-phishing head.

Browsers fail to curb phishing
Anti-phishing features inside popular browsers are failing to curb the onslaught of emails that attempt to steal confidential information.

Both the Internet Explorer 7 and Firefox 2.0 browsers incorporate blacklists that warn users when they attempt to visit known phishing websites.

Although the vendors behind those browser claim to be succesful in stopping the phishing attacks, this hasn't lead to a decrease in the amount of phishing emails, David Jevans, chairman of the Anti-Phishing Working Group (APWG) chief executive for security firm IronKey said at a meeting with reporters in San Francisco.

Insted criminals have wised-up to blacklists by registering a new domain for each phishing run. The result, claims Jevans, is an explosion in the number of unique phishing domains recorded. Up from 11,976 a year ago to 37,438 last month, according to APWG records.

"Definitely the trend is not going in the right direction," Jevans said.

Registring a new domain for each phishing attack offers the criminal several hours to steal information between the times when they send out their email messages and when their site is added to the blacklist.

In order to combat the practice in the short term, Jevans advises that browser venders add heuristics systems that analyze the behaviour of a website and flag suspicious pages to the user.

Those heuristics systems can also mistakenly label many legitimate sites as phishing operations, however.

The long term solution, suggests Jevans, is for a new system to be established that would allow for both web sites and e-mails to be authenticated.

Such a system, however, would require the cooperation of every major ISP, software vendor, and hosting service, a monumentally expensive undertaking that Jevans admits is not likely to happen any time soon.

"This stuff is going to be with us for a while, unfortunately," he conceded.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
browserscurbfailphishingsecurityto

Related Articles

  • AudiA6 crypto launderers arrested, network taken down by police AudiA6 crypto launderers arrested, network taken down by police
  • US charges suspected Russian hacker with facilitating cyber campaign US charges suspected Russian hacker with facilitating cyber campaign
  • Gov looks for upstream threat blocking by telcos, cloud operators Gov looks for upstream threat blocking by telcos, cloud operators
  • Federal Parliamentary Computer Network set for its "most significant" upgrade Federal Parliamentary Computer Network set for its "most significant" upgrade
Join our WhatsApp Channel

Partner Content

You meet the security standard. Shame no one can see it
Promoted Content You meet the security standard. Shame no one can see it
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
CommBank creates opportunities for technologists to upskill  with frontier AI companies
Partner Content CommBank creates opportunities for technologists to upskill with frontier AI companies
Take control of your connectivity with Telstra’s Adaptive Networks Centre
Partner Content Take control of your connectivity with Telstra’s Adaptive Networks Centre

Sponsored Whitepapers

Are Australian organisations as cyber-ready as they think?
Are Australian organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
Are New Zealand organisations as cyber-ready as they think?
From visibility to execution:  Fixing the SaaS management gap
From visibility to execution: Fixing the SaaS management gap
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
When cyber risk has no clear owner: A practical guide for senior Australian business leaders
Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • Forrester's AI Forum Sydney Forrester's AI Forum Sydney
  • The 2026 iAwards The 2026 iAwards
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Anthropic releases Mythos-class model for public use

Anthropic releases Mythos-class model for public use

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.