Researchers detail why phishing works

By
Follow google news

Researchers from Harvard University and the University of California at Berkeley released a paper last week on why users fall for phishing scams, concluding that current anti-phishing deterrents are ineffective.

Written by Rachna Dhamija of Harvard and J.D. Tygar and Marti Hearst of Berkeley, the paper asserts that existing anti-phishing cues are ineffective. What most concerned the researchers was that PC users are not utilizing the secure sockets layer (SSL) indicators designed to help them determine a site's trustworthiness.  


In a usability study, they found that 23 percent of participants only used a website's content to determine its legitimacy and an additional 36 percent used only content and domain name. Many of those that did use padlock and certificate indicators did not always understand how these work, and when presented with well-designed phishing sites, they were unable to identify them as fraudulent. 

A different approach is needed in the design of website security systems, the researchers concluded. 

"Rather than approaching the problem solely from a traditional cryptography-based security framework, a usable design must take into account what humans do well and what they do not do well," they wrote. 

They offered several concrete suggestions to developers. Most pressing, they said, was the need for security indicators to appear when users are at an untrusted site - rather than just at trusted sites.

Users often forget about security indicators in their absence, which is often when they are most needed, Dhamija, Tygar and Hearst said.  

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Commercial spyware targeted Samsung Galaxy users for months

Commercial spyware targeted Samsung Galaxy users for months

Queensland gov reveals strategy to harden cyber defences

Queensland gov reveals strategy to harden cyber defences

Researcher trawls cybercrime sites, collects billions of stolen credentials

Researcher trawls cybercrime sites, collects billions of stolen credentials

Log In

  |  Forgot your password?