Website Promotion
  Home arrow Website Promotion arrow Page 3 - What Phishers Can Teach You
SEO Chat Forums  
Choosing Keywords  
Google Optimization  
Link Trading  
MSN Optimization  
Search Engine News  
Search Engine Spiders  
Search Optimization  
Web Directories  
Website Marketing  
Website Promotion  
Website Submission  
Yahoo Optimization  
SEO Tools
Adsense Calculator
AdSense Preview
Advanced Meta-Tags
Alexa Rank Tool
Check Server Headers
Class C Checker
Code to Text Ratio
CPM Calculator
Domain Age Check
Domain Typos
Future PageRank
Google Dance
Google Keywords
Google Search
Google Suggest
Google vs Yahoo
Indexed Pages
Keyword Cloud
Keyword Density
Keyword Difficulty
Keyword Optimizer
Keyword Position
Keyword Typos
Link Popularity
Link Price Calculator
Meta Analyzer
Meta Tag Generator
Multiple Link Popularity
Page Comparison
Page Size
PageRank Lookup
PageRank Search
Robots.txt Generator
ROI Calculator 
S.E. Comparison 
S.E. Keyword Position 
Site Link Analyzer 
Spider Simulator 
URL Redirect Check 
URL Rewriting 
Mobile Linux 
APP Generation ROI 
IBM® developerWorks 
SEO Weekly Newsletter
 
Developer Updates  
Free Website Content 
 RSS  Articles
 RSS  Forums
 RSS  All Feeds
Write For Us Get Paid 
Request Media Kit
Contact Us 
Site Map 
Privacy Policy 
Support 
 USERNAME
 
 PASSWORD
 
 
  >>> SIGN UP!  
  Lost Password? 
WEBSITE PROMOTION

What Phishers Can Teach You
By: Terri Wells
  • Search For More Articles!
  • Disclaimer
  • Author Terms
  • Rating: 4 stars4 stars4 stars4 stars4 stars / 12
    2006-10-02

    Table of Contents:
  • What Phishers Can Teach You
  • How Users Sniff Out Bogus Sites
  • How Well Did They Do?
  • What Does This Mean?

  • Rate this Article: Poor Best 
      ADD THIS ARTICLE TO:
      Del.ici.ous Digg
      Blink Simpy
      Google Spurl
      Y! MyWeb Furl
    Email Me Similar Content When Posted
    Add Developer Shed Article Feed To Your Site
    Email Article To Friend
    Print Version Of Article
    PDF Version Of Article
     
     
    ADVERTISEMENT


    What Phishers Can Teach You - How Well Did They Do?


    (Page 3 of 4 )

    Before I go into the results of the study, I’d like to mention two participants that were at extreme ends of the spectrum as far as security awareness and checking for bogus web sites. The one who scored at the low end actually submitted her username and password to some websites to check whether it was a site at which she had an account. She’d used this strategy before, she said, thinking “What’s the harm? Passwords are not dangerous to give out, like financial information is.” (If you’re a sysadmin, you can be forgiven for making a dash to the bathroom before continuing).

    At the other end of the spectrum in both security awareness and score was the participant who opened up a second window into which he typed all URLs by hand to compare these pages with every web site presented to him in the study. He sometimes used Yahoo as well to search for the organization. His hypersensitivity can be attributed in part to the fact that a family member of his had fallen prey to a PayPal phishing attack.

    The study asked participants not only to judge whether a web site was legitimate or bogus, but how confident they were of their judgment, on a scale of 1 to 5. Interestingly, most participants were pretty confident of their judgments, whether or not they were correct. This is particularly disturbing in light of the fact that one of the phishing web sites fooled more than 90 percent of the participants. The fake web site, for Bank of the West, included the following factors that convinced most participants of its authenticity:

    • “Cute” design.
    • High level of detail.
    • Does not ask for a great deal of information.
    • Animated bear video which two participants believed would “take a lot of effort to copy.”
    • Links to other sites.
    • Link to an SSL protected web page, hosted at VeriSign, showing the SSL certificate status for the real Bank of the West web site.

    Of the two participants who realized this was a spoof web site, one noticed the URL in the address bar included a doubled “v” rather than a “w” for “west,” and the other one noticed an outdated date in the content of the web page.

    Disturbingly, in interviews about user knowledge of phishing and security, seven participants hadn’t even heard the term “phishing” before, and some seemed surprised that these kinds of attacks occur. Some did not know the meaning of the padlock in the address bar, and at least one participant incorrectly believed it meant the web site could not read passwords or set cookies. Only one of the participants was able to explain the purpose of SSL certificates, and he was a systems administrator.

    The one quarter of participants who used strategy one to distinguish legitimate from bogus web sites were wrong 40 percent of the time. While other participants fared better, it seems clear that there is cause for concern.

    More Website Promotion Articles
    More By Terri Wells


       · I thought the research was rather eye-opening. Thanks for reading. Feel free to...
       · Great article as always Terri.I'm wondering if you have thoughts about the...
       · Thanks Caroline! Well, I wouldn't extrapolate to little dancing bears on your...
     

    WEBSITE PROMOTION ARTICLES

    - How to Effectively Monetize Your WordPress B...
    - Blogging and SEO, a Beginner`s Guide
    - Formatting a Website with Personality Types ...
    - Copy Writing with Personality Types in Mind
    - Crafting a Website with Personality Types in...
    - Getting Included in Google News
    - Google AdWords and Yahoo Search Marketing Gu...
    - Checklists: A Blogger`s Second Best Friend
    - Top PPC Tips for Effective Marketing
    - Is Your Brand Killing Your Search Campaign?
    - Creating Your Domain Name
    - Using Images to Tell Your Story
    - Generate Traffic to Your Site by Posting in ...
    - Editorial Calendars: a Blogger`s Best Friend
    - Link Building Outside the Box





    © 2003-2009 by Developer Shed. All rights reserved. DS Cluster 6 Hosted by Hostway
    Stay green...Green IT