Sep 28 2005

Phishers trying to mimic sites even more

Published by Martin at 8:38 am under Phishing, scams, etc.

Phishers’ latest hook: SSL certificates

Phishers are working even harder to make the sites they maintain look like the real bank websites. By providing bogus SSL certificates to browser, the user is getting all the indications that they’ve reached a secure site. For the average user, any errors they recieve on the SSL certificate are just going to look like it’s a problem at the bank.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

2 Responses to “Phishers trying to mimic sites even more”

  1. Jesse Rudermanon 28 Sep 2005 at 2:13 pm

    The article makes it sound like heeding SSL warnings will keep you safe against phishing attacks. It won’t, because phishers can get “real” SSL certificates too. Checking the URL bar is more important, and in the absence of insecure DNS/routers, it’s all you need to do. That said, ignoring SSL warnings does negate the security benefit of SSL

  2. Garth Somervilleon 30 Sep 2005 at 7:45 am

    And to help consumers pay more attention to the certificate information and mitigate against these kinds of attacks there are a few free plugins like Trustbar:

    http://www.cs.biu.ac.il/~herzbea/TrustBar/