Sep 28 2005
Phishers trying to mimic sites even more
Phishers’ latest hook: SSL certificates
Phishers are working even harder to make the sites they maintain look like the real bank websites. By providing bogus SSL certificates to browser, the user is getting all the indications that they’ve reached a secure site. For the average user, any errors they recieve on the SSL certificate are just going to look like it’s a problem at the bank.
2 Responses to “Phishers trying to mimic sites even more”
The article makes it sound like heeding SSL warnings will keep you safe against phishing attacks. It won’t, because phishers can get “real” SSL certificates too. Checking the URL bar is more important, and in the absence of insecure DNS/routers, it’s all you need to do. That said, ignoring SSL warnings does negate the security benefit of SSL
And to help consumers pay more attention to the certificate information and mitigate against these kinds of attacks there are a few free plugins like Trustbar:
http://www.cs.biu.ac.il/~herzbea/TrustBar/