![]() |
|
An Effective Solution To The "Phishing" Scams Financial Institutions Should Use S/MIME With the rapid rise in "phishing" scams proliferating through the internet, there have been multitudes of suggestions on how to deal with this problem. Citibank (among others) are increasingly being "victimized" by these attempts, and they ARE attempts - relying solely on the naivete of the recipient for success. According to E-Week, there were over 1,200 unique attacks in May, a 6% increase April. Clearly this is a major issue, and the credibility, trust and indeed, the future viability of online financial services are at stake. By Chris Picciotto July 6, 2004
|
||
Most suggestions available today tend to address controlling the source of "evil" mail. In other words, if we can shut down the source of spammers and phishers, we can eliminate the problem. The very idea of accomplishing this is both naive and unrealistic. Much of this activity originates overseas. Can we really going to rely on the US government to institute bilateral agreements with every country from which mail scams originate? And even supposing that were accomplished - is it at all realistic that this would have any impact on the problem? The clear answer is "No" to both. This has been demonstrated with too many other criminal activities over the years. The internet is, by design, very flexible and changeable, and simply changing the source of email servers, ip's, domain names etc. is trivially easy to do. That is both the strength and and a weakness of the architecture. Another reason controlling at the source is impossible stems from the fact that much of the "evil mail" originates from unsuspecting home machines that have been commandeered by trojans. If you look at any log file for an incoming mail server, you will see an overwhelming amount of email coming directly from dynamic and residential network addresses. Although this is becoming easier to block - the majority of the incoming servers still do not take this basic step (but that is an entirely different problem!). If mail is coming from hijacked pc's in the home - who do you prosecute? The spammers and phishers have insulated themselves behind an innocent victim. And there will continue to be "victims"...there is no doubt about that. At this point - I seem to have effectively dismantled the value of the existing suggestions to deal with the problem. And I would like to put forth an idea which may provide a much better approach to the problem. S/Mime has been around for a long time, and is built into virtually every mail client out there. S/Mime relies on certificates for public key encryption or signing of messages. This article will not delve into the mechanics of public key encryption, or the workings of certificates; there are many well written explanations on this available at your fingertips. The important part is that public key encryption relies on a "private key" and a "public key", together called a key pair. The algorithms allow for one way encryption - meaning that a message encrypted with the private key can only be decrypted with the public key, and vice versa. Used wisely, this gives the user a few very valuable and functional options when sending email.The two key benefits of S/Mime are encryption and signing. To encrypt a mail to me for example, you would encrypt |
|
||