News, info, and opinion by Mac users, for Mac users.

February 28, 2008

internet

PayPal: Safari is a little phishy

Posted Feb. 28, ’08, 3:00 PM PT by Dan Pourhadi
Category | Internet

phishing1.jpgI get a lot of emails from PayPal about inconsistencies in my account, or requests to verify my account information, or to pay $1500 I didn’t know I owed. Don’t get me wrong, I appreciate the courtesy; but it’s just a little annoying when you have to verify your bank info three times a day, you know?

At least I’m not a victim of phishing, the tactic used by web criminals to acquire sensitive data by tricking people into thinking they’re inputting their information into a trustworthy site that’s really just a front for money-hungry evildoers.

And PayPal, one of the most phished sites on the ‘net, has a warning for Safari users: it’s one of the most susceptible web browsers to phishing fraud. Via the Mothership:

Unlike its competitors, Safari has no built-in phishing filter to warn users when they are visiting suspicious Web sites, Barrett said. Another problem is Safari’s lack of support for another anti-phishing technology, called Extended Validation (EV) certificates. This is a secure Web browsing technology that turns the address bar green when the browser is visiting a legitimate Web site.

They recommend using Firefox, or even Opera, instead, at least until Apple can get its anti-phish act together.

Remember kids, always verify you’re at the real website by checking the URL before submitting any sensitive data. These guys are slick.

Oh, come on. They want me to verify my account info again? Dammit PayPal, you’ve got the memory of a goldphish.


3 Comments

Call Me Yo Daddy Author Profile Page said:

Hopefully future versions of Safari will include anti-phishing protection. It's too bad Camino also does not support anit-phising technology. Anyway Firefox 3.0 is looking very promising and will likely be my default browser once the full version has been released.

G said:

I "must" use IE at work and find the antiphising filter one of the most annoying features in the new version. I hope Safari never adds it.


Goobimama said:

My bank has something called "Personal statement". So while signing up, you give them a random phrase (Eg. Microsoft suck$!) and every time they contact you, that phrase will be somewhere in the middle. A much more effective way than phishing filters...

Though I must admit, Safari does need to implement an Anti-Phishing filter (but not like IE!)

Leave a comment

 




Visit other IDG sites: