Phishing
Phishing will not be resolved until the financial institutions take responsibility

Banks told to take responsibility for phishing

Security expert says that only financial institutions can end the problem

Written by Iain Thomson

Phishing could be stopped very quickly if banks were made responsible for the losses incurred, according to security guru Bruce Schneier.

Writing in his Crypto-gram newsletter Schneier noted that, while new anti-phishing laws might have some effect, the problem will not be resolved until the financial institutions take responsibility for fraud, thus giving them an incentive to stop it.

"Push all of the responsibility for identity theft onto the financial institutions, and phishing will go away," said Schneier.

"This fraud will go away not because people will suddenly get smart and quit responding to phishing emails, or because California has new criminal penalties for phishing, or because ISPs will recognise and delete the emails.

"It will go away because the information a criminal can get from a phishing attack will not be enough to commit fraud because the companies won't stand for all those losses."

Schneier maintains that one of the fundamental rules of security is that " the entity that is in the best position to mitigate the risk is responsible for that risk".

While he accepts that many financial organisations already pay for phishing losses directly, this ignores the indirect costs. Damage to credit ratings and time spent opening new bank accounts are all handled by the consumer.

In the past banks have been accused of complacency about the phishing problem, even though it costs billions each year.

Tags:

Further reading

Phishing against banks hits all time high

Anti-Phishing Working Group warns of 'relentless increase'   More...

Global phishing outbreak hits four banks

Thieves get busy   More...

Phishing leaps fivefold as banks fall prey to attacks

Fraudsters looking forward to a very merry Christmas   More...

Related articles

Online banking fraud on the decline

But credit card fraud abroad pushing up overall losses   More...

Identity theft costs an average of $31K

US Secret Service files show the bigger the gang, the more money stolen   More...

Fidelity admits theft of data on 2.3m customers

Bank and credit card numbers lifted from payment monitoring firm   More...

US whistleblower's details exposed on the web

Bankruptcy fraud whistleblower files civil lawsuit   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement