Phishing
Technology will never provide a cure for phishing because it can always be subverted

No quick tech fix for phishing

Education not much cop either, says security expert

Written by Iain Thomson

A senior researcher at RSA Security has told vnunet.com that there is no technological solution for phishing.

Uriel Maimon, senior researcher in the office of the chief technology officer at RSA, said that technology solutions could never provide a cure for phishing and online fraud because technical fixes could always be subverted.

Such measures also depend on the end user to operate and, as such, are vulnerable to error or incompetence.

The only cure is for phishing to move high enough up the political and social agenda that politicians would fund police to deal with the problem adequately.

It will also be necessary to resolve international legal differences to make sure that the perpetrators are locked away regardless of their location.

Users are far too accepting of online fraud, according to Maimon, and the problem will not be solved until this attitude changes.

"It is battered wife syndrome. People need to say 'enough' and insist that action be taken," he said.

"Governments must apply social pressure. It is done with the drugs trade and you can see in Thailand what can be done to cut the problems of underage sex in this way."

Maimon added that the UK's Serious Organised Crime Agency is doing a great job but needs more manpower and greater resources to catch online criminals.

Sentencing also needs to be looked at because criminals get a stiffer prison sentence for laundering the cash that has been stolen than for stealing it in the first place.

International action is also vital, according to Maimon, and countries should be pressured to enforce their own laws.

In some cases phishing gangs were known to be operating in certain towns, but corrupt local police do not step in because they are on the payroll of the phishers.

Education is not proving successful either, despite the efforts of some governments. "Education is possibly the least effective method of stopping phishing," Maimon told vnunet.com.

"Education does not deter fraud. All it does is strengthen consumer confidence and you cannot trust consumers to make the right choices all the time."

However, education does have a role in telling people about their rights and what they should expect in the way of protection. In this way pressure would grow for real change to be made in government.

Tags:

Further reading

Phishers spreading multiple hooks

Financial services still primary target   More...

Study blasts failing phishing toolbars

Carnegie Mellon report shows inability to identify sites across the board   More...

Education failing to fight phishing

More integrated approach needed to stop theft   More...

Virus levels soar in August

Percentage of phishing emails increases dramatically   More...

Related articles

Infosec: Rock Phish threat deepens

Hugely successful malware gets a new twist   More...

Security experts slam Soca job cuts

Greatly increased threat to UK business   More...

vnunet.com analysis: The malware 'shadow economy'

Online criminals using techniques of the free market   More...

Underworld economy runs on bots and spam

Market for hijacked PCs fuels online crime   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

08 Jul 2008

3.67 MBSafe browsing, voice recognition and cyber-criminals More...

07 Jul 2008

2.76 MBLaptops on holiday, gaming in Vietnam and 'unbreakable' encryption More...

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Firefox

Firefox users shown to be safer

Internet Explorer users the worst of the bunch   More...

Internet Corporation for Assigned Names and Numbers

Icann downplays recent site hacks

Redirects were 'limited', says organisation   More...

Advertisement

DNA

Boffins build artificial DNA

Could be used in the ultimate computer   More...

Microsoft

Microsoft outlines appeal against EU fine

Two sides back in court   More...

Advertisement