Tuesday December 2, 2008 4:03 AM AEST
Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

No quick tech fix for phishing

  • Email a Friend
  • Print Page
No quick tech fix for phishing
By Iain Thomson
Jun 27, 2007 12:34 PM
Tags: No | quick | tech | fix | for | phishing
A senior researcher at RSA Security has told vnunet.com that there is no technological solution for phishing.

Uriel Maimon, senior researcher in the office of the chief technology officer at RSA, said that technology solutions could never provide a cure for phishing and online fraud because technical fixes could always be subverted.

Such measures also depend on the end user to operate and, as such, are vulnerable to error or incompetence.

The only cure is for phishing to move high enough up the political and social agenda that politicians would fund police to deal with the problem adequately.

It will also be necessary to resolve international legal differences to make sure that the perpetrators are locked away regardless of their location.

Users are far too accepting of online fraud, according to Maimon, and the problem will not be solved until this attitude changes.

"It is battered wife syndrome. People need to say 'enough' and insist that action be taken," he said.

"Governments must apply social pressure. It is done with the drugs trade and you can see in Thailand what can be done to cut the problems of underage sex in this way."

Maimon added that the UK's Serious Organised Crime Agency is doing a great job but needs more manpower and greater resources to catch online criminals.

Sentencing also needs to be looked at because criminals get a stiffer prison sentence for laundering the cash that has been stolen than for stealing it in the first place.

International action is also vital, according to Maimon, and countries should be pressured to enforce their own laws.

In some cases phishing gangs were known to be operating in certain towns, but corrupt local police do not step in because they are on the payroll of the phishers.

Education is not proving successful either, despite the efforts of some governments. "Education is possibly the least effective method of stopping phishing," Maimon told vnunet.com

"Education does not deter fraud. All it does is strengthen consumer confidence and you cannot trust consumers to make the right choices all the time."

However, education does have a role in telling people about their rights and what they should expect in the way of protection. In this way pressure would grow for real change to be made in government.

Copyright © 2008 vnunet.com

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Messaging Whitepapers