PayPal Battling Back Against The Phishers
from the paypalcom.ru dept
The idea of authenticating email as a means of stopping spam and phishing has been talked about for some time, but for various reasons, including standards disputes, the concept hasn't really gone anywhere. Now PayPal, the most popular target among phishers, is proposing a slightly different take on the concept that sounds sort of interesting. The company is urging popular webmail providers like Google and Yahoo to automatically deny any emails coming from a @paypal.com address unless it's authenticated with an established digital signature. So far, the company hasn't gotten any takers, but it would be an interesting experiment to try. Of course, this wouldn't stop attackers from sending emails from different addresses that looked like PayPal's, but these are likely to be less effective anyway. Ultimately, no one solution is going to be a magic bullet for stopping phishing, but anything that can reduce its volume while still allowing legitimate email to get through is a step in the right direction.
13 Comments | Leave a Comment..
- Leaked Memo Confirms Apple, Nokia & RIM Gave Indian Gov't Backdoors
- VW Will Block BlackBerry Email When People Are Off Work. Isn't That When It's Most Useful?
- Former Tunisian Regime Goes Beyond Spying On Internet Traffic... To Rewriting Emails & More
- Email Is 40 Years Old
- New US Postal Service Ad Campaign: Email Sucks, So Mail Stuff Instead





Reader Comments (rss)
(Flattened / Threaded)
Hax
[ reply to this | link to this | view in thread ]
do what the blogs do
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
re:do what the blogs do
paypal could instead borrow a page from banks... put an inbox in your account and send only notification messages to the user's email address. tell them in the notification emails that they have a new message in their paypal account inbox. internalize the messaging system.
otherwise, this idea sounds like it has the potential to work, but they should drop the whole "block the email part". the blocking part makes this solution hard to implement industry- or internet-wide. it requires each email service to maintain a list of domains to block without a cert.
http://opinionone.blogspot.com
[ reply to this | link to this | view in thread ]
The paypal spf record:
"v=spf1 mx include:s._spf.ebay.com include:m._spf.ebay.com include:p._spf.ebay.com include:c._spf.ebay.com include:spf-1.paypal.com ~all"
Just change that to -all and problem solved.
[ reply to this | link to this | view in thread ]
hmm...
[ reply to this | link to this | view in thread ]
Bigger problem requires bigger solution
As more companies embrace email as an integrated marketing channel, users will only have eyes for a few select messages. And the wider scope of this issue is how to put that control back with the reader; not the sender.
[ reply to this | link to this | view in thread ]
Paypal
[ reply to this | link to this | view in thread ]
[ reply to this | link to this | view in thread ]
Re: Paypal
:D
[ reply to this | link to this | view in thread ]
fake paypal emails?
[ reply to this | link to this | view in thread ]
Is this PayPal logon page a fake ????
[ reply to this | link to this | view in thread ]
megaupoad downloading
[ reply to this | link to this | view in thread ]
Add Your Comment