Latest Phishing Scam… Actually University Research

from the gotta-trick-you-to-understand dept

Lots of people are trying to research phishing scams in order to better understand them and come up with better ways to protect against them, but some folks are apparently a bit upset at research coming out of Indiana University that involved actually phishing a variety of people to con important information out of them in order to understand what kind of phishing scams work. The researchers and the university are defending the practice, saying they learned a lot from it, and it’s legal to be deceptive for the purpose of research so long as the deception is no different than what a person might come across normally and the risk to the person is minimal. Still, if any of the information is eventually misused or gets leaked, it certainly could create some problems for the university (and universities are no stranger to leaking data). The university still claims that this kind of research is key to preventing phishing… but oddly, the article seems to highlight what works for phishing scams, rather than what works to stop phishing scams. So, right now, the research seems to be telling scammers how to be more effective scammers, rather than coming up with ways to stop phishing.

Filed Under: , ,
Companies: indiana university

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “Latest Phishing Scam… Actually University Research”

Subscribe: RSS Leave a comment
10 Comments
Steven says:

In order to stop phishing...

don’t you have to know how it works?

I understand the privacy implications here, but how is a research supposed to come up with ways to reduce phishing without knowing what how/why it works (including stupid people)?

It seems to me that knowing what was most effective would at least be good fodder for an education campaign.

This is like saying a security firm shouldn’t be finding exploits in computer systems because that is just helping hackers.

Anonymous Coward says:

Well I can understand...


but oddly, the article seems to highlight what works for phishing scams, rather than what works to stop phishing scams. So, right now, the research seems to be telling scammers how to be more effective scammers, rather than coming up with ways to stop phishing.

They could be using the idea of exsposing the way the phishers operate. That way if the “secret” to phishing for info is no longer secret and everyone knows about it then people will hopefully wise up a bit. Kinda like someone telling how the magician made the elephant disappear.

Markus Jakobsson (user link) says:

why to perform phishing experiments

At first, many people may not see the benefits of phishing experiments, and may see it as a way to plainly confirm what is already known (“people fall for phishing attacks”.) That is not what is done in phishing experiments, though.

First of all, in a well designed experiment, no credential is even harvested by the researcher. Instead, he or she instead verifies that that right credentials were input — using the legitimate verification service. An example of how this is done, in the context of phishing eBay users, is available in

http://www.informatics.indiana.edu/markus/papers/ethical_phishing-jakobsson_ratkiewicz_06.pdf

This, and other experiments, are described from the ethical point of view in

http://www.indiana.edu/~phishing/papers/finn-conducting.pdf

Why are experiments useful, then? I think a good way to explain the needs for experiments is:

1. To improve phishing countermeasures, knowing what works and what does not.
2. To predict trends, knowing what the yet not exploited human vulnerabilities are.
3. To improve security education. An example effort is http://www.securitycartoon.com — this is directly influenced by phishing experiments.

Cheers,
Markus

Leave a Reply to Anonymous Coward Cancel reply

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...