Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Phishing Feeds Internet Black Markets (fake Internet sites take your personal info, bankruptcy)
Wash Post ^ | 11/18/04 | Brian Krebs

Posted on 11/18/2004 11:35:29 AM PST by Cableguy

click here to read article


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-65 last
To: Cableguy; Bush2000; Dominic Harr; Lazamataz; Nick Danger; Travis McGee; Xenalyte; kristinn; ...
"The e-mail directed Jackson to a Web site that looked like PayPal's. He keyed in his checking, credit card, bank routing and Social Security numbers, his birthday, his mother's maiden name and the personal identification number for his bank card. The Web site was a fake."

Such spoof sites work only because civilian sites such as eBay/PayPal are not knowledgeable about military-style dual verification.

ATM machines have the same vulnerability. Many an ATM user has been unknowingly burned by crooks who set up fake ATM's in shopping malls and convenience stores. Innocent people insert their ATM cards, key in their PIN's, and get a message about the system being down, try again later.

In the meantime, the fake ATM machine has read their ATM cards, copied their PIN's, and the crooks will soon be making up duplicate *valid* ATM cards to drain your checking account.

...And again, it is because most banks are unfamiliar with military-style dual verification.

Dual Verification means that *you* verify that the other guy is real, and the other guy verifies that you are real. Then information can be exchanged securely.

But ATM keosks don't allow you, the consumer, to verify that the ATM is real...which is the very first thing that you have to establish in order to have a secure transaction.

What *should* happen is that every ATM should *first* show you a 4 digit number after you insert your ATM card (prior to you entering your PIN). If you don't see the correct number, then you should phone the bank and be given a reward for catching a fake ATM keosk scam.

On the other hand, should the ATM show you the correct number, then you should feel confident typing in your PIN.

The fake ATM's won't know which 4 digit number to first show you. You'll get a reward for calling the bank anytime you are shown an incorrect number...and thereby honest citizens will easily put the fake ATM crooks out of business.

That's dual verification. The ATM shows *you* a special, pre-agreed number, and only then do you show the ATM your PIN. Since fake ATM's aren't tapped into the bank's database, those fake ATM's won't know which number to show to you. The reward for catching machines that display the incorrect dual verification number will quickly shut them down.

...And the same thing goes for web sites like paypal and ebay. They should be showing *you* a unique number or phrase before you enter your final password to log on (or to input requested private information such as bank account numbers).

The eBay spoof sites run by crooks won't know which phrase or number to show you, so you'll know to call eBay to get your reward for identifying a criminal web site.

Simple dual verification, combined with public rewards, will shut down such criminal web sites.

Our military and spy agencies have been using this sort of security system for decades. It's time that civilians caught up.

61 posted on 11/18/2004 2:37:57 PM PST by Southack (Media Bias means that Castro won't be punished for Cuban war crimes against Black Angolans in Africa)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MineralMan
So how did you get them off AOL? I stoutly refuse to do a damn thing with it besides uninstall (and I've offered to come do that at the drop of a hat, any time they call) . . . but Mom refuses to countenance any other ISP. She "just knows AOL too well" to switch.

Come to think of it, the fact that she "just knows AOL too well" might be my out. If she knows AOL so well, she shouldn't need to call me, the AOL-hater.
62 posted on 11/18/2004 2:46:58 PM PST by Xenalyte (And so he says, I don't like the cut of your jib, and I go, I says, It's the only jib I got, baby!)
[ Post Reply | Private Reply | To 59 | View Replies]

To: garyhope
They are used by hackers to take control of your PC. Some malicious web sites take advantage of active-x.Just make sure you keep your system up to date with the latest patches and don't use MS email programs. I use Firefox as an internet browser and only use MS Explorer when a site I trust won't load properly.
63 posted on 11/18/2004 2:53:51 PM PST by John Lenin
[ Post Reply | Private Reply | To 60 | View Replies]

To: Cableguy

bump for later read


64 posted on 11/18/2004 2:54:24 PM PST by ralph rotten
[ Post Reply | Private Reply | To 1 | View Replies]

To: Xenalyte

"So how did you get them off AOL? I stoutly refuse to do a damn thing with it besides uninstall (and I've offered to come do that at the drop of a hat, any time they call) . . . but Mom refuses to countenance any other ISP. She "just knows AOL too well" to switch.
"

I finally refused to offer any more support at all unless they let me switch them to another dial-up access and Yahoo Mail.

Yahoo Mail is terrific. It screens every attachment for viruses and its bulk mail filter is excellent. I highly advise it.


65 posted on 11/18/2004 5:06:11 PM PST by MineralMan (godless atheist)
[ Post Reply | Private Reply | To 62 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-65 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson