<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.thestandard.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>The Industry Standard - Anti-phishing apps are not foolproof - Comments</title>
 <link>http://www.thestandard.com/news/2008/07/08/anti-phishing-apps-are-not-fool-proof</link>
 <description>Comments for &quot;Anti-phishing apps are not foolproof&quot;</description>
 <language>en</language>
<item>
 <title>Anti-phishing apps are not foolproof</title>
 <link>http://www.thestandard.com/news/2008/07/08/anti-phishing-apps-are-not-fool-proof</link>
 <description>&lt;p&gt;&lt;!--paging_filter--&gt;
&lt;p&gt;&lt;img src=&quot;/sites/thestandard.com/files/u4993/flagfox_logo.png&quot; alt=&quot;FlagFox logo image&quot; align=&quot;left&quot; border=&quot;0&quot; height=&quot;32&quot; hspace=&quot;10&quot; vspace=&quot;10&quot; width=&quot;32&quot; /&gt;Michael Horowitz of Webware has been &lt;a href=&quot;http://www.webware.com/8301-1_109-9984196-2.html?part=rss&amp;amp;tag=feed&amp;amp;subj=Webware&quot; rel=&quot;nofollow&quot;&gt;pushing Firefox extension Flagfox&lt;/a&gt; as an added protection above and beyond Firefox 3&#039;s built-in anti-phishing capabilities. The problem? Even the IP address and associated location can be hijacked by skilled hackers. Horowitz claims it&#039;s impossible, but until &lt;a href=&quot;http://www.networkworld.com/news/2008/070808-dns-flaw-disrupts-internet.html&quot; rel=&quot;nofollow&quot;&gt;CERT issued their alert today&lt;/a&gt; in conjunction with patches offered by major DNS software vendors, it actually wasn&#039;t all that difficult to accomplish.&lt;/p&gt;
&lt;p&gt;DNS routing is beyond me, so I asked an old friend who is a former hacker, and he said that it will be more difficult with today&#039;s releases, but not all servers will be covered. Some are using a version of DNS software so old that the patches won&#039;t fix the vulnerability.&lt;/p&gt;
&lt;p&gt;Even easier, he told me, is hacking the client PC (which would be yours) and poisoning the DNS or resetting the host file to point to the malicious site. Software is only as smart as your system allows it to be, and for every backdoor closed, hackers are opening windows. Horowitz did a lot of work to verify where the banks said their servers were, but it&#039;s still no guarantee.&lt;/p&gt;
&lt;p&gt;Relying on any simple solution to a problem when the best defense is awareness and education is asking to be deceived.&lt;/p&gt;
&lt;p&gt;More news, commentary, and predictions from The Industry Standard:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prediction: &lt;a href=&quot;http://thestandard.com/predictions/worldwide-enterprise-network-spending-grows-2x-faster-spending-servers-and-storage-2008&quot; rel=&quot;nofollow&quot;&gt;Worldwide enterprise network spending grows 2x faster than on servers and storage in 2008&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;a href=&quot;http://thestandard.com/news/2008/06/24/microsoft-google-paypal-all-want-share-your-id&quot; rel=&quot;nofollow&quot;&gt;Microsoft, Google, PayPal all want to share your ID&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;News: &lt;a href=&quot;http://thestandard.com/news/2008/06/03/phisher-targets-uks-chinese-residents-hong-kong-site&quot; rel=&quot;nofollow&quot;&gt;Phisher targets UK&#039;s Chinese residents with Hong Kong site&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
 <comments>http://www.thestandard.com/news/2008/07/08/anti-phishing-apps-are-not-fool-proof#comments</comments>
 <category domain="http://www.thestandard.com/taxonomy/term/1683">Phishing</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5793">product:Firefox</category>
 <category domain="http://www.thestandard.com/taxonomy/term/6310">product:FlagFox</category>
 <category domain="http://www.thestandard.com/taxonomy/term/5667">Software &amp;amp; Web</category>
 <category domain="http://www.thestandard.com/taxonomy/term/2514">The Industry Standard</category>
 <pubDate>Tue, 08 Jul 2008 22:57:41 -0700</pubDate>
 <dc:creator>Cyndy Aleo-Carreira</dc:creator>
 <guid isPermaLink="false">109318 at http://www.thestandard.com</guid>
</item>
</channel>
</rss>
