Home / Blogs

Phish or Fair?

It shouldn’t be a big surprise to hear that phishing is a big problem for banks. Criminals send email pretending to be a bank, and set up web sites that look a lot like a bank. One reason that phishing is possible is that e-mail has no built in security, so that if a mail message comes in purporting to be from, say, [email protected], there’s no easy way to tell whether the message is really from bankofamerica.com, or from a crook.

Mail authentication schemes like DKIM and the new dmarc.org group use cryptographic signatures to help authenticate mail and prove that it really is from who it purports to be from. So, if the mail can authenticate the sender, the phishing problem goes away, right?

Unfortunately not. One huge problem is that even if you have all the crypto stuff so you can be 100% sure that a message really is from, say, BANK-AMERICA.COM, you don’t know whether BANK-AMERICA.COM is actually your bank or not.

I’ve made a little game called Phish or Fair. It shows you a domain name, you guess whether it belongs to Bank of America. Try it out and see how you do.

Then see if you can figure out why a bank would use over a thousand different domains. My example here is Bank of America, but they’re no worse than other big banks; I picked them because their name is easy to search for.

If banks were serious about phishing, they’d pick one name, one domain, and use that consistently. But they don’t.

PS: BANK-AMERICA.COM belongs to some guy in France.

By John Levine, Author, Consultant & Speaker

Filed Under

Comments

Not "little". The Famous Brett Watson  –  Feb 7, 2012 4:19 PM

That’s not a “little” game: I called it quits with 105 right, 0 wrong.

For all its untrustworthiness, WHOIS is still great for cheating on tests like this—and this is one of the few tests on which I recommend cheating as much as possible.

Really "great"? Alessandro Vesely  –  Feb 8, 2012 8:51 AM

If WHOIS is such a great tool, why don't registrars like MarkMonitor put it somewhat more prominently on their web site, possibly explaining what can it be useful for?

Stupid Unnecessary Domain Names Daniel R. Tobias  –  Feb 8, 2012 2:03 AM

It’s all those idiot marketing types, at banks just like other businesses, that insist on using a zillion different domains for every marketing gimmick.  Line the marketing people against a wall and execute them by firing squad, then change the bank’s web structure to use logical subdomains of their one main domain.

Maybe The Famous Brett Watson  –  Feb 8, 2012 9:54 AM

It's hard to tell in this case, just by looking at the domains, as to whether they were registered with marketing intent, or registered by others then seized with the force of law (and held in perpetuity so it won't happen again). Some of them are clearly the latter kind; others, not so much. It's also not clear whether "using a zillion different domains" is intrinsically a bad idea, particularly for a large organisation. This can be used to produce an illusion of choice. There may be so many brands in a given market that the consumer limits his evaluation to a small number of prominent ones. Under those conditions, a seller is at an advantage if he floods the market with brands, none of which are obviously related to each other. In this way, a consumer may decide to evaluate five "separate" brands, not realising that three of them are just different entrances to the same shop. Marketing deals with people's perceptions and desires, and is thus far removed from structure and logic.

Comment Title:

  Notify me of follow-up comments

We encourage you to post comments and engage in discussions that advance this post through relevant opinion, anecdotes, links and data. If you see a comment that you believe is irrelevant or inappropriate, you can report it using the link at the end of each comment. Views expressed in the comments do not represent those of CircleID. For more information on our comment policy, see Codes of Conduct.

CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

I make a point of reading CircleID. There is no getting around the utility of knowing what thoughtful people are thinking and saying about our industry.

VINTON CERF
Co-designer of the TCP/IP Protocols & the Architecture of the Internet

Related

Topics

Threat Intelligence

Sponsored byWhoisXML API

Brand Protection

Sponsored byCSC

Domain Names

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global

New TLDs

Sponsored byRadix

Cybersecurity

Sponsored byVerisign

DNS

Sponsored byDNIB.com