Home / Blogs

Phish or Fair?

John Levine

It shouldn't be a big surprise to hear that phishing is a big problem for banks. Criminals send email pretending to be a bank, and set up web sites that look a lot like a bank. One reason that phishing is possible is that e-mail has no built in security, so that if a mail message comes in purporting to be from, say, accounts@bankofamerica.com, there's no easy way to tell whether the message is really from bankofamerica.com, or from a crook.

Mail authentication schemes like DKIM and the new dmarc.org group use cryptographic signatures to help authenticate mail and prove that it really is from who it purports to be from. So, if the mail can authenticate the sender, the phishing problem goes away, right?

Unfortunately not. One huge problem is that even if you have all the crypto stuff so you can be 100% sure that a message really is from, say, BANK-AMERICA.COM, you don't know whether BANK-AMERICA.COM is actually your bank or not.

I've made a little game called Phish or Fair. It shows you a domain name, you guess whether it belongs to Bank of America. Try it out and see how you do.

Then see if you can figure out why a bank would use over a thousand different domains. My example here is Bank of America, but they're no worse than other big banks; I picked them because their name is easy to search for.

If banks were serious about phishing, they'd pick one name, one domain, and use that consistently. But they don't.

PS: BANK-AMERICA.COM belongs to some guy in France.

By John Levine, Author, Consultant & Speaker. More blog posts from John Levine can also be read here.

Related topics: Cybercrime, Domain Names, Email, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Not "little". The Famous Brett Watson  –  Feb 07, 2012 8:19 AM PST

That's not a "little" game: I called it quits with 105 right, 0 wrong.

For all its untrustworthiness, WHOIS is still great for cheating on tests like this — and this is one of the few tests on which I recommend cheating as much as possible.

Really "great"? Alessandro Vesely  –  Feb 08, 2012 12:51 AM PST

If WHOIS is such a great tool, why don't registrars like MarkMonitor put it somewhat more prominently on their web site, possibly explaining what can it be useful for?

Stupid Unnecessary Domain Names Daniel R. Tobias  –  Feb 07, 2012 6:03 PM PST

It's all those idiot marketing types, at banks just like other businesses, that insist on using a zillion different domains for every marketing gimmick.  Line the marketing people against a wall and execute them by firing squad, then change the bank's web structure to use logical subdomains of their one main domain.

Maybe The Famous Brett Watson  –  Feb 08, 2012 1:54 AM PST

It's hard to tell in this case, just by looking at the domains, as to whether they were registered with marketing intent, or registered by others then seized with the force of law (and held in perpetuity so it won't happen again). Some of them are clearly the latter kind; others, not so much.

It's also not clear whether "using a zillion different domains" is intrinsically a bad idea, particularly for a large organisation. This can be used to produce an illusion of choice. There may be so many brands in a given market that the consumer limits his evaluation to a small number of prominent ones. Under those conditions, a seller is at an advantage if he floods the market with brands, none of which are obviously related to each other. In this way, a consumer may decide to evaluate five "separate" brands, not realising that three of them are just different entrances to the same shop.

Marketing deals with people's perceptions and desires, and is thus far removed from structure and logic.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Public Sector Experiences Largest Increase in DDoS Attacks (Verisign's Q4 2014 DDoS Trends)

NSW Government Launches .sydney Domain

New .VOTE and .VOTO Domains Now Available

Help Ensure the Availability and Security of Your Enterprise DNS with Verisign Recursive DNS

Verisign iDefense 2015 Cyber-Threats and Trends

Verisign Launches New Monthly Blog Series: Top 10 Keywords Registered in .COM and .NET

.LGBT Public Launch Begins Today

Verisign Celebrates .com's 30th Anniversary, Launches Domain Name Contest

What's in Your Attack Surface?

New .LGBT Domain Sunrise Period Begins

Minds + Machines in 2014 and 2015

DNW Podcast Interview with Antony Van Couvering

TLD Registry and Right of the Dot Establish a Domain Name Industry "Dream Team"

"Chinese Domaining Masterclass" to be Presented at NamesCon Las Vegas in January 2015

Q3 2014 DDoS Trends: Attacks Exceeding 10 Gbps on the Rise

LogicBoxes Announces Automation Solutions for ccTLD

TLD Registry Wins Best Marketing Award at China New gTLD Roadshow

Update on Minds + Machines' Top-Level Domain Launches

ICANN Los Angeles Recap Webinar

TLD Registry Appoints First China General Manager, Mr Jin Wang

Sponsored Topics

dotMobi

Mobile

Sponsored by
dotMobi
Afilias

DNS Security

Sponsored by
Afilias
Verisign

Security

Sponsored by
Verisign
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines