Home / Blogs

Phish or Fair?

John Levine

It shouldn't be a big surprise to hear that phishing is a big problem for banks. Criminals send email pretending to be a bank, and set up web sites that look a lot like a bank. One reason that phishing is possible is that e-mail has no built in security, so that if a mail message comes in purporting to be from, say, accounts@bankofamerica.com, there's no easy way to tell whether the message is really from bankofamerica.com, or from a crook.

Mail authentication schemes like DKIM and the new dmarc.org group use cryptographic signatures to help authenticate mail and prove that it really is from who it purports to be from. So, if the mail can authenticate the sender, the phishing problem goes away, right?

Unfortunately not. One huge problem is that even if you have all the crypto stuff so you can be 100% sure that a message really is from, say, BANK-AMERICA.COM, you don't know whether BANK-AMERICA.COM is actually your bank or not.

I've made a little game called Phish or Fair. It shows you a domain name, you guess whether it belongs to Bank of America. Try it out and see how you do.

Then see if you can figure out why a bank would use over a thousand different domains. My example here is Bank of America, but they're no worse than other big banks; I picked them because their name is easy to search for.

If banks were serious about phishing, they'd pick one name, one domain, and use that consistently. But they don't.

PS: BANK-AMERICA.COM belongs to some guy in France.

By John Levine, Author, Consultant & Speaker. Visit the blog maintained by John Levine here.

Related topics: Cybercrime, Domain Names, Email, Security

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Not "little". The Famous Brett Watson  –  Feb 07, 2012 9:19 AM PDT

That's not a "little" game: I called it quits with 105 right, 0 wrong.

For all its untrustworthiness, WHOIS is still great for cheating on tests like this — and this is one of the few tests on which I recommend cheating as much as possible.

Really "great"? Alessandro Vesely  –  Feb 08, 2012 1:51 AM PDT

If WHOIS is such a great tool, why don't registrars like MarkMonitor put it somewhat more prominently on their web site, possibly explaining what can it be useful for?

Stupid Unnecessary Domain Names Daniel R. Tobias  –  Feb 07, 2012 7:03 PM PDT

It's all those idiot marketing types, at banks just like other businesses, that insist on using a zillion different domains for every marketing gimmick.  Line the marketing people against a wall and execute them by firing squad, then change the bank's web structure to use logical subdomains of their one main domain.

Maybe The Famous Brett Watson  –  Feb 08, 2012 2:54 AM PDT

It's hard to tell in this case, just by looking at the domains, as to whether they were registered with marketing intent, or registered by others then seized with the force of law (and held in perpetuity so it won't happen again). Some of them are clearly the latter kind; others, not so much.

It's also not clear whether "using a zillion different domains" is intrinsically a bad idea, particularly for a large organisation. This can be used to produce an illusion of choice. There may be so many brands in a given market that the consumer limits his evaluation to a small number of prominent ones. Under those conditions, a seller is at an advantage if he floods the market with brands, none of which are obviously related to each other. In this way, a consumer may decide to evaluate five "separate" brands, not realising that three of them are just different entrances to the same shop.

Marketing deals with people's perceptions and desires, and is thus far removed from structure and logic.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

.IN.NET - New Internet Address for India, Launching June 17th

Radix Registry Passes 4 New gTLD Initial Evaluations

DomainsBot to Help Professionals Find .PRO Internet Addresses More Easily

INTA 2013: Gearing Up for Dallas

Hope is Not a Strategy: Neustar Releases 2012 Annual DDoS Attack and Impact Survey

.PW Crosses 50,000 Domain Registrations in 3 Weeks

The Ratings Are In: Measuring .ORG's Trust and Success in Numbers

How Neustar Technology Can Help Mitigate DDoS Attacks

dot Brand or dot What? Consumers Unaware of New TLDs, Including .Google, .Microsoft and .Nike

Zodiac Prepares for Chinese New gTLDs, Announces "Chinese Advisory Services" for New gTLD Applicants

.PW General Availability Opens With More Than 4000 Orders in 30 Minutes

CentralNic Powers First New Top-Level Domains Announced by ICANN

Invitation to a Seminar on "A New Beginning - Domain Name Market in China"

LogicBoxes Announces Vertical Integration Solutions for New gTLDs

.PW Registry Extends Landrush Till March 22, 2013

DCA Registry Services Participates in ICANN Africa Strategy Meeting, Addis Ababa

Network Solutions & Register.com, Web.com, become 100th and 101st Accredited Registrars for .PW

gTLD Update: No TLDH or Client Strings Affected

Public Interest Registry Releases Report Revealing Continued Growth of the .ORG Domain

Dyn to Host Email Analytics Webinar With Ongage

Sponsored Topics

Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
dotMobi

Mobile

Sponsored by
dotMobi
Neustar

DNS

Sponsored by
Neustar
Afilias

DNS Security

Sponsored by
Afilias