[17816] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: New Credit Card Scam (fwd)

daemon@ATHENA.MIT.EDU (Jason Holt)
Tue Jul 12 13:11:22 2005

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
Date: Tue, 12 Jul 2005 01:01:05 +0000 (UTC)
From: Jason Holt <jason@lunkwill.org>
To: Lance James <lancej@securescience.net>
Cc: cryptography@metzdowd.com
In-Reply-To: <42D30B23.6060504@securescience.net>


On Mon, 11 Jul 2005, Lance James wrote:
[...]
> place to fend off these attacks. Soon phishers will just use the site itself 
> to phish users, pushing away the dependency on tricking the user with a 
> "spoofed" or "mirrored" site.
[...]

You dismiss too much with your "just".  They already do attack plenty of 
sites, but they also phish because it has a larger return on investment. 
Security is the process of iteratively strengthening the weakest links in the 
chain.

 					-J

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post