big-national.bank.criminalz.ru
|
Mikko Hypponen of F-Secure has come up with an idea for combating some phishing - the .bank top-level domain. Not just any clown could register a domain under this TLD, just clowns at banks. The ideaI guessis that customers will learn to trust that bank sites always have the .bank TLD. Mikko's usually a lot more insightful than this. The problem is that users don't look at the URL carefully, and often they can be confused and fooled by domains like the one in the title of this blog entry. In fact, if users could be trusted to look at such things they would be better-served by EV SSL, which has the same high cost of entry that Mikko proposes for .bank and a much more prominent display to the user. |

Comments (3)
I'm with you Larry. Please check out my recent blog post on the topic.
Posted by Ben Feinstein | May 9, 2007 11:02 AM
I think you are underestimating us, the users. I might not be a security expert but I surely know how to read the url in the address bar. Even if I dont know what ssl is. Any normal citizen who reads his monthly bank reports, or reads his phone and electricity bills, any normal person who respects himself, without being an expert, can point out such obvious differences. Its plain .bank and nothing else. How difficult is that to understand?
I wish that governments would take domain registrations more seriously and not give them away so easily. That would reduce the amount of fraud out there. Now its just too easy to get any domain, and if we cant correct the harm we have already done to the internet by making the domain registration processes more complicated, ideas like the .bank are surely a solution.
I believe that internet education and awareness should start in high school. Protecting the audience with technical means is one way of solving the problem. Protecting them by educating them is another. In my academy we went through seminars about the nature and dangers of drugs. Why can't they do the same about internet fraud and pc security?
Posted by Angelina Kontini | May 19, 2007 10:09 AM
But Angelina, you aren't the users Larry et al. are concerned for. You can read the URL. So can a lot of other people, but bottom-line, too many people don't. Even with your idea of high school (let's make it elementary for that matter) education, you still have a good 60+ years of post-high school grads out there who will not have had your lessons. BTW- people still get duped into taking drugs despite all the brainwashing in school.
At the end of the day, a new TLD will do nothing more than a .com. It will be easily spoofed and we can make links and URL's say whatever we want them to say.
Posted by Harry | May 20, 2007 7:02 PM