Slashdot Mirror


Netcraft Toolbar for Firefox Available

miller60 writes "Netcraft has just released the Firefox version of its anti-phishing toolbar, which blocks known phishing sites and suspicious urls, and displays the hosting information and risk rating for visited sites. Toolbar users have submitted more than 5,600 phishing sites since the IE version was released in late December."

38 of 170 comments (clear)

  1. Netcraft confirms.... by FriedTurkey · · Score: 5, Funny

    Netcraft confirms that Firefox users are already smart enough to figure out if a site is phishing

    Netcraft confirms that IE users will install spyware to combat phishing.

    1. Re:Netcraft confirms.... by NetNifty · · Score: 4, Insightful

      " Netcraft confirms that Firefox users are already smart enough to figure out if a site is phishing"

      Not necessarily, it isn't just geeks that use Firefox any more - I for one (and I'm sure many other /.ers have too) have installed Firefox for many other people who would be using IE otherwise.

  2. Sweet! by Anonymous Coward · · Score: 5, Funny

    Now I canfirm that *BSD is dying without navigating to a separate page!

  3. Kudos Netcraft by bogaboga · · Score: 3, Insightful
    "...Better late than never..."

    That aside; if it takes a company like Netcraft almost 6 months to come out with a Linux version, to me that's being slow to act. Thanx never-the-less to Netcraft.

    1. Re:Kudos Netcraft by ProfaneBaby · · Score: 4, Interesting

      Speaking of 'slow', the IE version was so painfully slow that I uninstalled it after 2 days.

      I'm not sure if the load was because it was 'new' and popular, or if they didn't anticipate the number of downloads, but having the toolbar active would cause a 2-3 second delay in loading EVERY site. Very annoying.

      Hopefully they've found a way to fix that problem, either by fixing the code or adding hardware.

      --
      Video Phone Blogs send video messages straight to the web.
    2. Re:Kudos Netcraft by MynockGuano · · Score: 2, Funny

      Yes, but all it does is put a red stripe across your screen that reads, "The OS you are using appears to be dead. Consider installing something trendier."

  4. Soooon....... by cloudreader · · Score: 5, Funny

    there wont be any space in the browser to look at pages, only toolbars. someone has to come up with a toolbar organizing plugin may be?

    --
    sigbldr is currently in pre-alpha.
    1. Re:Soooon....... by StratoChief66 · · Score: 5, Funny

      Of course... but it will take the form of another toolbar.

      --
      Frylock: "We should have cloned twenties, Jackson wouldn't have given a fuck."
  5. Petname toolbar by SiliconEntity · · Score: 5, Informative

    I'd also like to remind people about the Petname Toolbar from Tyler Close, which uses capability-security concepts.

    When you visit your bank site for the first time, you enter your own chosen "pet name" for the bank, which is like a nickname. Then when you (supposedly) visit the bank again via clicking on a link, it will show you the same pet name if it is the same site. If it is a phishing site you will see a glaring indication that the site is new and not one you have previously visited and trusted. This way you will know when you are at the site that you should be at.

    It is a simple concept and doesn't rely on any humongous database created by external users. For Firefox, available today!

    1. Re:Petname toolbar by smashin234 · · Score: 3, Interesting

      "If a person is too stupid to realize whether or not they're logging into THEIR bank or not, perhaps they don't deserve the privilege of online banking"

      The scam that is scary is the bank of america scam where a bunch of miscreants copied the BOA website and had anyone typing in varieties of bankofamerica.com (I think one of them was bankofanerica.com ...)directed to their copy of the BOA website. (Identicle to the BOA website BTW)

      I am sure even you occasionally mistypes, and if you were not paying attention, you would enter you password into the wrong site.

      Of course, I don't use online banking, but for someone who does, I can't see how you could keep that from happening without being extremly careful.

      A plugin like mentioned would be very useful in this regard.

    2. Re:Petname toolbar by cant_get_a_good_nick · · Score: 2, Informative

      If a person is too stupid to realize whether or not they're logging into THEIR bank or not, perhaps they don't deserve the privilege of online banking.
      DNS spoofing
      Spyware host file poisoning.
      Spyware taking over your entire browser, pointing you to sites you don't want.
      IE bug where what you see in address bar is not the site you're on.

      Phishing is a comlicated problem with multiple vectors. Saying that a user that doesn't know all vectors at every given time is stupid is unwarranted.

    3. Re:Petname toolbar by Ochu · · Score: 3, Insightful

      And anyone computer-savvy enough to be using firefox, downloading addons, making pet names, and then remembering to check won't be caught by a pisher anyway...

    4. Re:Petname toolbar by Frank+T.+Lofaro+Jr. · · Score: 2, Interesting

      Well, I have a BOOKMARK to my bank, so I can just click on that and be safe.

      --
      Just because it CAN be done, doesn't mean it should!
  6. Re:There are enough security tools available... by 8086ed · · Score: 4, Funny

    Vegetarians don't know how to eat, let alone how to use a toolbar.

  7. In the spirit of the Nietzche/God quote... by Anonymous Coward · · Score: 5, Funny

    Slashdot is dead
    -Netcraft

    Netcraft is Slashdotted
    -Death

    (Stupid filters can't handle a well formatted joke...)

  8. Wouldn't it be ironic... by $$CALL+NOW · · Score: 5, Funny

    if this was an imitation site tricking visitors into installing a malicious "toolbar" ?

  9. Now if only I could get my people to use firefox by 1967mustangman · · Score: 5, Interesting

    I work as a sysadmin and I recently sent out an e-mail about phishing just as a general warning. As I was walking around to the other offices one of my co-workers said she wished I had sent that out a week ago and that she had just recently been phished. I got htat from two other people in the course of my rounds (in an org of less than 50). Now if only I could get my people to adopt firefox........ They could join in the battle rather than being duped.

    --
    Madre de Dios! Es El Pollo Diablo! -- Captain Blondebeard
  10. how well does this actually work by JeanBaptiste · · Score: 5, Insightful

    no I havent tried it (don't really use phishing sites much myself ;)

    but "Toolbar users have submitted more than 5,600 phishing sites"

    aren't these phishing sites usually up for only a short time, like a couple days, before they get shut down? I would think that most the sites on the 'bad list' would be shut down by the time a user gets around to updating thier 'bad list' for their toolbar.

    just a guess.

    1. Re:how well does this actually work by MrLint · · Score: 2, Interesting

      I researched and reported a phishing site on someone host and the owner of the domain actually thanked me. It was weird.

  11. First Impressions by DanCentury · · Score: 5, Informative

    I wasn't too happy with it. I uninstalled it an hour or so after installing it.

    The anti-phishing feature ID'd just about every site I visited as a threat. In some cases it might be looking at images hosted on a different host, but I think it was choking on xhtml namespaces as well. I need to reinstall it too figure this out.

    I seems to add about 10-15 seconds to Firefox's start up time. I observed the same issue with the IE version. This was enough to uninstall the toolbar from both browsers.

    I value Netcraft's services, but I think I'll go directly to their site instead.

  12. Re:There are enough security tools available... by 99BottlesOfBeerInMyF · · Score: 3, Insightful

    A vegetarian diet is tastier and better for you than what most people eat

    Your point is well taken, but the "tastiness" of a vegetarian diet is very much a personal preference and the healthiness is a matter of your metabolism. A full 8% of the human race will slowly die without meat in their diet due to the lack of certain enzymes. As an aside, have you ever noticed how vegetarian meals often are imitations of meat or dairy products? I've seen vegetarian cheeseburgers and thought, "man, just buy the real thing already." As I said though, it's a a personal preference.

  13. Netcraft toolbar function via javascript bookmark by Ized · · Score: 3, Interesting

    Eventough the toolbar gives some additional features, the main function of seeing the site's "report" can be done in any browser with a mere javascript bookmarklet. This example bookmarklet was available since last January.

  14. Now if only I could get my people to use Firefox by ndansmith · · Score: 3, Insightful
    Use the same tactics as the Phishers to dupe your fellow employees to use Firefox:

    1. Remove the IE shortcut from the desktop
    2. Add a Firefox shortcut to the desktop
    3. Rename said shortcut "Internet Explorer"
    4. Change icon of said shortcut to the blue "E"
    5. Download and install a Firefox theme which emulates the look and feel of IE.

    And there you have it! You have adapted the malicious tactics of Phishers to keep your people safe from Phishers.

  15. It breaks tabbed browsing. by topher1kenobe · · Score: 4, Informative

    According to aebrahim's head it does some really bad things to tabbed browsing.

    --

    yadda

    1. Re:It breaks tabbed browsing. by BrynM · · Score: 2, Insightful

      Confirmed, at least for the 20 minutes the toolbar was installed for me. Netcraft has a lot more porting to do to get a FF version of the toolbar working right. The toolbar doesn't appear to be aware of tabs itself and the other open tabs stopped updating the address bar when they are switched to. FYI: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.8) Gecko/20050511 Firefox/1.0.4 - Already submitted to Netcraft.

      --
      US Democracy:The best person for the job (among These pre-selected choices...)
  16. This looks like.. by hass · · Score: 2, Interesting

    A result of all the nagging /.ers that read this post --> http://yro.slashdot.org/article.pl?sid=05/05/02/18 8202&tid=158&tid=172&tid=95 I was one of the probably hundreds of people that e-mailed asking for a Firefox extension.

  17. Re:Now if only I could get my people to use Firefo by 1967mustangman · · Score: 2, Interesting

    Yeah, That would work until they went to Yahoo Games or some other site like that wich will popup and say You must have Internet Explorer 4.5 or better. Then I get a call to come fix their games.

    --
    Madre de Dios! Es El Pollo Diablo! -- Captain Blondebeard
  18. Mozilla on FreeBSD confirms by cant_get_a_good_nick · · Score: 3, Funny

    Netcraft is dying....

  19. Re:Now if only I could get my people to use Firefo by Geekboy(Wizard) · · Score: 3, Funny

    at which point you show them the clause in the employment contract that says "our computers are only avaliable for you to do actual work on", then go to slashdot and post about it.

  20. Needed? by Ochu · · Score: 3, Interesting

    Haven't we established that this doesnt work anyway? I could swear that was what the last story on this was. Something about how every phisher will just make several sites anyway, and the massive problems with false positves... It's only real purpose is the nice feeling you get from reporting it, like spam.

  21. Re:There are enough security tools available... by JOhn-E+G · · Score: 2, Funny

    You also never see Imitation veggies made out of beef!

  22. Vegetarians: The Other White Meat! by kaladorn · · Score: 3, Funny

    Tastier? I think that would be hard to substantiate objectively.

    I'd say with vast array of available animal protein out there (Bison, Ostrich, Gator, Cow, Pig, a huge variety of Fish (Cod, Halibut, Trout, Herring, Sardine, Mackerel, Talapia, Swordfish, Marlin, Tuna, Salmon, etc), other Aquatic life (Shrimp, Scallops, Lobster, Crab, Oysters, Octopus, etc), and various birds (Turkey, Chicken, Duck, Goose, Pheasant, Quail, etc)), there is little doubt that with proper preparation, you can have a vast variety of flavours. Yes, you can also have a vast variety of vegetable flavours (if they are prepared right), but if you think Vegetarian is tastier, it is either a personal preference or a very limited exposure to the range of animal-related meal items. Being an omnivore and fairly well travelled food-wise, I've sampled great vegetarian and carnivore dishes and couldn't imagine trying to say which was 'tastier'.

    As for healthy, vegetarian diets have some shortcomings. I've actually had one friend who was a Vegan ordered by her doctor to start eating meat again despite her best efforts to procure all the required nutrients and vital vitamins elsewhere. If I recall, one of the B complex vitamins was fairly hard to come by sufficiently without eating meat, despite various supplementations during any given year.

    Keep in mind as well that herbivores rule few food chains. Why? Because when worst comes to worst, an omnivore can eat plants *and* animals. A vegetarian that is rigidly so can only eat one out of two. The ominvores natural advantage is he can actually eat the vegetarians. Generally, the omnivore also recieves the benefit of concentration of food value up the food chain that predators do - the lower creatures in the chain (often herbivores) do a lot of the work concentrating food value and the predator reaps the reward.

    Or put another way, when you look at a salad, you don't see food, you see what food eats.

    We can all only make our own choices, but my ancestors worked for many millions of years to get to the top of the food chain, and that involved eating meat. I'm not about to dishonour that huge amount of effort and sacrifice :)

    To each his own, just keep in mind that when the end comes, one camp will be walking rations for the other.... :)

    --
    -- Mal: "Well they tell you: never hit a man with a closed fist. But it is, on occasion, hilarious."
  23. Alternate solution: by deacon · · Score: 2, Insightful
    Read your email in pine. No links. No images. No web-bugs.

    Press "h" on the keyboard to see the raw html of html email, including all the headers.

    It is very easy to spot fake emails once pine strips off all the glitzy fluff, and you look at the header of any emails that pass initial inspection.

  24. Re:There are enough security tools available... by Anonymous Coward · · Score: 2, Funny

    Yes, but they are masters of the saladbar.

  25. why are they using a toolbar by krunk4ever · · Score: 2, Insightful

    I don't really know why netcraft needs to be in the form of a toolbar. Why can't it be like AdBlock and put a small icon in lower right corner. I mean, it's not like a search engine where you actually need to have much intereaction with it.

    instead i suggest that they have a small icon on the lower right corner as suggested before. when the user is trying to access a known phishing site, either pop up a error box asking if user would like to continue, or redirect them to warning page. to submit phising sites to netcraft, you can easily add netcraft menu on the right click (like how you blocking ads in adblock works) and within that menu, you can submit the site.

  26. Why not just Tool Icons? by CatMan79 · · Score: 3, Interesting

    I'm so sick of entire damned toolbars. Why not just a nice little Tool Icon that displays a menu when clicked on? Something neat like the RSS bookmarks in Firefox?

  27. What to do when you're bored? Fish the phishers! by BetaJim · · Score: 3, Funny

    I have a guilty pleasure, and I want to share it with everyone here. ;)

    I look forward to receiving a phishing email. In the past I would just delete the message, but no more! I always visit their web site and give all the information I can (all the info. I can make up that is!) I try my best the make the info look legit; the credit card, bank routing numbers, name, and address, everything!

    What better way to bring attention to these crooks than to have them try to access fraudulent accounts? I guess they may have a way to filter out the bogus info, but I have fun making their work more difficult. ;)

    Lately, I noticed that the phishers web pages contain some javascript code to checksum the credit card numbers. This was a downer, until I d/l'ed a CC number generator! Oh, now my fun could continue. I hope that more people will take up my pastime.

    --

    "Drug related crime" is a misnomer, "prohibition related crime" is the more accurate and correct phrase.

  28. Re:What to do when you're bored? Fish the phishers by BetaJim · · Score: 2, Insightful

    yeah that is until you unintentionally enter a real account number and someone somewhere is the victim... perhaps one of those people out there that you wanted to help you in your quest generates your CC or bank account number an end up with no money in your account or a maxed out CC.... moron!

    I guess you don't know much about bank accounts or credit cards. What I'm doing is very safe. The likelihood of submitting a valid credit card number, expiration date, and verification number is very small. Especially, when you include an account holder name! Please get a clue.

    --

    "Drug related crime" is a misnomer, "prohibition related crime" is the more accurate and correct phrase.