Slashdot Mirror


Dealing with Phishing

Apu writes "SecurityFocus has published an interesting interview with Rachna Dhamija, co-author of the paper 'Why Phishing Works' and creator of Dynamic Security Skins (a plugin for Mozilla). She presented some very interesting results from her research efforts, for example 'simply showing a user's history information ("you've been to this website many times" or "you've never submitted this form before") can significantly increase a user's ability to detect a spoofed website and reduce their vulnerability to phishing attacks.' She also suggested to 'make it easy for users to personalize their interfaces. Look at how popular screensavers, ringtones, and application skins are — users clearly enjoy the ability to personalize their interfaces. We can take advantage of this fact to build spoof resistant interfaces.'"

1 of 168 comments (clear)

  1. Very offtopic: What's with this slashdot banner? by 88NoSoup4U88 · · Score: 0, Offtopic

    I just had an, imo, very 'intrusive' ad here on the frontpage of Slashdot: The reason why I report this is the fact that I am not a subscriber, but also don't use any ad-blockers on Slashdot (nor on other sites), as I think it's a fair deal: I get to read/write for free and they serve me ads which will give them some money in return.

    I don't mind the banners, animated or not: But I think this one (have a look at the screengrab ) got a bit too intrusive, or at least very annoying: Once you roll-over the normal banner, it changes in that one shown in the screenshot, taking up almost half of your screen.

    Going back to the original banner (by hovering off the big-size banner), I noted that, in smallprint, it warned (?) that, on mouse-over, it would pop-up the bigger one: That, imo, does not justify it though (since the banner is on top, there's a big chance of hitting it by mistake with your mouse pointer).

    Again, the reason why I made this post is not that I think (as a non-subscriber) I got any right to 'complaint' about something I receive for free: Just that -because- normally the ads are non-intrusive, I don't bother with blocking them.