Slashdot Mirror


Paypal Advises Users To Stop Using Safari

eldavojohn writes "Over concerns for lack of an anti-phishing mechanism for Safari, Paypal is telling its Mac users to use another browser. An author from Ars Technica reveals that he has been using Camino and has fallen victim to a Paypal related phishing scam via e-mail so this story must hit home for him. 'Currently the Apple browser does not alert users to sites that could be phishing for your info, and it lacks support for Extended Validation. PayPal is, of course, a popular site among phishers in their neverending search for personal information, user IDs, and passwords. While it's not entirely fair singling out Safari (other Mac browsers like Camino also lack this support), it is perhaps at least a helpful reminder of the threat.'"

69 of 362 comments (clear)

  1. Maybe Apple should... by gillbates · · Score: 4, Insightful

    Tell Safari users to stop using PayPal...

    --
    The society for a thought-free internet welcomes you.
    1. Re:Maybe Apple should... by Jeremiah+Cornelius · · Score: 5, Insightful

      C'mon.

      Apple is deficient here - no doubt about it. If you want Mom & Pop to click "pay now", you don't expect 'em to be able to parse "http://www.barclays.validation.co.uk". You don't have to be an "idiot" to fall for this - just outside your area of expertise.

      I have replaced Safari with FireFox on every friend and family mac I get my hands on. Re-theme it, copy and paste the icon resource, and they don't notice the change!

      Except for the missing ads - thanks to Ad Block+

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    2. Re:Maybe Apple should... by Breakfast+Pants · · Score: 2, Funny

      Paypal will have to tell phishing sites to copy this Safari warning as well, which I'm sure they will be happy to do.

      --

      --

      WHO ATE MY BREAKFAST PANTS?
    3. Re:Maybe Apple should... by goombah99 · · Score: 2, Interesting

      What theme do you recommend as the most "mac-like" and minimalist in screen real estate? and what do you mean copy and paste the icon resource.

      --
      Some drink at the fountain of knowledge. Others just gargle.
    4. Re:Maybe Apple should... by Constantine+XVI · · Score: 2, Informative

      The Firefox3 betas come with a new very Mac-like theme, called Proto. I believe you can download it for Firefox2 as well

      --
      "I think an etch-a-sketch with an ethernet port would beat IE7 in web standards compliance."
    5. Re:Maybe Apple should... by MacDork · · Score: 5, Insightful

      C'mon.

      Apple is deficient here - no doubt about it.

      Deficient eh? I use Omniweb. Same issues I'm sure, but I'm comfortable with it. I have something I feel is far more secure than a colored URL bar and Extended Validation box that begs for attention... I have an encrypted system wide keychain that is not going to have a username/password for paypa|.com. I might not catch that pipe as a lower case L... I my not catch a cyrillic character that looks just like an 'a' in there, but my keychain aware browser certainly will. It won't have a password for that domain, and that will instantly alert me to the fact that something is fishy. Proceed to open a new window and manually enter the address as a test... I rely on my keychain so much, I generally don't know the password for most websites I use, so I therefore cannot be suckered into revealing it. I'm sure Safari can be configured the same way.

      Instead of railing on Apple for not adopting the technologically deficient solution of other browser makers, perhaps they should instead focus on what is IMHO a superior approach to security... No dice on Windows Safari, sure, but on the Mac I have no fear of phishers.

    6. Re:Maybe Apple should... by Anonymous Coward · · Score: 4, Insightful

      What theme do you recommend as the most "mac-like" and minimalist in screen real estate?
      Please - that's like asking for "the most Windows-like and stylish".

      Minimalist use of screen real estate is not a Mac virtue: Apple's principle is that screen real estate should be used well, not minimally. That's why they've made a big deal out of having bigger icons than Windows, for example, even though that means the Dock takes up about three times as much screen real estate as Windows' taskbar. Big icons = easier to hit = more efficient for the user. You aren't wasting that space, you're trading it for your time. And I assure you, unless you flip burgers or something then your time is valuable enough that you can certainly justify buying a bigger screen if you really need more working space.

      (Incidentally, I do rather wonder why, with modern Macs all having wide-aspect monitors, the default Dock position is still along the bottom of the screen, and why windows still have their toolbars along the top rather than down the side, but those are whole other cans of worms...)
    7. Re:Maybe Apple should... by MightyYar · · Score: 4, Informative

      Let Safari/Firefox save your username/password. Then when it doesn't auto fill-in, you know something is up.

      Safari is better for this strategy since it uses the secure key chain and not the - last time I checked - weak obfuscation that Firefox uses.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    8. Re:Maybe Apple should... by Anonymous Coward · · Score: 3, Insightful

      So why is closing a Mac window harder than threading a needle? And with the close button so small, why do standard dialogs generally lack an "OK" or "Close" button, with the expectation that we use those itty-bitty buttons way up in the corner?


      Why does Microsoft Windows have such big titlebars and buttons on all windows? Why does it always have these unnecessary 'ok' 'close' buttons everywhere? Why doesn't it have fast, easy keyboard shortcuts for most tasks?

      Actually, the huge, hunking graphics in Windows is as good enough reason as any to avoid it.
    9. Re:Maybe Apple should... by misleb · · Score: 4, Interesting

      I have replaced Safari with FireFox on every friend and family mac I get my hands on. Re-theme it, copy and paste the icon resource, and they don't notice the change!


      And with Firefox 3, you don't even need a theme. They look very similar now. Firefox 3 even seems to use the Aqua style widgets.

      -matthew
      --
      "THERE IS NO JUSTICE, THERE IS ONLY ME." -Death
    10. Re:Maybe Apple should... by Jeremiah+Cornelius · · Score: 3

      The day I let a browser/OS save credentials to my critical, financial account information is the day Tom Cruise goes straight.

      I spent five years doing pen/VA for banks and insurance companies. I take none of this crap for granted.

      Physical security of your laptop becomes far too high a risk.

      "Keychain" is for .Mac, not Lloyd's.

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    11. Re:Maybe Apple should... by catwh0re · · Score: 2, Insightful
      While I agree that anti-phishing features would be a plus for Safari.(go download an extention like you do for any other browser) I think the problem should be addressed on the Paypal end. After all their website, links to ebay and methods are severly lacking as is it - even when you aren't diverted to a phishing scam there are a whole list of reasons not to use paypal.

    12. Re:Maybe Apple should... by fangorious · · Score: 2, Insightful

      I would complain about you breaking keychain integration, most people I know hate when someone does crap like that, and they just stop asking for your help because they're afraid you'll just break something else.

    13. Re:Maybe Apple should... by PopeRatzo · · Score: 4, Funny

      Are you some sort of cripple?
      Another Mac fan shows his people skills.
      --
      You are welcome on my lawn.
    14. Re:Maybe Apple should... by Jeremy+Erwin · · Score: 2, Interesting

      Another Mac fan shows his people skills.


      Why shade truths? One of my maths professors, who contracted polio in his younger years, was quite content to use that term to describe himself, when it was relevant.

      Unless you have some physical condition that prevents it, there's really very little excuse for poor mousing skills. If the mouse doesn't track properly, or isn't weighted correctly, buy a new one.
    15. Re:Maybe Apple should... by navyjeff · · Score: 2

      I never had a problem with Cmd-W, Cmd-Q or Tab/Spacebar.

    16. Re:Maybe Apple should... by MightyYar · · Score: 2, Insightful

      I wouldn't trust it on my laptop, either. If someone is sitting on your home computer, you've got bigger problems than the password to your eBay account.

      But if I did have it on my laptop, I'd sure as hell change my passwords the first chance I get.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
    17. Re:Maybe Apple should... by Jeremiah+Cornelius · · Score: 2

      These are people who say: You do security for a living. How do I keep from getting my credit card stolen on the Internet? Can you help me?

      Not a choice I sneak on to their computer, in the dead of night! :-)

      --
      "Flyin' in just a sweet place,
      Never been known to fail..."
    18. Re:Maybe Apple should... by Jarjarthejedi · · Score: 2, Insightful

      "I wouldn't trust it on my laptop, either."

      "But if I did have it on my laptop, I'd sure as hell change my passwords the first chance I get."

      This seems like a bit of an illogical statement, along the lines of calling to cancel a lost credit card. You seem to be making the claim that a laptop with those saved credentials can be lost, which is a good enough reason to not make use of it, and yet people have been losing and canceling credit cards for years, a laptop is much easier to notice missing than a piece of plastic, and the problem wouldn't be hard at all to fix.

      Personally I commit my passwords to memory and let my computer auto-fill them, the auto-fill for convenience (and because the chances of me losing my laptop, my primary computer which is pretty much on my person at all times and has a high strength login password among other security measures are slim to none) and the memory so that I can get into them without my computer, whether it be to change them or simply to get to them from another computer.

      --
      There are two kinds of fool One says 'This is old therefore good' Another says 'This is new therefore better'- Dean Ing
    19. Re:Maybe Apple should... by Jarjarthejedi · · Score: 2, Interesting

      Speed is as good an excuse as any. On a Windows machine I can swing my mouse from one part of the screen to another and end up on the close button with 90% accuracy, primarily because of its size. On macs (and the distro of linux my school uses) I have to swing the mouse over, then spend a few extra seconds lining it up because of how small the close button is. Sure, it's only a few seconds, but convienience is a factor in OS choice, and Window's close buttons got that part right a lot more than Mac (if you can avoid the ever present 'there's no space between the restore to default and close buttons, be careful' problem, which is usually irrelevant if you don't use non-maximized windows much).

      --
      There are two kinds of fool One says 'This is old therefore good' Another says 'This is new therefore better'- Dean Ing
    20. Re:Maybe Apple should... by Z34107 · · Score: 4, Interesting

      Why doesn't it [Windows] have fast, easy keyboard shortcuts for most tasks?

      Enter - hit the default button. Closes all those annoying "OK" dialogs.

      Space - hit the currently selected button. Like a left mouse-click, but for the soul.

      Tab - Switch between buttons/check boxes/tabs/etc in a form. Use arrow keys to select an option from a series of radio buttons.

      Shift+Tab - Switch between buttons/check boxes/tabs/etc, but going the other way.

      Windows+R - Bring up the "Run" dialog.

      Windows+E - Bring up Explorer.

      Windows+D - Minimize everything to your desktop. (Or restore everything again.)

      F1 - Help.

      CTRL+C or CTRL+INS - Copy files/selected text/etc. to clipboard. (Sorry, meta+C.)

      CTRL+V or SHIFT+INS - Paste files/selected text/etc. from clipboard.

      ALT+F4 - Close current program or dialog box.

      CTRL+SHIFT+ESC - Bring up task manager.

      CTRL+ALT+DEL - You should know what this does. Also brings up "Windows 2000" style login from the welcome (user selection) screen in XP.

      You can run Windows without a mouse. No, really, you can - my desktop only has icons for games with long paths hidden in program files. With Windows 98 (and maybe others) you could set the default shell in WIN.INI or some other file to the command prompt instead of explorer.exe - the effect was a DOS-looking computer that could run all your Windows 98 apps! (My parents didn't see the novelty in this.)

      As for honking graphics... Aero! (ducks)

      But, I use a DAS Keyboard 2 and type 140 wpm on a slow day. I hate the lag time involved in reaching for the bloody 2-dimensional X,Y coordinate translocator, so I use these shortcuts daily. I'm sure there are others; these are just the ones that came to mind.

      --
      DATABASE WOW WOW
    21. Re:Maybe Apple should... by vertigoCiel · · Score: 2, Insightful

      Firefox 3 even seems to use the Aqua style widgets. Seems being the operative word.
    22. Re:Maybe Apple should... by iamacat · · Score: 2, Insightful

      Why, you want your Linux browser to sport Windows XP title bar, ignore -display directive, omit support for .tar.gz files, require Ctrl-C/Ctrl-V for copy and paste and ignore middle mouse click...?

    23. Re:Maybe Apple should... by iamacat · · Score: 2

      why do standard dialogs generally lack an "OK" or "Close" button

      Which standard dialogs are you talking about? Open, Save and Quit dialogs definitely have non-titlebar buttons for each possible action. Would be kind of hard to use them otherwise since they are actually sheets and share the titlebar with document windows.

      Offhand, I can only confirm that applications' about Dialogs are lacking buttons. Do you really bring them up often enough to have trouble using the titlebar to dismiss them?

    24. Re:Maybe Apple should... by NotAgent86 · · Score: 2, Insightful

      So which windows version came before the mac?

    25. Re:Maybe Apple should... by dangitman · · Score: 2, Interesting

      Re-theme it, copy and paste the icon resource, and they don't notice the change!

      Yeah right. Firefox fails because of the way it handles text fields in a totally non-Mac-like way. Have your cursor at the end of a single-line text field (like the URL entry field) and want to go back to edit something at the beginning of the line? In just about every other Mac application, you simply hit the up-arrow once, and it goes to the beginning of the line of text. But not in Firefox, for some reason. Instead, I have to hold down the left-arrow and wait for it to get to the start of the line.

      The same thing shits me when using Ubuntu. How can major applications get such basic text navigation so wrong? Changing the "theme" to look like something else isn't going to fix fundamental interface flaws. Firefox also has problems with the behavior of drop-down menus and selecting items in them.

      --
      ... and then they built the supercollider.
    26. Re:Maybe Apple should... by theurge14 · · Score: 3, Insightful

      Minimalist use of screen real estate is not a Mac virtue:

      Big icons is your only example of this? On the contrary:

      * The 'Maximize' button will only open the app window as large as the content inside of it requires, it will not fill the screen.
      * One menu bar along the top for all open windows ensures no screen space is wasted with repeated displays of a menu bar.
      * Mac OS X automatically resizes dialog boxes to accommodate the content inside of them.
      * Dialog boxes that open off the edge of the screen will be automatically moved back into the screen along with the rest of the app, and when closed the OS will shift the app back where it was before you opened the dialog box.
      * Most apps do not have a 'background' window as to allow interaction with the desktop while the app is open. One common example is Photoshop.

      Most Windows users I observe maximize all their open apps to completely cover the desktop and use the Start bar as a full-screen task-switcher. In other words, a multi-tasking MS-DOS.

    27. Re:Maybe Apple should... by darthflo · · Score: 2, Informative

      Stupid science, having a different opinion than me again ;)

      Anyways, there's an easy, system-independent solution for at the very least your input troubles: Localized keyboards. You seem to be using lots of international characters (ë is french, ö is german, £ english), you may want to try the German (Switzerland) keyboard layout. It's a bit more convoluted than en-US (up to four or five characters on a single key), but it does have all the chars you get on en-US, all the chars you need for german, french, italian, conversations about english, american or european currencies.

      Check it out

  2. IE by webmaster404 · · Score: 2, Insightful

    So wait.... you shouldn't use a (decently) secure browser such as Safari that is partly open-source, while you should use a browser that is fully proprietary (though with anti-phishing) and has a track record of being insecure? Not to mention how easy it is to keylog most Windows systems have already? Honestly, I think that making sure your browser is secure is much more important then making sure your info isn't going to an incorrect site.

    --
    There is no "disagree" moderation, and troll, flamebait and overrated are not valid substitutes
    1. Re:IE by Loconut1389 · · Score: 2, Insightful

      Good point- the types of people who would install/use another browser, probably already do check.

    2. Re:IE by teh+moges · · Score: 2, Insightful

      This used to be a valid point, but Safari ships with OSX and a lot of users get Firefox installed by their tech-savvy friends. Still, there is a very simple way of getting around these problems:
      1) No financial institution should ever ask for your email address. Ever. Not as a required field, not as an optional field. The person signing up should be informed that they are deliberately not being asked for this information either.
      2) The exception to this: Reminders. These are setup WHILE logged in to the site, and the email address is stored in relation to the reminder, not the account profile (so it will be indirectly linked, but a helpdesk person won't see it when troubleshooting account information).
      3) All reminder emails are plain text only, with a clear message informing the user not to trust this email or any other email and to log in to the website by typing the address into a browser only.

      Like was said above, people don't need to be stupid, they just need to be out of their expertise. I'm not a security expert, but through my knowledge of computers, I know when I get sent a phishing email, I know how to surf safely. You can't expect everyone to be the same though. This is just a case of needing to inform the users, and to keep reminding them.
      * The method shown above is not foolproof, in the case of DNS attacks, or websites with similar names (user types in address, typos, and is sent to another site).

  3. OpenDNS to the rescue by bstadil · · Score: 5, Informative

    Just change your DNS to OpenDNS and you are covered. OpenDNS monitors Phising sites and will not let you resolve to it. You don't need to sign up just use their nameservers at 208.67.222.222 and 208.67.220.220. It's free. If you sign up you get some additional cool features like blocking selected domain types Like Pron if that's not your thing.

    --
    Help fight continental drift.
    1. Re:OpenDNS to the rescue by karmatic · · Score: 4, Insightful

      OpenDNS monitors Phising sites and will not let you resolve to it.
      That's assuming, of course, that it's using a unique DNS name. For pages hosted on SourceForge, Geocities, etc. it won't do anything at all, and may provide a false sense of security.

      Furthermore, it's really easy to create phishing pages that will only show their contents to humans, and not spiders.

    2. Re:OpenDNS to the rescue by fm6 · · Score: 5, Funny

      OpenDNS monitors Phising sites and will not let you resolve to it.
      OpenDNS monitors known phishing sites. Phishers really should update the database when they start a new site, but for some strange reason, they rarely bother.
    3. Re:OpenDNS to the rescue by Peaker · · Score: 2, Insightful

      Furthermore, it's really easy to create phishing pages that will only show their contents to humans, and not spiders. Isn't it equally easy to create spiders that look like humans?

      Does there phishing information originate from a spider, anyhow?
  4. What nonsense. by gnutoo · · Score: 5, Informative

    IE over Safari? Really? I can understand wanting a good free browser like Firefox on OSX but IE? Do they even have IE 7 for OSX yet? The article Ars points to says that this is driven by IE7 users not quiting PayPal. The fishing stuff is pure speculation and not even Microsoft thinks IE7 fishing protection is effective:

    Last year, researchers at Microsoft and Stanford University published a study showing that, without training, people were unlikely to notice the green address-bar notification provided by EV certificates.

    Barrett says data compiled on PayPal's Web site show that the EV certificates are having an effect. He says IE 7 users are more likely to sign on to PayPal's Web site than users who don't have EV certificate technology, presumably because they're confident that they're visiting a legitimate site.

    Over the past few months, IE 7 users have been less likely to drop out and abandon the process of signing on to PayPal, he said. "It's a several percentage-point drop in abandonment rates," he said. "That number is... measurably lower for IE 7 users."

    Rather than percieved security, I think the reason they see more IE7 users still logging in is because IE7 users are the kind of sheep that move along when prodded. They are using Windows, right? Like sheep to the slaughter, every day.

    I've got a paypal account. I don't use it much because I don't use Ebay much. I would never use an emailed link to visit the site because it's just as easy to find the right page through Paypal itself. If they make it hard, they don't deserve my business.

    1. Re:What nonsense. by Knara · · Score: 2, Informative

      AFAIK there will never be an IE7 for OS X

  5. here phishie phishie by themushroom · · Score: 3, Insightful

    Look, if you're not checking what's in the URL of your browser, or are in the habit of clicking on links in email blindly, you get the phishing you deserve. The best protection mechanism in any browser against phishing is your eyes, looking at the address bar.

    snark: And Safari users are advised to stop using PayPal.

    1. Re:here phishie phishie by Niten · · Score: 4, Insightful

      Look, if you're not checking what's in the URL of your browser, or are in the habit of clicking on links in email blindly, you get the phishing you deserve.

      I'm all for exercising personal responsibility, but I'd never argue that anybody 'deserves' to fall victim to a phishing scam.

      The fact of the matter is that there are some people (my grandparents, for example) who like to use the Web, but who are perhaps just a little bit senile and might one day fall for this sort of thing. If even an Ars Technica writer can fall for it, how can we expect an 80+ year-old to constantly exercise due vigilance?

      I'm actually quite OK with this PayPal advisory: the kind of people who will act upon it -- computing amateurs, basically -- probably should be using a browser that raises a big fat red flag when it hits a known scam site, and I'd recommend that such people use Firefox, Opera, or even IE 7 rather than Safari. The rest of us, those who are clueful enough to know how to protect themselves, aren't really the ones that PayPal is addressing here.

    2. Re:here phishie phishie by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      Look, if you're not checking what's in the URL of your browser, or are in the habit of clicking on links in email blindly, you get the phishing you deserve.

      On this I must disagree. Right now the best solution probably is double checking URLs, but that is realistically not a good solution for the majority of people. Apple (and every other browser developer) should be working on a a URL whitelist/greylist/blacklist detection and warning technology. I'm not sure, however, that they should rush to deploy such technology. It might be better to wait until it is reliable enough to provide real benefit without providing a false sense of security. Right not IE has such a technology, but reviews show it to be of little, practical use. I know Apple is working on such technology and depending upon how effective it seems to be, it might be best that they have not rolled it out for Safari yet. I do think there s a real demand for this type of technology and developers should be trying to fill that need.

      snark: And Safari users are advised to stop using PayPal.

      Well... I might say all security minded users might be well advised to stop using Paypal. We have Google Checkout now who would want to use Paypal?

    3. Re:here phishie phishie by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      Why is double checking the URL not a good solution for most people?

      First, because as more and more services become dependent upon URLs there are fewer and fewer URLs that don't have some feature that might indicate they are really a phishing attempt. Also, as the Web becomes more international more characters that look the same or very similar are introduced. More and more legitimate e-mail messages, even automated ones, reference Web sites. Am I going to look at every single e-mail I get from Netflix to make sure the URL that pops up really is NetFlix? Maybe, or maybe I won't sometime and if the tab that loads does not have a warning, maybe I'll mistake it for Netflix. Maybe I will look, but maybe I won't notice it is netf1ix.com instead of netflix.com. Everyone makes a mistake now and again and most people are nowhere near as security conscious as I am.

      Can you honestly say there is no way you would ever make that mistake? Can you honestly say there is no way your grandmother or 8 year-old nephew could not make that mistake? Technology to automatically verify the identity of a Web server is useful for everyone and I believe there is a real demand. If that demand is ignored, people will go elsewhere, maybe to IE7 where they feel safer, or maybe to Opera. Web browser developers ignoring that demand will probably lose out. If you don't want to use it, don't worry. I'm sure Firefox will let you turn it off, and if it won't, will you can always fork it.

      Are they blind?

      Some of them are, certainly. I know it takes my friend a lot longer to listen to a page via an audio interface or even read it using his braille board. By default, I don't even think it reads the URL and if it did it would be a huge annoyance for him.

      Oh did you mean that as a rhetorical question? Too bad, it is a real concern.

      If you want a car analogy, "If I can't be relied on to observe traffic around me while driving, then I should not be driving, regardless of how necessary society says driving is."

      By that logic, we should all be observant enough to check our coolant levels before driving too. After all, once in a great while it is too low and the engine will overheat. Why bother to put a heat sensor and warning light on the dash? What are you, blind or something? If you can't check your engine coolant periodically you should just walk everywhere.

  6. Phishing protection? Really? by SanityInAnarchy · · Score: 4, Insightful

    The kinds of people who fall for phishing scams aren't likely to pay attention to what PayPal advises them to do.

    So why not cut the middleman and just advise them to not fall for phishing scams -- that is, to always verify https://www.paypal.com/ in the URL?

    --
    Don't thank God, thank a doctor!
    1. Re:Phishing protection? Really? by Mesa+MIke · · Score: 5, Funny

      DON'T CLICK ON THAT LINK!

      It might be a phishing scam!

  7. Every browser has and anti-phishing mechanism by edalytical · · Score: 4, Interesting

    It's called the address bar. It's very easy to use, just type where you want to go and press return. Before entering sensitive information into a browser window check the address bar and make sure you are where you think you are. I know your mom and my mom might not fully understand the address bar, but I think it would be easier for them to learn about it than installing a new browser.

    --
    Win a signed Stephen Carpenter ESP Guitar from the Deftones: http://def-tag.com/?r=0008781
    1. Re:Every browser has and anti-phishing mechanism by mikael_j · · Score: 3, Insightful

      But DNS cache poisoning isn't really a browser issue, is it? (although I suppose a browser exploit could be used to pollute the local DNS cache on a user's machine)

      /Mikael

      --
      Greylisting is to SMTP as NAT is to IPv4
  8. i've gotten those scam e-mails before... by kesuki · · Score: 2, Interesting

    http://www.fightidentitytheft.com/paypal_scam.html

    mine was similar, only it claimed they were doing a fraud investigation about fraudulent use to my account.

    they use the images and everything it looks exactly like a paypal e-mail, only the hyper link when you hover over it says a different website than in the email message. (they're doing a simple html trick, which is always the first thing i look for)

    I've seen them do the same thing with say, yahoo mail login sites, etc. one of my less savvy friends got her IM name stolen for use sending IM spam.

    safari is bass acwards to not show the real url on a tool bar! i couldn't live a day without that feature.

    1. Re:i've gotten those scam e-mails before... by Gewalt · · Score: 2, Insightful

      You mean the status bar, and safari hides that by default because it can be erronously updated with javascript. In other words, if you're relying on the status bar, you're your own worst enemy.

      --
      Modding Trolls +1 inciteful since 1999
  9. Browsers cannot help by wardk · · Score: 2, Insightful

    those too ignorant to leave URL's in emails ALONE

    the headline could have also just said "Paypal tells idiots to stop clicking on paypal emails"

    but that would potentially stop the 1 in 1000000 clicks that are legit and paypal would not want that transaction to not happen, so it's message to us is to stop using Safari.

    isn't anything going on worth reporting? this is filler...

  10. They've had it too good for too long... by SterlingSylver · · Score: 5, Funny

    Well, if there's group of users that has been told repeatedly that their computer is safe from viruses, that it "just works," and that they don't need to be concerned with computer threats of any kind...it's Apple users. Sitting in their offices, wearing their turtlenecks and sipping their lattes, the only thing about phishing they've heard about is that it happens to other people. Uglier people. They're not used to having to defend themselves, not like Windows users. Windows users have a battle-scarred paranoia...they've seen worms that can rewrite their BIOS, steal their credit cards, and kidnap their firstborn. Their 50 yard stares have been earned by fixing their mom's computer for the eighth time this month, and damnit if they're going to lose another computer to some Ethiopian scammer...not after the last time. Their nightmares are the stuff of Steven King novels, the earlier stuff with lovecraftian clowns and superplagues that are the start of apocalyptic battles between good and evil. Their best days on the internet involve life and death struggles against the next pop-up, because it might be their last. Ironically, Mac users have never had to live with the terror that clicking on that "win a free iPod" might just cause their computer to explode, spamming their grandmother with anal tranny porn on its way out. Maybe it's time they should... ...wait, what the hell was I talking about?

    1. Re:They've had it too good for too long... by sharkey · · Score: 2, Funny

      Windows users have a battle-scarred paranoia...they've seen worms that can rewrite their BIOS, steal their credit cards, and kidnap their firstborn.

      And the fuckers STILL just click every YES button that pops up.

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  11. Oh, stop whining. by Whiney+Mac+Fanboy · · Score: 5, Insightful

    All Paypal did was have a faq containing a list of anti-phishing features & browsers that support those features.

    They don't recommend against Safari, they just recommend browsers that support anti-phishing features.

    No doubt when Apple gets around to adding these features (pity Safari's not OSS, or it could be added easily by third parties), PayPal will add them to the list.

    --
    There are shills on slashdot. Apparently, I'm one of them.
  12. Re:How good Ars Technica writers at tech and revie by Niten · · Score: 5, Insightful

    I'm very happy for you, that you've never made a single careless mistake in your life. However, please do try to have a little mercy on those of us who are merely human, especially when we're honest enough to admit it.

  13. Re:In other news... by PPH · · Score: 4, Funny

    IE is perfectly secure .... as long as you stay off the Internet.

    --
    Have gnu, will travel.
  14. Use IE? One problem... by Myrkridian42 · · Score: 4, Insightful
    There is *NO* Internet Explorer for Mac!

    Microsoft stopped making (and supporting) IE for Mac in 2003. See for yourself.

  15. Re:How good Ars Technica writers at tech and revie by Dachannien · · Score: 2, Insightful

    Step 1: Assume that any e-mail you get is a phishing attempt.
    Step 2: There's no step 2. There's no step 2!

    It's not exactly rocket science.

  16. Fish all you want... by cybereal · · Score: 5, Informative

    I bought the $5 keyfob for paypal and ebay, (plus it works on my verisign openid provider) and this phishing problem is no longer an issue for me.

    They can get my paypal username and password, but they still need the electronic key that only *I* have. I suggest anyone who actually uses paypal get one of these, they are trivial to use and paypal is selling them incredibly cheaply.

    --
    I read the script, and I think it would help my character's motivation if he was on fire. -Bender
  17. Uhm, no by Bryansix · · Score: 2, Interesting

    Honestly, I think that making sure your browser is secure is much more important then making sure your info isn't going to an incorrect site.
    This is most assuredly wrong. You see, the browser can be completely secure and if you are loging into a fake website your login will be stolen and your bank account emptied. Note that there are TWO ways to deal with this. One is anti-phishing features in browsers and the other is a stronger login mechanism like the one ING uses. ING just recently had the lowest reported incidence of ID theft of all the banks with an online presence with Bank of America being worst. The reason is that ING allows the users to KNOW that they are on the correct website through the use of a custom image of their choice. In addition the PIn keypad is randomized to prevent keyloggers from working. Paypal should implement THESE features.
    1. Re:Uhm, no by russotto · · Score: 3, Informative

      The reason is that ING allows the users to KNOW that they are on the correct website through the use of a custom image of their choice.
      Bank of America has the same system, so that fails to explain the difference in ID theft. Probably one reason is that ING Direct gets more savvy users than BoA.
  18. Re:This has huge ramifications by urcreepyneighbor · · Score: 2, Insightful

    While Opera may not have the market share of Firefox, it does run a helluva lot better than IE / Firefox / Safari on lower-end and older hardware.

    --
    "The fight for freedom has only just begun." - Geert Wilders
  19. EASILY fixed - never click on email links by grrrl · · Score: 5, Informative

    I'm with those who think this is simply avoided by NEVER clicking on a link in an email.

    Paypal will NEVER require you to click on a link in an email. All ebay functions can be accessed from my.ebay.com. My bank specifically states 'we will never send you links in an email, ALWAYS type in our website address yourself'.

    Follow that advice and you have no problems. PERIOD.

    If you think the email is legit, log into the site you type in yourself and see if there is an alert. Or ring them yourself. (On a side note I once had a credit card company ring ME and refuse to say who they were until I confirmed who I was by giving my DOB. I rang them back on the proper number and went off at them.)

    Case closed yadda yadda.

    1. Re:EASILY fixed - never click on email links by josath · · Score: 2, Informative

      I once had a credit card company ring ME and refuse to say who they were until I confirmed who I was by giving my DOB. I rang them back on the proper number and went off at them.

      Happened to me once, with a Wells Fargo credit card. Except it wasn't a person, it was a computer! (ie, voice prompts). And it wanted me to enter not my DOB, but my SSN!! At first I was sure it was a scam, that there was no way my bank would do something so stupid. But after hanging up & calling them back directly, I found out it was something they do. It's so sad how poor the security is for credit card related stuff these days in the US.
      --
      sig? uhh, umm, ok
  20. Re:In other news... by Daimanta · · Score: 3, Funny

    .....and we're not even sure about that.

    --
    Knowledge is power. Knowledge shared is power lost.
  21. Questionable Motives by sofla · · Score: 4, Insightful

    I have my doubts about this whole story. I question Barrett's motives. For the simple reason that the only way to find out that Paypal doesn't like Safari is to read the InfoWorld article and his quote. If you login to Paypal using Safari... nothing. Not a peep. No mail in your inbox, either. Seems to me that if Paypal really felt strongly about Safari they'd do a little more than that. But they don't. All we have is Barrett's quote. Which makes me wonder he's really after. And to me, the most plausible thing, is that as an EV early adopter, he's evangelizing how great EV is. Or maybe he has MSFT stock. Dunno. At any rate, if the user isn't looking at the URL bar in the first place, I don't know what difference it would make if it was green or not.

    And don't even get me started on how effective I think the whole "keep a list of the bad guys" approach is.

  22. Re:In other news... by TheSkyIsPurple · · Score: 2, Insightful

    USB storage autoruns, notices it's not on internet... install something that hooks into IE, whose core is used in basic System functions.
    Now it's snarfed your bank info from some notepad you keep.

    USB Key gets into an internet connected machine someday, its autorun notices that there's an internet connection, so it uploads what it found.

  23. Solution is simple by naasking · · Score: 3, Informative

    Just provide a Petname toolbar. All the anti-phishing you'll ever need, and it doesn't submit your URLs or browsing info to third-party servers, like the Google toolbar and Microsoft's "anti-phishing" extensions do (a technique which will ultimately prove ineffectual IMO).

  24. No ads required in Safari by Lord+Satri · · Score: 3, Informative

    Except for the missing ads - thanks to Ad Block+ I recently switched to Safari as main browser (at home, work = Firefox under Debian) for various reasons, and one of the software that made that switch enjoyable is http://safariadblock.sourceforge.net/ ... (much easier to use than PithHelmet in my opinion, and open source)
  25. A clash of the titans! by TheVelvetFlamebait · · Score: 2, Funny

    Whiney Mac Fanboy goes head to head with a Mac Fanboy who is currently whining!

    --
    You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
  26. Re:How good Ars Technica writers at tech and revie by pandrijeczko · · Score: 4, Insightful
    I've been into computers for 25-odd years, I'm Linux and Windows certified, I program in shell, Perl & C & I work as a security consultant...

    ...and 3 months ago even I fell for a Paypal phishing scam where I handed over my username, password and account details.

    Fortunately, I realised what had happened within a few minutes, immediately changed my Paypal password and cancel my bank card. I also reported the site to Paypal where it was taken down within an hour. As a result, I've not had any problems between then and now.

    Yes, it's all about attention, I agree - but it just takes a lapse in concentration to fall for one of these scams.

    Oh, and before it happened to me, I, like you, was mouthing off on Slashdot about how it could never happen to me also...

    --
    Gentoo Linux - another day, another USE flag.
  27. Paypal hasn't been Safari friendly for a while by Ingenium13 · · Score: 2, Informative

    Paypal hasn't been Safari friendly for a while. I once was using paypal "buy it now" links on a website. After a few months, I got emails from a user asking how to buy the product because there was no link. Apparently Safari doesn't show the "buy now" image because it's in a form. I guess Safari doesn't support that feature, but I would think Paypal would do something about it.