Phishing Is a Minimum-Wage Job
rohitm918 writes "A study by Microsoft Research concludes that phishers make very little (PDF): '...low-skill jobs pay like low-skill jobs, whether the activity is legal or not.' They also find that the Gartner numbers that everyone quotes ($3.2B/year etc) are rubbish, off by a factor of 50. 'Even though it harvests "free money," phishing generates total revenue equal to the total costs incurred by the actors. Each participant earns, on average, only as much as he would have made in the opportunities he gave up elsewhere. As the total phishing effort increases the total phishing revenue declines: the harder individual phishers try the worse their collective situation gets. As a consequence, increasing effort is a sign of failure rather than of success.'"
I always wondered what the remaining 5% of computer science majors did, who didn't end up working minimum wage jobs at McBurger Queen...
Everyone knows that if you overphish a stream, there's no phish left for everyone else. Its a classic case of resource depletion!
You have the choice:
1. earn minimum wage at McDonalds
2. earn less than minimum wage selling drugs
Which do you choose? Selling drugs of course. Why? Cause you've got respect for yourself and refuse to work a demeaning job.
Before you object, whether or not you agree that working at McDonalds is demeaning is irrelevant. Many, many, many women have been given the choice:
1. work as a stripper
2. work as a waitress
and decided that working as a waitress is less demeaning than working as a stripper. You may disagree with that, also but that's also irrelevant. The facts are that you can make a lot more money working as a stripper than as a waitress, and yet so many people choose not to.
The economically rational human is a myth.
How we know is more important than what we know.
If you read the article (which no-one ever does, but just in case you get modded insightful by a mod who didn't either), you'll see that minimum wage is a relative term.
The pool of phishing money is (more or less) static, so when more people start phishing (which happens as it becomes easier), the available money per phisher goes down until its not worth it. If this is less then the minimum wage, then people wouldn't do it, if its more, then more people do it. Hence it stabilizes around that mark. This is also one of the reasons why there are more phishers in poorer nations.