{"id":28,"date":"2006-10-24T17:22:27","date_gmt":"2006-10-24T16:22:27","guid":{"rendered":"http:\/\/www.itwriting.com\/blog\/?p=28"},"modified":"2006-10-24T17:22:27","modified_gmt":"2006-10-24T16:22:27","slug":"firefox-20-ie7-both-fail-phishing-test","status":"publish","type":"post","link":"https:\/\/www.itwriting.com\/blog\/28-firefox-20-ie7-both-fail-phishing-test.html","title":{"rendered":"FireFox 2.0, IE7 both fail phishing test"},"content":{"rendered":"<p>I&#8217;m not in the habit of visiting these sites, but when an email apparently from Bank of America plopped into my inbox a few minutes ago, it seemed the ideal moment to test out my brand new browsers &#8211; release versions of IE7 and Firefox 2.0.<\/p>\n<p>The score is tied at zero for both browsers. Here&#8217;s the site in IE7:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.itwriting.com\/images\/ie7phishfail1.gif\"> <\/p>\n<p>Looks good, doesn&#8217;t it? No little padlock; so just to be sure I clicked Tools &#8211; Phishing filter &#8211; Check this website:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.itwriting.com\/images\/ie7phishfail2.gif\"> <\/p>\n<p>Personally I think this dialog is overly reassuring. Further, it strikes me that most sites where you suspect phishing are probably aping a site that uses SSL, so the dialog could usefully alert me to this. Never mind, let&#8217;s try Firefox 2.0:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.itwriting.com\/images\/firefoxphishfail.gif\"> <\/p>\n<p>No better, sadly. I tried both the options in the security section, including the scary one that sends all your web activity to Google, but still FireFox failed to warn me that I was about to give away precious financial secrets.<\/p>\n<p>Luckily I don&#8217;t have an account with Bank of America. Still, the lesson here is that that neither browser is magic. There&#8217;s a delay between the appearance of a phishing site, and its blacklisting. It&#8217;s the same problem with anti-virus signatures: default permit is a broken security model. You have been warned.<\/p>\n<p>Incidentally I reported the sites in both browsers. No instant change; but I&#8217;ll try the url again later.<\/p>\n<p>PS: see <a href=\"http:\/\/www.itwriting.com\/blog\/?p=29\">here<\/a> and <a href=\"http:\/\/www.itwriting.com\/blog\/?p=30\">here<\/a> to see how quickly IE7 and Firefox started detecting this fraudulent site.<\/p>\n<p><div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:0ccc538d-afd8-4259-9623-43e0b41aaf59\" contenteditable=\"false\" style=\"padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px\">Technorati tags: <a href=\"http:\/\/technorati.com\/tags\/phishing\" rel=\"tag\">phishing<\/a>, <a href=\"http:\/\/technorati.com\/tags\/internet%20explorer%207\" rel=\"tag\">internet explorer 7<\/a>, <a href=\"http:\/\/technorati.com\/tags\/ie7\" rel=\"tag\">ie7<\/a>, <a href=\"http:\/\/technorati.com\/tags\/firefox\" rel=\"tag\">firefox<\/a>, <a href=\"http:\/\/technorati.com\/tags\/security\" rel=\"tag\">security<\/a><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m not in the habit of visiting these sites, but when an email apparently from Bank of America plopped into my inbox a few minutes ago, it seemed the ideal moment to test out my brand new browsers &#8211; release versions of IE7 and Firefox 2.0. The score is tied at zero for both browsers. &hellip; <a href=\"https:\/\/www.itwriting.com\/blog\/28-firefox-20-ie7-both-fail-phishing-test.html\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">FireFox 2.0, IE7 both fail phishing test<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44,75],"tags":[],"class_list":["post-28","post","type-post","status-publish","format-standard","hentry","category-internet","category-security"],"_links":{"self":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/28","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/comments?post=28"}],"version-history":[{"count":0,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/28\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/media?parent=28"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/categories?post=28"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/tags?post=28"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}