{"id":30,"date":"2006-10-25T17:13:19","date_gmt":"2006-10-25T16:13:19","guid":{"rendered":"http:\/\/www.itwriting.com\/blog\/?p=30"},"modified":"2006-10-25T17:13:19","modified_gmt":"2006-10-25T16:13:19","slug":"ie7-22-hours-to-catch-a-phish","status":"publish","type":"post","link":"https:\/\/www.itwriting.com\/blog\/30-ie7-22-hours-to-catch-a-phish.html","title":{"rendered":"IE7: 22 hours to catch a phish"},"content":{"rendered":"<p>It is now 24 hours since I <a href=\"http:\/\/www.itwriting.com\/blog\/?p=28\">received an obvious phishing email<\/a> in my inbox and reported it through both IE7 and FireFox 2.0. Two hours ago, IE7 still said, &#8220;This is not a reported phishing website&#8221;. Now&nbsp;it&#8217;s finally made it:<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.itwriting.com\/images\/ie7phishcatch.gif\"> <\/p>\n<p>If this is typical, then the IE7 phishing filter is little use. Phishing sites don&#8217;t last long,&nbsp;usually only a few days. Most victims will click that link the moment it turns up in their inbox, not a day later. Speed is of the essence. After 22 hours, most of the damage will already&nbsp;have been done.&nbsp;<\/p>\n<p>Actually, the IE7 phishing filter could be worse than useless. The message, &#8220;This is not a reported phishing website&#8221; imparts a false sense of security, making it more likely that someone will tap in their personal information.<\/p>\n<p>Checking again in Firefox, it&nbsp;now catches the phish on its downloaded-list settings, which is the default. Using the dynamic query option in Firefox caught it earlier, but even that won&#8217;t catch a brand new phish.<\/p>\n<p>Let me add that anyone clicking one of these links is ignoring plentiful advice from banks and from the media; and in this case the lack of an SSL connection is another sure-fire indication that this is a forgery. But some phishing attempts are cleverly phrased, making you think that someone has placed an order in your name, or hacked your paypal account, or damaged your eBay reputation.&nbsp;In the heat of the moment, it is easy to make mistakes.<\/p>\n<p>Conclusion: Don&#8217;t rely on phishing filters to protect you; and if you want to use the one in FireFox, turn on dynamic queries (which means sending a record of&nbsp;your browsing activity to Google). <\/p>\n<div class=\"wlWriterSmartContent\" id=\"0767317B-992E-4b12-91E0-4F059A8CECA8:4d5f185d-1ac7-4fe3-a0ab-fb8aa7fcc8c1\" contenteditable=\"false\" style=\"padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px\">Technorati tags: <a href=\"http:\/\/technorati.com\/tags\/ie7\" rel=\"tag\">ie7<\/a>, <a href=\"http:\/\/technorati.com\/tags\/firefox\" rel=\"tag\">firefox<\/a>, <a href=\"http:\/\/technorati.com\/tags\/phishing\" rel=\"tag\">phishing<\/a>, <a href=\"http:\/\/technorati.com\/tags\/security\" rel=\"tag\">security<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>It is now 24 hours since I received an obvious phishing email in my inbox and reported it through both IE7 and FireFox 2.0. Two hours ago, IE7 still said, &#8220;This is not a reported phishing website&#8221;. Now&nbsp;it&#8217;s finally made it: If this is typical, then the IE7 phishing filter is little use. Phishing sites &hellip; <a href=\"https:\/\/www.itwriting.com\/blog\/30-ie7-22-hours-to-catch-a-phish.html\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">IE7: 22 hours to catch a phish<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[44,75],"tags":[],"class_list":["post-30","post","type-post","status-publish","format-standard","hentry","category-internet","category-security"],"_links":{"self":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/30","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/comments?post=30"}],"version-history":[{"count":0,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/30\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/media?parent=30"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/categories?post=30"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/tags?post=30"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}