Risk
4/30/2008
02:18 PM
Connect Directly
LinkedIn
Twitter
Google+
RSS
E-Mail
50%
50%

Google Warns Users About Phishing

In advising users to be wary of clicking on links in e-mail messages or responding to requests for personal information, Google is trying to protect its own business.

In a continuation of its series of posts on Internet security, Google on Tuesday warned its users about phishing attacks.

Google engineer Ian Fette in a blog post explains that phishing is pretty simple: "Someone masquerades as someone else in an effort to fool you into sharing personal or other sensitive information with them," he says. "Phishers can masquerade as just about anyone, including banks, e-mail and application providers, online merchants, online payment services, and even governments."

Fette acknowledges that while some phishing attacks are obvious, many are not. "That fake e-mail from 'your bank' can look very real; the bogus 'login page' you're redirected to can seem completely legitimate," he cautions.

As if to demonstrate that point, the SANS Internet Storm Center earlier this month warned that CEOs of some companies are being targeted with a phishing attack that relies on fake federal subpoenas sent via e-mail. It's an obvious attack if you understand that subpoenas aren't sent via e-mail, yet Matt Richard, director of rapid response for security firm iDefense estimated that about 1,800 executives -- about 10% of the total who received the attack -- fell for it and responded.

If business leaders, who ought to know better, get duped, what chance do less sophisticated computer users have?

Jaded Internet veterans and the paranoid may marvel that anyone clicks any links in e-mail messages or believes anything contained therein. They've already stopped trusting anything sent in an e-mail.

But Google can't afford to give up. It cannot afford to let mistrust become the norm among the masses because its business depends upon trust. If skepticism of e-mail spreads to the Web, people will stop clicking on ads and abandon the browser for applications that can deliver safer online interaction.

So it is that Google is advising its users to be wary of clicking on links in e-mail messages or responding to requests for personal information. It's Google's way of saying all is not lost.

Fette suggests that when presented with a URL in an e-mail, users should type it into the browser address bar or select it from the bookmark, if bookmarked already. Sound advice, to be sure, but it's dangerously close to admitting that e-mail just can't be trusted.

It is in Fette's penultimate recommendation -- "Be wary of the 'fabulous offers' and 'fantastic prizes' that you'll sometimes come across on the Web" -- that the challenge Google faces becomes apparent. Google isn't so much warning users about phishing attacks as it is warning users about themselves.

"If something seems too good to be true, it probably is...," explains Fette in a well-meaning attempt to save people from human nature. He's alluding to the promises of riches that phishers use to bait their messages, but his words apply to the Google-powered Internet economy. Advertising may pick up the tab for the free lunch of Internet services available at Google and elsewhere. Just make sure to add the cost of security to the bill.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0993
Published: 2014-09-15
Buffer overflow in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarcadero Delphi XE6 20.0.15596.9843 and C++ Builder XE6 20.0.15596.9843 allows remote attackers to execute arbitrary code via a crafted BMP file.

CVE-2014-2375
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, and obtain sensitive information or cause a denial of service (disk consumption), via the CSV export feature.

CVE-2014-2376
Published: 2014-09-15
SQL injection vulnerability in Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2377
Published: 2014-09-15
Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.

CVE-2014-3077
Published: 2014-09-15
IBM SONAS and System Storage Storwize V7000 Unified (aka V7000U) 1.3.x and 1.4.x before 1.4.3.4 store the chkauth password in the audit log, which allows local users to obtain sensitive information by reading this log file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
CISO Insider: An Interview with James Christiansen, Vice President, Information Risk Management, Office of the CISO, Accuvant