ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

PayPal steps up fight against phishing

Tim Ferguson silicon.com

Published: 14 Apr 2008 09:58 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

PayPal is stepping up its battle against phishing with new technology and by collaborating with others in the industry.

Speaking at the RSA security conference in San Francisco last week, Michael Barrett, PayPal's chief information security officer, outlined the company's strategy for dealing with the phishing problem.

As one of largest secure online payment providers, Barrett said PayPal needs to step up efforts to stamp out the phishing problem — not just to protect customers but also the internet as a whole.

He said: "We know we're always going to be an attractive target for criminals. But what I don't want is PayPal to be protected and the rest of the industry not. Phishing could be solved, there's no need for it to happen."

According to Gartner, 3.3 percent of the 124 million people who received phishing emails in 2007 were duped and lost money.

PayPal is taking a three-pronged approach to tackling phishing using education, technology and partnerships.

Barrett equated the current situation in educating consumers to the early years of the car industry when the benefits of rules of the road and safety had not been fully realised.

Read this

Feature
Corporate espionage: Not if, but when

When it comes to business-to-business theft of information, experts agree — it's best to assume it will happen to your company

Read more +

He said: "I would say we're at the same stage on the internet. I think we probably have another decade of consumer education ahead of us."

PayPal has brought in a number of tech solutions including digital email signatures — something that the company now does with 100 per cent of its outbound emails.

Currently PayPal is also focusing on an approach where ISPs block emails seemingly sent from PayPal that don't have the correct digital signature.

The company is doing this with Yahoo! since autumn last year and so far it has blocked 50 million phishing emails from reaching customer inboxes.

But Barrett said other measures are needed such as email certification.

The warning systems on browsers such as Microsoft's Internet Explorer 7 — which indicates whether sites are trustworthy — are also helping to stop people clicking through to phishing sites, Barrett added.

But he stressed that partnerships are also key in the fight against phishing. "The saying 'united we stand, divided we fall' couldn't be clearer in this area," he said.

PayPal works with owner eBay along with AOL, Google, Verisign, Yahoo! and various government bodies.

Barrett said: "The internet is a global medium and we need to be running it in a much more unified way."

Credit: PayPal wages war on phishing from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
4 out of 4 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

EXPERT C# ASP.NET DEVELOPER - STRONG OO - GOOD EDUCATION

My financial client is looking for a C# ASP.NET Developer with strong OO skills to join a prestigious, well-respected, growing company. In addition ...

Mathematical Software Engineer 1st Class education Banking - Oxford

My client is seeking a C#, C++, Delphi or Object Oriented Software Engineer with an outstanding academic background, (2:1 or above from a to 10 ...

SQL Server? PHP Experience? Good Education? Hedge Fund - 500

My Hedge Fund client is looking for an expert SQL Server Developer, with PHP development experience (commercial or non-commercial). The successful ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation