spf-discuss
[Top] [All Lists]

Re: Achilles heel of SPF

2005-06-22 12:29:32
Terry Fielder wrote:

Microsoft is essentially threatening banks, paypay, etc with
a Microsoft sponsored increase in phishing fraud for hotmail
customers unless they immediately publish PRA records.

Banks and PayPal won't use a From: paypal(_at_)gmx(_dot_)de, that's IMHO
a bit exaggerated.

Smart users don't get phished.

That's the opposite.  Here's a nice phishing IQ test:

http://survey.mailfrontier.com/survey/quiztest.html
lang=de http://www.heise.de/newsticker/meldung/60345

I'm not smart enough, 8 out of 10 (2 false positives).

what makes you think the little PRA box saying "PASS"
is going to mean anything to anyone that wasn't already
vulnerable???

If I'd get a PRA-PASS for say your GMX-address (you're
no bank) when I'm used that it's really you, then PRA is
playing with your reputation.  Social engineering isn't
limited to banks or obvious 419-jokes, it can be subtle.

                    Bye, Frank



<Prev in Thread] Current Thread [Next in Thread>