spf-discuss
[Top] [All Lists]

Re: Re: Achilles heel of SPF

2005-06-22 12:46:53


Frank Ellermann wrote:
Terry Fielder wrote:


Microsoft is essentially threatening banks, paypay, etc with
a Microsoft sponsored increase in phishing fraud for hotmail
customers unless they immediately publish PRA records.


Banks and PayPal won't use a From: paypal(_at_)gmx(_dot_)de, that's IMHO
a bit exaggerated.
I (Terry) never said that.



Smart users don't get phished.


That's the opposite.  Here's a nice phishing IQ test:

http://survey.mailfrontier.com/survey/quiztest.html
lang=de http://www.heise.de/newsticker/meldung/60345

No, its not a test. Its sensationalism/FUD; smart users will not even *attempt* to make a decision without looking at more detail (like hovering *all* the links to see where they *really* go, and viewing the header source to see where it *really* came from). Or am I missing some functionality of the test where I can view that?


I'm not smart enough, 8 out of 10 (2 false positives).

I am, I refused to make a decision on *any* of the potential "PASS"'s without the ability to look at more details.



what makes you think the little PRA box saying "PASS"
is going to mean anything to anyone that wasn't already
vulnerable???


If I'd get a PRA-PASS for say your GMX-address (you're
no bank) when I'm used that it's really you, then PRA is
playing with your reputation.  Social engineering isn't
limited to banks or obvious 419-jokes, it can be subtle.

Agreed.


                    Bye, Frank


-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Read the whitepaper!  http://spf.pobox.com/whitepaper.pdf
To unsubscribe, change your address, or temporarily deactivate your subscription, please go to http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com


--
Terry Fielder
terry(_at_)greatgulfhomes(_dot_)com
Associate Director Software Development and Deployment
Great Gulf Homes / Ashton Woods Homes
Fax: (416) 441-9085


<Prev in Thread] Current Thread [Next in Thread>