Showing posts with label email. Show all posts
Showing posts with label email. Show all posts
Monday, January 30, 2012

Google joins Facebook and Microsoft to fight Phishing

0 comments
Microsoft+Google+Facebook fights Phishing

On Monday, Google, Facebook, Microsoft, Yahoo!, and eleven others outfits announced they had formed a new alliance to combat phishing — a way of fooling email and web users into providing sensitive information, including credit card numbers. The alliance is known as Domain-based Message Authentication, Reporting and Conformance, DMARC for short, and the aim of this sprawling alliance is to lay down new email standards that help stop the nefarious practice.

“One of the worst experiences for a user is being phished,” Adam Dawes, a Google product manager and DMARC representative, tells Wired. “The best way to protect them is to make sure the email never reaches the spam folder at all.”

Phishing is a relatively simple trick. Often, the spammer spoofs the data in the email message so it really looks like it came from a legitimate sender. There’s usually a way to figure out where the message really came from, but it can be hard for the average Joe to spot.

Today, as Dawes points out, phishing messages are often caught by an email client’s spam filters. But even as they check out their spam folders, many users can’t help but open on a message than says its from PayPal. Before they know it, someone has phished their credit card number. With DMARC, the idea is to get the email companies working behind the scenes to prevent phishing emails from ever hitting your inbox or spam folder.
About eighteen months ago, PayPal began working directly with Google and Yahoo to set standards for Gmail and Yahoo! Mail that would prevent fake PayPal messages from hitting a user’s inbox. According to Brett McDowell, one of PayPal’s security managers and now chairman of DMARC, the three companies were blocking over 200,000 fake PayPal messages each day.
Eventually, PayPal, Google, and Yahoo! started asking other outfits to get involved. Behind the scenes, new names began using what would become the DMARC protocols, and as more and more companies used the protocols, engineers noticed new flaws — and fixed them. Mike Adkins, a Facebook messaging engineer, says that Monday’s news isn’t a “Coming soon” announcement. “You’ve been protected by DMARC for a while,” he says.
The DMARC protocols are based on existing technologies, including the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). Both are common mail security protocols. SPF verifies the IP address of the email’s sender, while DKIM vets the structure of the email’s content, comparing it to encoded information coming from the sender.
DMARC is hardly the only cross-industry effort to battle phishing. A global non-profit called The Anti-Phishing Working Group encourages businesses to share the latest information about phishing tactics and techniques. Paul Ferguson, a senior threat researcher at anti-virus developer Trend Micro, tells Wired he supports any collaboration that fight malicious software and phishing — up to a point. “The only caution that I would have is that there are too many of these kinds of these of efforts, they start working against each other,” he says. Even inside a single company, he continues, you might have the marketing department backing one anti-phishing group, while the research department backs another.
PayPal’s McDowell reiterates that the goal of DMARC — at least for the moment — is to defend legitimate domains, not to address what’s sometimes called “typo-phishing,” where scammers use something that looks like a common domain but is actually a slightly different spelling.
“Domain-based phishing cannot happen when both parties deploy DMARC,” he says.

Other companies involved in the group include American Greetings Corp, LinkedIn Corp and Yahoo as well as privately held Agari, Cloudmark, eCert, Return Path and the Trusted Domain Project.

IDC security analyst Michael Versace said that the approach recommended by the group appeared to be effective and inexpensive to implement.

Yet he said that the industry should keep developing new technologies to fight spammers because he expects that cyber criminals will eventually figure out how to circumvent the DMARC protections.
Continue reading →
Thursday, December 29, 2011

India ranks top in source of spam in 3rd quarter of 2011 with 14.8 percentage

0 comments
More than 50 per cent of all spam messages in the world during the third quarter of 2011 originated from just six countries, with India accounting for the highest 14.8 percent of such messages.

According to Kaspersky Lab's spam report, India was ahead of countries like Indonesia (10.6 per cent), Brazil (9.65 per cent), Peru (6.65 per cent), South Korea (5.85 per cent) and Ukraine (3.7 per cent).

All of the countries that make up the top 10 sources of spam are situated in South America, Asia and Eastern Europe, the report said.

"This is due to the fact that there are numerous users in these countries and they are, for the most part, not very experienced when it comes to IT security. This makes them a soft target for cybercriminals spreading spam-bots," it said.

The report said that all GCC countries together accounted for only 1.33 per cent of all global spam, with Saudi Arabia leading the pack. This was attributed to the low number of users and more vigilance in protecting computers in these countries.

GCC countries are Bahrain, Kuwait, Oman, Qatar, Saudi Arabia, and United Arab Emirates.
Continue reading →
Sunday, December 11, 2011

Microsoft's Hoax email Spamming- The Power of email Network

0 comments
Recently, 

Many Professionals and Students in India reported that they've got a mail which includes this image and titled -  

Read and forward it.( From Micosoft Bill Gates) No harm in trying

 
Some believe its somewhat true and forwards it to all since it is claimed to have come from Billgates. But it's not the case.

Report analysis :

1. Tentative Sender Name : Melquir Sagyarajan - Wikipedia Profile Link - Guessed from the Image

2. He is not from Microsoft. He is a Web Professional Consultant. 

3. Since he is a web professional,  This seems it is some SEO / Fame Gaining technique.

4. Blog post about this in December 2009. - This shows its too old.

From these reports, we can summarize it is a planned spamming using email Network Chain.

Probable Consequences: 

1. Email id tracking for Spamming and Selling.

2. IP tracking.

3. SEO .

4. Malware installation.

Please don't forward these kind of emails to anyone and Try to report us. We'll expose it to the world.

Break the chain!!!

Continue reading →
Tuesday, November 29, 2011

French IT Company to ban emails in office

0 comments

Atos, one of biggest information technology companies in the world with over 80,000 workers in 42 countries, will soon ban e-mails because it says 90 percent of them are a waste of time.

Atos, headquartered in France, said too many employees waste time dealing with irrelevant e-mails, according to the Daily Mail.

The company would phase out e-mailing within 18 months, and said it wants people to spend more time talking to each other -- either on the phone or in person.

Atos's 56-year-old chief executive officer Thierry Breton said: "It is not right that some of our fellow employees spend hours in the evening dealing with their e-mails."

Breton said only 20 out of every 200 e-mails received by his staff every day turn out to be important.

"The e-mail is no longer the appropriate tool. It is time to think differently," he said.

He said the main problem was people switching to a "useless" e-mail while they were carrying out a far more important task.

Breton said a real-time messaging interface like that available on Facebook would be preferable to e-mail.
Continue reading →

Followers

Aco

Related Posts Plugin for WordPress, Blogger...