<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Boxbe Blog &#187; Phishing</title>
	<atom:link href="http://blog.boxbe.com/category/unwanted-email/phishing/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.boxbe.com</link>
	<description></description>
	<lastBuildDate>Tue, 29 Sep 2009 23:41:24 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Holiday coupon phishing scams</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/holiday-coupon-phishing-scams</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/holiday-coupon-phishing-scams#comments</comments>
		<pubDate>Thu, 06 Dec 2007 23:26:17 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[DKIM]]></category>
		<category><![CDATA[DomainKeys]]></category>
		<category><![CDATA[Email Tips]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[SPF]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/unwanted-email/phishing/holiday-coupon-phishing-scams</guid>
		<description><![CDATA[The Associated Press is warning email users yesterday to be wary of coupons that they have received via email.
Instead of money saving deals, e-mailed coupons could lead recipients into &#8220;phishing&#8221; schemes where the consumer is redirected to a copycat site, whose real purpose is to siphon the user&#8217;s credit card information, passwords and other financial [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/skrewtape/859179849/"><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/12/859179849-bf878c8116-m.jpg" alt="859179849_bf878c8116_m.jpg" border="0" width="240" height="95" align="right"/></a>The Associated Press is warning email users yesterday to be wary of coupons that <a href="http://www.washingtonpost.com/wp-dyn/content/article/2007/12/05/AR2007120502114.html">they have received via email</a>.</p>
<blockquote><p>Instead of money saving deals, e-mailed coupons could lead recipients into &#8220;<a href="http://blog.boxbe.com/category/phishing">phishing</a>&#8221; schemes where the consumer is redirected to a copycat site, whose real purpose is to siphon the user&#8217;s credit card information, passwords and other financial data, IBM Corp. security executive Christopher Rouland warned.
</p></blockquote>
<p>If you are a Boxbe member and have approved email from say Amazon.com, messages from a an address that claims to be from Amazon, but really aren&#8217;t,  won&#8217;t make it through to your inbox.</p>
<p>Boxbe uses two email authentication methods (<a href="http://blog.boxbe.com/category/dkim">DKIM</a> and <a href="http://blog.boxbe.com/category/spf">SPF</a>) to verify that the emailer is who they claim to be.  DKIM and SPF are two email authentication standards backed by Google, Microsoft, Yahoo!, and AOL.  Boxbe blocks messages that come from senders who claim to be someone that they are not </p>
<p>Be safe out there this holiday season and let us worry about your email.<br />
<strong><a href="http://www.washingtonpost.com/wp-dyn/content/article/2007/12/05/AR2007120502114.html">Read</a></strong></p>
<h5>image from Flickr user <a href="http://www.flickr.com/photos/skrewtape/">skrewtape</a>.</h5>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/holiday-coupon-phishing-scams/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Email news for Tuesday, October 9, 2007</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/email-news-for-tuesday-october-9-2007</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/email-news-for-tuesday-october-9-2007#comments</comments>
		<pubDate>Tue, 09 Oct 2007 23:20:40 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[Apple Mail]]></category>
		<category><![CDATA[Email apps]]></category>
		<category><![CDATA[Entourage]]></category>
		<category><![CDATA[Mail.app]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Thunderbird]]></category>
		<category><![CDATA[Unwanted Email]]></category>
		<category><![CDATA[Yahoo! Mail]]></category>
		<category><![CDATA[]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[ymail]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/unwanted-email/phishing/email-news-for-tuesday-october-9-2007</guid>
		<description><![CDATA[It&#8217;s been a while since we&#8217;ve posted any news about other places here on the blog, but that doesn&#8217;t mean we haven&#8217;t been watching.  Here&#8217;s the latest and greatest from the world of email.
Happy 10th Birthday, Yahoo! Mail
We&#8217;ve had a great time working with the team down in Sunnyvale on the new Yahoo! Mail [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/04/thunderbirdlogo.gif" alt="Thunderbird" / align="right"/>It&#8217;s been a while since we&#8217;ve posted any news about other places here on the blog, but that doesn&#8217;t mean we haven&#8217;t been watching.  Here&#8217;s the latest and greatest from the world of email.</p>
<p><strong><a href="http://yodel.yahoo.com/2007/10/08/happy-10th-birthday-yahoo-mail/">Happy 10th Birthday, Yahoo! Mail</a></strong><br />
We&#8217;ve had a great time working with the team down in Sunnyvale on the new Yahoo! Mail application and wish them the best on this momentous occasion.  Congrats!</p>
<p><strong><a href="http://www.news.com/8301-10784_3-9790822-7.html">Yahoo Mail to block fake eBay and PayPal e-mail</a></strong> &#8211; CNET News.com<br />
Good news for eBay and Paypal users, Yahoo! will be blocking spoofed emails from senders claiming to be Paypal and eBay.  We have to applaud Yahoo! for taking steps to curb these phishing emails.  </p>
<p><strong><a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9040198">Mac e-mail showdown: Which program delivers?</a> </strong> &#8211; Computerworld<br />
Looking to switch email apps on the Mac?  Or maybe coming from the PC world and wanted to know what your Mac options are?  Computerworld takes a look at Mail.app, Thunderbird and Microsoft Entourage desktop mail applications for OSX.</p>
<p><strong><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2007/10/08/BUHRSL4CF.DTL&amp;feed=rss.business">Techies take on spam zombies</a></strong>  -San Francisco Chronicle<br />
&#8220;Computer scientists in Menlo Park are releasing a free diagnostic program today to help network administrators find PCs infected with an insidious new type of virus that has already tainted millions of computers.&#8221;  Strangely, SFGate doesn&#8217;t link directly to the software page, but if you want to check it out, go to the <a href="http://www.cyber-ta.org/BotHunter/">BotHunter Free Internet Distribution Page</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/email-news-for-tuesday-october-9-2007/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dad, where does malware come from?</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/dad-where-does-malware-come-from</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/dad-where-does-malware-come-from#comments</comments>
		<pubDate>Tue, 11 Sep 2007 16:50:19 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Unwanted Email]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/unwanted-email/phishing/dad-where-does-malware-come-from</guid>
		<description><![CDATA[Ever wonder where spam, viruses and malware come from?  Apparently, it comes from the mob.
Tony Soprano, spammer?
Auckland, New Zealand based computer security expert, Peter Gutmann has an informative presentation on the subject here.  Malware, it seems, has become quite an industry and Gutmann posits that much of it is being ran by various [...]]]></description>
			<content:encoded><![CDATA[<p>Ever wonder where spam, viruses and malware come from?  Apparently, it comes from the mob.</p>
<h3>Tony Soprano, spammer?</h3>
<p>Auckland, New Zealand based computer security expert, Peter Gutmann has an informative presentation on the subject <a href="http://www.cs.auckland.ac.nz/~pgut001/pubs/malware_biz.pdf">here</a>.  Malware, it seems, has become quite an industry and Gutmann posits that much of it is being ran by various mafias around the world.</p>
<p>Organized crime recruit so-called &#8220;script kiddies&#8221; that are writing malware and viruses for fun and pay them to turn their software into money making machines.  Gutmann cites a number of internet business practices that have been employed by such as &#8220;Malware as a Service,&#8221;  making it easier than ever to spam people.</p>
<h3>A deal you can&#8217;t refuse</h3>
<p>Gutman, the self proclaimed &#8220;professional paranoid,&#8221; goes into a high level of detail of exactly how people in the malware industry make money.  </p>
<p>Here are a few examples:</p>
<ul>
<li>$1 per credit card numbers down to the verification number</li>
<li>$40 credit card, with date of birth and social security number</li>
<li>$1000 for 10,000 compromised computers.</li>
</ul>
<p>Additionally, he takes a technical deep dive into how malware authors hide what they are doing.</p>
<p>If you are an aspiring spammer or virus maker, this is must read. For everyone else, read the end of the document about how to keep yourself safe.  </p>
<p><strong><a href="http://www.cs.auckland.ac.nz/~pgut001/">Peter Gutmann</a></strong> <br />
<strong><a href="http://www.cs.auckland.ac.nz/~pgut001/pubs/malware_biz.pdf">Economics of Malware pdf</a></strong><br />
[via <a href="http://www.metafilter.com/64542/The-Economics-of-Malware">Metafilter</a>]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/dad-where-does-malware-come-from/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers and their mind games</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/spammers-and-their-mind-games</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/spammers-and-their-mind-games#comments</comments>
		<pubDate>Thu, 28 Jun 2007 23:22:11 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/unwanted-email/phishing/spammers-and-their-mind-games</guid>
		<description><![CDATA[
McAfee released an interesting report this week about the mind games that spammers play on people and as eWeek called it, why we click on these emails.
From the &#8220;Say &#8220;No Thanks&#8221; to Unwanted Email&#8221; white paper from McAfee:
&#8220;Scam spam works best by providing recipients with a sense of familiarity and legitimacy, either by creating the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/fabiovenni/389018982/"><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/06/389018982-ea85b0d835-m.jpg" border="0" height="160" width="240" alt="389018982_ea85b0d835_m.jpg" align="right" /></a></p>
<p>McAfee released an interesting report this week about the mind games that spammers play on people and as eWeek called it, <a href="http://www.eweek.com/article2/0,1759,2151568,00.asp">why we click</a> on these emails.</p>
<p>From the &#8220;Say &#8220;No Thanks&#8221; to Unwanted Email&#8221; <a href="http://www.mcafee.com/us/about/press/corporate/2007/20070625_201010_g.html">white paper</a> from McAfee:</p>
<blockquote><p>&#8220;Scam spam works best by providing recipients with a sense of familiarity and legitimacy, either by creating the illusion that the email is from a friend or colleague, or providing plausible warnings from a respected institution,&#8221; Dr. Blascovich noted. &#8220;Once the victim opens the email, criminals use two basic motivational processes, approach and avoidance, or a combination of the two, to persuade victims to click on dangerous links, provide personal information, or download risky files. By scamming $20 from just half of one percent of the U.S. population, cyber criminals can earn $15 million each day and nearly $5.5 billion in a year, a powerful attraction for skillful scam artists.&#8221;</p></blockquote>
<p>For me, I like to keep spam out of my inbox altogether and thankfully that&#8217;s what Boxbe does.  </p>
<p>The report goes on to talk about how most people are susceptible on some level to convincing spam and attacking base human emotion can fool almost all of us some of the time.  </p>
<p>Personally, I&#8217;m still waiting on all the money to come in from <a href="http://en.wikipedia.org/wiki/Advance_fee_fraud">Nigeria</a>.</p>
<h6>photo from Flickr user <a href="http://www.flickr.com/photos/fabiovenni">fabbio</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/spammers-and-their-mind-games/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Robert Soloway &#8211; canned spammer</title>
		<link>http://blog.boxbe.com/productivity/anti-spam/robert-soloway-canned-spammer</link>
		<comments>http://blog.boxbe.com/productivity/anti-spam/robert-soloway-canned-spammer#comments</comments>
		<pubDate>Thu, 31 May 2007 19:19:39 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[Anti-Spam]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Unwanted Email]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/productivity/anti-spam/robert-soloway-canned-spammer</guid>
		<description><![CDATA[This morning&#8217;s Seattle PI cover story reports that alleged spammer, Robert Soloway has been arrested under a provision of the 2003 CAN-SPAM Act.
AP Legal Affairs Writer, Gene Johnson reports that Robert Soloway is being held on &#8220;a 35-count indictment &#8230; charging him with mail fraud, wire fraud, e-mail fraud, aggravated identity theft and money laundering.&#8221;
Soloway [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/r80o/1583486/"><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/05/1583486-c6221ed17c-m.jpg" border="0" height="180" width="240" alt="1583486_c6221ed17c_m.jpg" align="right" /></a>This morning&#8217;s Seattle PI cover story <a href="http://seattlepi.nwsource.com/local/317795_soloway31.html">reports</a> that alleged spammer, <a href="http://en.wikipedia.org/wiki/Robert_Soloway">Robert Soloway</a> has been arrested under a provision of the <a href="http://en.wikipedia.org/wiki/Can_Spam_Act_of_2003">2003 CAN-SPAM Act</a>.</p>
<p>AP Legal Affairs Writer, <a href="http://news.yahoo.com/s/ap/20070531/ap_on_hi_te/spam_arrest">Gene Johnson</a> <a href="http://www.businessweek.com/ap/financialnews/D8PF8H301.htm">reports</a> that Robert Soloway is being held on &#8220;a 35-count indictment &#8230; charging him with mail fraud, wire fraud, e-mail fraud, aggravated identity theft and money laundering.&#8221;</p>
<p>Soloway has previously lost two civil lawsuits resulting in fines of seven and ten million dollars, but this is his first criminal indictment.</p>
<p>&#8220;He&#8217;s one of the top 10 spammers in the world,&#8221; said Tim Cranton, a Microsoft Corp. lawyer who is senior director of the company&#8217;s Worldwide Internet Safety Programs. &#8220;He&#8217;s a huge problem for our customers. This is a very good day.&#8221;</p>
<p>Allegedly, Robert Soloway was using so-called &#8220;Zombie&#8221; computers (or <a href="http://blog.boxbe.com/unwanted-email/spam/what-is-a-botnet">botnets</a>) to create his attacks.  Federal agents have been quoted as saying that Soloway was responsible for billions of spam emails and that we should expect a drop in spam as a result of his arrest.  </p>
<p><a href="http://www.amazon.com/Spam-Wars-Spammers-Scammers-Hackers/dp/1590790634">Spam Wars</a> author, Danny Goodman <a href="http://spamwars.com/archives/2007/05/naive_media_at.html">disagrees:</a> </p>
<blockquote><p>I don&#8217;t care how big a spammer Soloway allegedly is; his contribution to the 63 billion spam messages per day (Ironport) can&#8217;t be so big that we&#8217;ll even notice the absence. Additionally, there is no way of knowing how much of his process is automated and already in the hopper waiting to spew. Also, he was taken into custody before 8:00am PDT yesterday. Spam volume here yesterday was (alas) quite normal.
</p></blockquote>
<p>We tend to agree with Danny as we&#8217;ve seen no marked decrease in quarantined messages, but nevertheless, it&#8217;s good to see such a notorious spammer brought to justice.</p>
<h3>More discussion and commentary</h3>
<p><a href="http://it.slashdot.org/article.pl?sid=07/05/31/0332220">Slashdot</a><br />
<a href="http://news.com.com/Seattle+Spammer+arrested/2100-7348_3-6187754.html?tag=nefd.top">CNET</a><br />
<a href="http://richi.co.uk/blog/2007/05/soloway-arrested.html">Richi Jennings</a><br />
<a href="http://valleywag.com/tech/robert-soloway/is-this-the-most-hated-man-on-the-web-264850.php">Valleywag</a><br />
<a href="http://www.dvorak.org/blog/?p=11710">John C. Dvorak</a><br />
<a href="http://www.tingog.com/technology/spam-king-robert-alan-soloway-arrested.html">Tingog.com</a><br />
<a href="http://www.boingboing.net/2007/05/31/zombie_spammer_nabbe.html">Boing Boing</a><br />
<a href="http://www.downloadsquad.com/2007/05/31/feds-arrest-one-of-worlds-most-prolific-spammers/">Download Squad</a><br />
<a href="http://techdirt.com/articles/20070530/232149.shtml">TechDirt</a></p>
<h6>image by Flickr user <a href="http://www.flickr.com/photos/r80o/">r80o</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/productivity/anti-spam/robert-soloway-canned-spammer/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DKIM gets IETF approval</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/dkim-gets-ietf-approval</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/dkim-gets-ietf-approval#comments</comments>
		<pubDate>Fri, 25 May 2007 00:17:37 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[DKIM]]></category>
		<category><![CDATA[DomainKeys]]></category>
		<category><![CDATA[Junk Mail]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Standards]]></category>
		<category><![CDATA[Unwanted Email]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/unwanted-email/phishing/dkim-gets-ietf-approval</guid>
		<description><![CDATA[A few days ago, Domain Keys Identified Mail or DKIM, was approved by the Internet Engineering Task Force (IETF).  DKIM is one of the standards that we use at Boxbe to keep your email safe from phishing attacks and fake emails in general.
What is DKIM?
From Yahoo:
DKIM is an email authentication framework that addresses the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/lordcuauhtli/218948748/"><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/05/218948748-36df4c81df-m.jpg" border="0" height="180" width="240" alt="218948748_36df4c81df_m.jpg" align="right" /></a>A few days ago, <a href="http://antispam.yahoo.com/domainkeys">Domain Keys Identified Mail or DKIM</a>, was approved by the <a href="http://ietf.org/">Internet Engineering Task Force (IETF)</a>.  DKIM is one of the standards that we use at Boxbe to keep your email safe from <a href="http://blog.boxbe.com/unwanted-email/phishing/what-is-phishing">phishing</a> attacks and fake emails in general.</p>
<h3>What is DKIM?</h3>
<p>From Yahoo:</p>
<blockquote><p>DKIM is an email authentication framework that addresses the widespread issue of email forgery, using cryptography to verify the domain of the sender. It allows email providers to validate an email&rsquo;s originating domain, making use of blacklists and whitelists more effective. It also makes phishing attacks easier to detect by helping to identify abusive domains. </p></blockquote>
<p>DKIM is good for the internet and will help detect forged email addresses.  However, DKIM alone won&#8217;t stop spam originating from non-faked addresses nor will it stop other forms of unwanted email.  <a href="http://richi.co.uk/blog/2007/05/cnets-error-explaining-dkim.html">Email expert Richi Jennings says</a> &#8220;At best, they give a partial indication whether a message is spam or not, but their main use is to allow recipients to look up the reputation of the sending domain.&#8221;</p>
<p>The UK&#8217;s PC Advisor <a href="http://www.pcadvisor.co.uk/news/index.cfm?newsid=9472&amp;pn=2">says</a> &#8220;To make it work, DKIM now has to be adopted and incorporated by independent software vendors into their email applications and related infrastructures.&#8221;  </p>
<p>That said, this is a step forward in stopping phishing schemes and other illegal activities that originate from non-authenticated senders and we are happy to see the DKIM standard approved and hopefully more widely adopted.</p>
<h3>More about DKIM</h3>
<p><strong><a href="http://dkim.org/">DKIM Workgroup</a></strong><br />
<strong><a href="http://dkim.org/info/dkim-faq.html">DKIM FAQ</a></strong><br />
<strong><a href="http://yodel.yahoo.com/2007/05/22/one-small-step-for-email-one-giant-leap-for-internet-safety/">Yahoo! Anecdotal</a></strong></p>
<h3>More discussion of the standard approval</h3>
<p><a href="http://news.com.com/Promising+antispam+technique+gets+nod/2100-1029_3-6185904.html">Promising antispam technique gets nod</a> &#8211; CNET News<br />
<a href="http://arstechnica.com/news.ars/post/20070524-ietf-backs-new-cryptographic-scheme-to-battle-the-effects-of-spam.html">IETF backs new cryptographic scheme to battle the effects of spam</a> &#8211; Ars Technica<br />
<a href="http://software.silicon.com/security/0,39024655,39167246,00.htm">Junked: Is this the end of spam and spoof email?</a> &#8211; Silicon.com<br />
<a href="http://it.slashdot.org/it/07/05/24/2142206.shtml">Bye Bye Spam and Phishing with DKIM?</a> &#8211; Slashdot.org<br />
<a href="http://www.darkreading.com/document.asp?doc_id=124796&#038;WT.svl=news2_1">New Spec Could Cut Phishing, Spam</a> &#8211; Dark Reading<br />
<a href="http://www.lockergnome.com/nexus/marcerickson/2007/05/24/internet-engineering-task-force-approves-domainkeys-identified-mail-specification-dkim-to-fight-spam-and-phishing/">IETF approves DKIM to fight spam and phishing</a> &#8211; A Canadian Geek<br />
<a href="http://steveshah.blogspot.com/2007/05/why-dkim-will-fail.html">Why DKIM will fail</a> &#8211; Spin on Cue<br />
<a href="http://www.geeksaresexy.net/2007/05/23/promising-new-antispam-technique-gains-key-approval/">Promising new anti-spam techique gains key approval</a> &#8211; Geeks Are Sexy</p>
<h5>photo from Flickr user <a href="http://www.flickr.com/photos/lordcuauhtli/218948748/">lordcuauhtli</a></h5>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/dkim-gets-ietf-approval/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is phishing?</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/what-is-phishing</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/what-is-phishing#comments</comments>
		<pubDate>Fri, 16 Feb 2007 21:32:03 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[DKIM]]></category>
		<category><![CDATA[Definitions]]></category>
		<category><![CDATA[DomainKeys]]></category>
		<category><![CDATA[FAQ]]></category>
		<category><![CDATA[Junk Mail]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[SPF]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[Unwanted Email]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/news/what-is-phishing</guid>
		<description><![CDATA[In an earlier post, I mentioned a spammer who was phishing getting convicted and facing up to a 101 years in prison as a result.  But what exactly is phishing?

Photo by Flickr user thermodynamix

Wikipedia defines phishing as 
&#8220;a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords [...]]]></description>
			<content:encoded><![CDATA[<p>In an earlier <a href="http://blog.boxbe.com/news/spammer-faces-101-years-in-prison">post</a>, I mentioned a spammer who was phishing getting convicted and facing up to a 101 years in prison as a result.  But what exactly is phishing?</p>
<p><a href="http://www.flickr.com/photos/thermodynamix/29693320/"><img src="http://blog.boxbe.com/blog/wp-content/uploads/2007/02/imagesphishing.jpg" border="0" height="180" width="240" alt="phishing.jpg" align="" /></a><br />
<h6>Photo by Flickr user <a href="http://www.flickr.com/photos/thermodynamix/">thermodynamix</a></h6>
</p>
<p>Wikipedia defines <a href="http://en.wikipedia.org/wiki/Phishing">phishing</a> as </p>
<blockquote><p>&#8220;a criminal activity using social engineering techniques. Phishers attempt to fraudulently acquire sensitive information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an electronic communication. Phishing is typically carried out using email or an instant message, although phone contact has been used as well. Attempts to deal with the growing number of reported phishing incidents include legislation, user training, and technical measures.&#8221;</p></blockquote>
<p>In a nutshell, phishing is something criminals do to trick people into giving them sensitive information.  The stolen information is then used by the criminal for further illicit activities.</p>
<h3>Boxbe and phishing</h3>
<p>So, what does Boxbe do about phishing?  First, the only email that you receive when using Boxbe is from senders that you have approved, have passed a human test or have paid a fee.  Second, we use two emerging industry standards, <a href="http://en.wikipedia.org/wiki/Sender_Policy_Framework">SPF</a> and <a href="http://antispam.yahoo.com/domainkeys">DomainKeys</a> to increase the likelihood that the sender isn&#8217;t <a href="http://en.wikipedia.org/wiki/Spoofing_attack">spoofing</a> or faking their email address.<br />
<br />
Is it a 100% solution?  No. Unfortunately, we can&#8217;t guard against all forms of <a href="http://en.wikipedia.org/wiki/Pretexting">social engineering</a> or deception.  What we can do is guard against emails from entering your inbox that make false claims as to their point of origin.  The rest is up to you.</p>
<h3>Learn more about phishing</h3>
<p>We suggest that everyone educate themselves against phishing.  Here are some great places to learn more about phishing:<br />
</p>
<ul>
<li><strong><a href="http://www.microsoft.com/athome/security/email/phishing.mspx">Microsoft &#8211; Recognizing phishing scams and fraudulent emails</a></strong>
</li>
<li><strong><a href="http://www.fraud.org/tips/internet/phishing.htm">Tips from Fraud.org</a></strong></li>
<li><strong><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=_vdc-security-spoof-outside">Paypal Security Center</a></strong></li>
<li><strong><a href="http://reviews.cnet.com/4520-3000_7-6459186.html">CNET &#8211; How to avoid phishing scams</a></strong></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/what-is-phishing/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Spammer faces 101 years in prison</title>
		<link>http://blog.boxbe.com/unwanted-email/phishing/spammer-faces-101-years-in-prison</link>
		<comments>http://blog.boxbe.com/unwanted-email/phishing/spammer-faces-101-years-in-prison#comments</comments>
		<pubDate>Fri, 16 Feb 2007 21:11:50 +0000</pubDate>
		<dc:creator>Randy Stewart, Product Manager</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://blog.boxbe.com/news/spammer-faces-101-years-in-prison</guid>
		<description><![CDATA[Score one for the good guys.


photo by Flickr user assbach
Goodin, who was arrested last year, was found guilty of operating a sophisticated phishing scheme, the prosecutors said in the statement. As part of the scam, he sent e-mails posing as AOL&#8217;s billing department to trick people into giving up their credit card information, according to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Score one for the good guys.<br />
</strong></p>
<p><a href="http://news.com.com/AOL+phisher+faces+up+to+101+years+in+prison/2100-7348_3-6150592.htm"><img src="http://farm1.static.flickr.com/67/223936210_6f5aae38c5_m.jpg" border="0" height="170" width="240" alt="prison" align="" /></a></p>
<h6>photo by Flickr user <strong><a href="http://www.flickr.com/photos/assbach">assbach</a></strong><br /></h6>
<blockquote><p>Goodin, who was arrested last year, was found guilty of operating a sophisticated phishing scheme, the prosecutors said in the statement. As part of the scam, he sent e-mails posing as AOL&#8217;s billing department to trick people into giving up their credit card information, according to the statement. He then used the credit card data to make purchases, prosecutors said Tuesday.</p></blockquote>
<p>While he won&#8217;t get a 101 years for just spamming, this case is a perfect example of how spam can be tremendously harmful to people.  </p>
<p>Be careful out there.</p>
<p><strong><a href="http://news.com.com/AOL+phisher+faces+up+to+101+years+in+prison/2100-7348_3-6150592.html">Read</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.boxbe.com/unwanted-email/phishing/spammer-faces-101-years-in-prison/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
