Phishing -- Be careful

| No Comments | No TrackBacks
Many, perhaps most, computer security breaches occur not because software is out of date or because hackers have discovered some obscure backdoor in the most recent version but because the person sitting at the keyboard fall victim to some clever social engineering.

You get an e-mail from your IT department that tells you their doing maintenance on the e-mail server and they need you to logon to the system to re-verify your credentials. You click on the handy link, see your familiar logon screen, and enter your credentials. Only later do you realize that the site to which you gave your credentials wasn't run by your IT department at all. Someone, quite possibly a criminal, now has your credential, and you have to hope you can get them changed before the criminal has a chance to use them.

Sound farfetched? Think you'd never fall for such a scam? Meet Brad DeLong, professor of economics at UC Berkeley and deputy assistant secretary of the U.S. Treasury during the Clinton administration. The scenario I described is roughly what happened to him, as he describes in a blog post entitled "Phishers 1, DeLong 0."

You have been warned!


No TrackBacks

TrackBack URL: http://darwin.eeb.uconn.edu/cgi-bin/mt/mt-tb.cgi/946

Leave a comment

 Subscribe in a reader

Pages

OpenID accepted here Learn more about OpenID

Technorati

Technorati search

» Blogs that link here

Nature Blog Network
Creative Commons License
This blog is licensed under a Creative Commons License.

About this Entry

This page contains a single entry by Kent published on June 9, 2012 6:00 AM.

Today in DC was the previous entry in this blog.

Password compromised is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Trending content