<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Don&#8217;t Use Email Like a Stupid Person</title>
	<atom:link href="http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Emergent Chaos</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1105</link>
		<dc:creator>Emergent Chaos</dc:creator>
		<pubDate>Thu, 25 Aug 2005 17:55:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1105</guid>
		<description>&lt;strong&gt;&quot;Preserving the Internet Channel Against Phishers&quot;&lt;/strong&gt;

I&#039;ve updated the concepts first presented in &quot;Don&#039;t Use Email Like a Stupid Person&quot; and &quot;More on Using Email Like A Stupid Person,&quot; to make them more palatable to readers. The new short essay is &quot;Preserving the Internet Channel...
</description>
		<content:encoded><![CDATA[<p><strong>&#8220;Preserving the Internet Channel Against Phishers&#8221;</strong></p>
<p>I&#8217;ve updated the concepts first presented in &#8220;Don&#8217;t Use Email Like a Stupid Person&#8221; and &#8220;More on Using Email Like A Stupid Person,&#8221; to make them more palatable to readers. The new short essay is &#8220;Preserving the Internet Channel&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jhlipton</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1104</link>
		<dc:creator>jhlipton</dc:creator>
		<pubDate>Fri, 19 Aug 2005 20:04:32 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1104</guid>
		<description>&lt;i&gt;If my bank sends me a url to go to I ignore it and go to the secure URL I know. The same with email from my ISP, I go to their site and send a copy of the eMail. I assume that anyone asking me for confidential information is phishing.&lt;/i&gt;
Duh, yeah. That goes for &lt;b&gt;all&lt;/b&gt; my accounts. If I get a mail from XYZ, I&#039;ll navigate to XYZ&#039;s home site, login, and track the message from there.
I like getting reminders and receipts in my mail. Doesn&#039;t mean I have to clicky-click on &lt;b&gt;any&lt;/b&gt; of them!
</description>
		<content:encoded><![CDATA[<p><i>If my bank sends me a url to go to I ignore it and go to the secure URL I know. The same with email from my ISP, I go to their site and send a copy of the eMail. I assume that anyone asking me for confidential information is phishing.</i><br />
Duh, yeah. That goes for <b>all</b> my accounts. If I get a mail from XYZ, I&#8217;ll navigate to XYZ&#8217;s home site, login, and track the message from there.<br />
I like getting reminders and receipts in my mail. Doesn&#8217;t mean I have to clicky-click on <b>any</b> of them!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1103</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Tue, 16 Aug 2005 07:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1103</guid>
		<description>You are right about the arms race, but the suggestions are only the beginning.  The phishing thing is now institutionalised, and it is beyond the ability of bank sites to solve it.  That&#039;s been the case for about 1-2 years now.
Which isn&#039;t to say that those things on the list shouldn&#039;t be done, but it&#039;s fighting last year&#039;s war.
</description>
		<content:encoded><![CDATA[<p>You are right about the arms race, but the suggestions are only the beginning.  The phishing thing is now institutionalised, and it is beyond the ability of bank sites to solve it.  That&#8217;s been the case for about 1-2 years now.<br />
Which isn&#8217;t to say that those things on the list shouldn&#8217;t be done, but it&#8217;s fighting last year&#8217;s war.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eleanor</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1102</link>
		<dc:creator>Eleanor</dc:creator>
		<pubDate>Sun, 14 Aug 2005 08:01:11 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1102</guid>
		<description>My bank doesn&#039;t know my email address.  They asked for it, but I refused to give it to them because they didn&#039;t need it - they would have sent me my passcode etc. by snail mail anyway.  That way, I know that every email I get from them is spam.
</description>
		<content:encoded><![CDATA[<p>My bank doesn&#8217;t know my email address.  They asked for it, but I refused to give it to them because they didn&#8217;t need it &#8211; they would have sent me my passcode etc. by snail mail anyway.  That way, I know that every email I get from them is spam.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Extra</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1101</link>
		<dc:creator>Extra</dc:creator>
		<pubDate>Sat, 13 Aug 2005 17:34:45 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1101</guid>
		<description>The simplest security is to never respond to a URL in eMail.
If my bank sends me a url to go to I ignore it and go to the secure URL I know.  The same with email from my ISP, I go to their site and send a copy of the eMail. I assume that anyone asking me for confidential information is phishing.
</description>
		<content:encoded><![CDATA[<p>The simplest security is to never respond to a URL in eMail.<br />
If my bank sends me a url to go to I ignore it and go to the secure URL I know.  The same with email from my ISP, I go to their site and send a copy of the eMail. I assume that anyone asking me for confidential information is phishing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clifton Royston</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1100</link>
		<dc:creator>Clifton Royston</dc:creator>
		<pubDate>Fri, 12 Aug 2005 22:39:09 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1100</guid>
		<description>Sorry, whoever told you Schwab is doing that is just plain wrong.  I just reviewed my June email bulletin from them.
1) It is in HTML.  2) It contains numerous direct links to the Schwab website.  It teeters on the edge of violating 3) in that all the links are of the form &lt;a href=&quot;http://q1.schwab.com/s/r?l=[suppressed]&amp;m=[suppressed].&quot; rel=&quot;nofollow&quot;&gt;http://q1.schwab.com/s/r?l=[suppressed]&amp;m=[suppressed].&lt;/a&gt; I suspect the q1 is delegated to Quris which is the mailer they outsource to.  If you expect the average user to recognize that, for instance, q1.schwab.com (or www.hostedapp.bigbank.com) is legitimate but that www.schwab.com.secure-users.com is not, I think you are expecting vastly too much sophistication from them.  I am already seeing some phishes using the latter style of URL.
A broader problem is that this solution will work only to the extent that most users understand the difference between ASCII mail and HTML mail and can clearly distinguish between them - this will probably only be achieved if tens or hundreds of millions of users stop using Outlook Express.  Then there&#039;s the difficulty of simply convincing management at thousands of banks to listen to security authorities and ignore their marketing departments (who want to use HTML).  Your proposal would greatly help - but it requires big changes in institutional and individual behavior.  That&#039;s not easy.
</description>
		<content:encoded><![CDATA[<p>Sorry, whoever told you Schwab is doing that is just plain wrong.  I just reviewed my June email bulletin from them.<br />
1) It is in HTML.  2) It contains numerous direct links to the Schwab website.  It teeters on the edge of violating 3) in that all the links are of the form <a href="http://q1.schwab.com/s/r?l=[suppressed]&#038;m=[suppressed]." rel="nofollow">http://q1.schwab.com/s/r?l=suppressed&#038;m=suppressed.</a> I suspect the q1 is delegated to Quris which is the mailer they outsource to.  If you expect the average user to recognize that, for instance, q1.schwab.com (or <a href="http://www.hostedapp.bigbank.com" rel="nofollow">http://www.hostedapp.bigbank.com</a>) is legitimate but that <a href="http://www.schwab.com.secure-users.com" rel="nofollow">http://www.schwab.com.secure-users.com</a> is not, I think you are expecting vastly too much sophistication from them.  I am already seeing some phishes using the latter style of URL.<br />
A broader problem is that this solution will work only to the extent that most users understand the difference between ASCII mail and HTML mail and can clearly distinguish between them &#8211; this will probably only be achieved if tens or hundreds of millions of users stop using Outlook Express.  Then there&#8217;s the difficulty of simply convincing management at thousands of banks to listen to security authorities and ignore their marketing departments (who want to use HTML).  Your proposal would greatly help &#8211; but it requires big changes in institutional and individual behavior.  That&#8217;s not easy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jamie Flournoy</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1099</link>
		<dc:creator>Jamie Flournoy</dc:creator>
		<pubDate>Fri, 12 Aug 2005 21:21:56 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1099</guid>
		<description>&gt;We couldn&#039;t do that if we had to have the software in their domain withough having
&gt;to do production moves on their web servers
On the internet, a &quot;domain&quot; doesn&#039;t mean a server or hosting facility. &quot;Domain&quot; means &quot;domain name&quot;, as in the thing in the browser location bar, which is mapped to one or more IP addresses. The address is what&#039;s tied to a server and/or physical hosting facility.
Get the bank to set up a subdomain for you, like hostedappco.bigbank.com. That can be served by a separate name server you control, and has nothing at all to do with making you deploy your apps on their web servers. Then you can set www.hostedappco.bigbank.com to point at whatever server you like.
Alternatively they could just point www.hostedapp.bigbank.com at your server&#039;s IP address, which takes flexibility away from you (you can&#039;t change your IP without co-ordinating the name change with them) but gives them a sense of security.
</description>
		<content:encoded><![CDATA[<p>>We couldn&#8217;t do that if we had to have the software in their domain withough having<br />
>to do production moves on their web servers<br />
On the internet, a &#8220;domain&#8221; doesn&#8217;t mean a server or hosting facility. &#8220;Domain&#8221; means &#8220;domain name&#8221;, as in the thing in the browser location bar, which is mapped to one or more IP addresses. The address is what&#8217;s tied to a server and/or physical hosting facility.<br />
Get the bank to set up a subdomain for you, like hostedappco.bigbank.com. That can be served by a separate name server you control, and has nothing at all to do with making you deploy your apps on their web servers. Then you can set <a href="http://www.hostedappco.bigbank.com" rel="nofollow">http://www.hostedappco.bigbank.com</a> to point at whatever server you like.<br />
Alternatively they could just point <a href="http://www.hostedapp.bigbank.com" rel="nofollow">http://www.hostedapp.bigbank.com</a> at your server&#8217;s IP address, which takes flexibility away from you (you can&#8217;t change your IP without co-ordinating the name change with them) but gives them a sense of security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mario contestabile</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1098</link>
		<dc:creator>mario contestabile</dc:creator>
		<pubDate>Fri, 12 Aug 2005 16:23:29 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1098</guid>
		<description>Hi Adam.
On the subject of phishing, I am currently examining adding this as a new service in upcoming versions of our security suite software.
You may know that:
- IE 7 includes anti-phishing
- MS has chosen a partner I&#039;ve reviewed, Whole Security in Austin(http://www.wholesecurity.com/news/index.html)
Of course, our solution will be browser independent due to my http proxy.
By the way, I do have an RSS feed ;-)
&lt;a href=&quot;http://bubbler.net/feeds/560399/notes.xml&quot; rel=&quot;nofollow&quot;&gt;http://bubbler.net/feeds/560399/notes.xml&lt;/a&gt;
talk soon
</description>
		<content:encoded><![CDATA[<p>Hi Adam.<br />
On the subject of phishing, I am currently examining adding this as a new service in upcoming versions of our security suite software.<br />
You may know that:<br />
- IE 7 includes anti-phishing<br />
- MS has chosen a partner I&#8217;ve reviewed, Whole Security in Austin(http://www.wholesecurity.com/news/index.html)<br />
Of course, our solution will be browser independent due to my http proxy.<br />
By the way, I do have an RSS feed ;-)<br />
<a href="http://bubbler.net/feeds/560399/notes.xml" rel="nofollow">http://bubbler.net/feeds/560399/notes.xml</a><br />
talk soon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hervey smoots</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1097</link>
		<dc:creator>hervey smoots</dc:creator>
		<pubDate>Fri, 12 Aug 2005 15:14:06 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1097</guid>
		<description>Unfortunately, the &quot;don&#039;t put your banking software anywhere but on your server&quot; thing might not work--I work for a company that makes this kind of software, and we (and many of our competitors) host the banking sites ourselves. We couldn&#039;t do that if we had to have the software in their domain withough having to do production moves on their web servers--not something that&#039;s terribly acceptable to the banks for security reasons, understandably enough.
</description>
		<content:encoded><![CDATA[<p>Unfortunately, the &#8220;don&#8217;t put your banking software anywhere but on your server&#8221; thing might not work&#8211;I work for a company that makes this kind of software, and we (and many of our competitors) host the banking sites ourselves. We couldn&#8217;t do that if we had to have the software in their domain withough having to do production moves on their web servers&#8211;not something that&#8217;s terribly acceptable to the banks for security reasons, understandably enough.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Seth Gordon</title>
		<link>http://emergentchaos.com/archives/2005/08/dont-use-email-like-a-stupid-person.html/comment-page-1#comment-1096</link>
		<dc:creator>Seth Gordon</dc:creator>
		<pubDate>Fri, 12 Aug 2005 09:22:10 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=953#comment-1096</guid>
		<description>Bankruptcy is too kind a fate for UAL.  Their board of directors should be lined up before a firing squad on the tarmac of Denver International Airport.
</description>
		<content:encoded><![CDATA[<p>Bankruptcy is too kind a fate for UAL.  Their board of directors should be lined up before a firing squad on the tarmac of Denver International Airport.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

