<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Phriday Phish Blogging: Randomly Flagged</title>
	<atom:link href="http://emergentchaos.com/archives/2007/04/phriday-phish-blogging-randomly-flagged.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/04/phriday-phish-blogging-randomly-flagged.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2007/04/phriday-phish-blogging-randomly-flagged.html/comment-page-1#comment-3480</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Fri, 06 Apr 2007 15:52:41 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2303#comment-3480</guid>
		<description>There is a valid use case in the governance world where random accounts are selected and probed.  Of course, if we knew this, then it would be easy to craft defences against this being abused by phishers ... the problem is that the users don&#039;t know it and aren&#039;t easily able to work it out.
</description>
		<content:encoded><![CDATA[<p>There is a valid use case in the governance world where random accounts are selected and probed.  Of course, if we knew this, then it would be easy to craft defences against this being abused by phishers &#8230; the problem is that the users don&#8217;t know it and aren&#8217;t easily able to work it out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sid</title>
		<link>http://emergentchaos.com/archives/2007/04/phriday-phish-blogging-randomly-flagged.html/comment-page-1#comment-3479</link>
		<dc:creator>Sid</dc:creator>
		<pubDate>Fri, 06 Apr 2007 10:42:33 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2303#comment-3479</guid>
		<description>It gets even worse when banks hire third-party marketing firms to manage communication with their clients!  I have seen quite a few emails from domains not my bank&#039;s, and they are legit.
It gets even better when they say &quot;click this link and fill out a short survey for a $100 credit to your account.&quot;  (Chase bank has done this.)  The URL is never at thebank.com (always the marketing firm), so it looks shady.  Here the banks are &lt;i&gt;training&lt;/i&gt; people to fall victim to phishing!
&lt;a href=&quot;http://stop-phishing.blogspot.com/2006/11/validating-phishers.html&quot; rel=&quot;nofollow&quot;&gt; Click here for another &quot;training&quot; email from a bank...&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>It gets even worse when banks hire third-party marketing firms to manage communication with their clients!  I have seen quite a few emails from domains not my bank&#8217;s, and they are legit.<br />
It gets even better when they say &#8220;click this link and fill out a short survey for a $100 credit to your account.&#8221;  (Chase bank has done this.)  The URL is never at thebank.com (always the marketing firm), so it looks shady.  Here the banks are <i>training</i> people to fall victim to phishing!<br />
<a href="http://stop-phishing.blogspot.com/2006/11/validating-phishers.html" rel="nofollow"> Click here for another &#8220;training&#8221; email from a bank&#8230;</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Mason</title>
		<link>http://emergentchaos.com/archives/2007/04/phriday-phish-blogging-randomly-flagged.html/comment-page-1#comment-3478</link>
		<dc:creator>Justin Mason</dc:creator>
		<pubDate>Fri, 06 Apr 2007 05:57:29 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2303#comment-3478</guid>
		<description>Banks _ARE_ sending URLs like that, that&#039;s the problem!  We regularly have to ditch promising phish-detection rules in SpamAssassin because they match the cruddy &quot;link-tracking&quot; URLs the banks send out.
</description>
		<content:encoded><![CDATA[<p>Banks _ARE_ sending URLs like that, that&#8217;s the problem!  We regularly have to ditch promising phish-detection rules in SpamAssassin because they match the cruddy &#8220;link-tracking&#8221; URLs the banks send out.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

