<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Should we stop faking phishing data?</title>
	<atom:link href="http://emergentchaos.com/archives/2007/07/should-we-stop-faking-phishing-data.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2007/07/should-we-stop-faking-phishing-data.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2007/07/should-we-stop-faking-phishing-data.html/comment-page-1#comment-3802</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Sat, 28 Jul 2007 21:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2438#comment-3802</guid>
		<description>My comment about expense should have said &quot;assume&quot; not &quot;presume.&quot;  What I meant is that if it costs you and a phisher the same effort to validate an account, then dumping hundreds of fake accounts into the site might be a worthwhile thing because it absorbs lots of phisher time, and may help banks identify phishing data exploitation.
Also the question of resolving (closing) the site isn&#039;t the only question.
Without any disrespect to the APWG or castlecops, I don&#039;t think they have all the data we&#039;d like to have.  For example, imagine that tomorrow, Congress asked the FBI how many agents they&#039;d need to shut down this problem.  Do we have data to tell us how big it is? How many people are involved?    I haven&#039;t seen such, and I&#039;m interested in seeing if we can get that sort of data.
</description>
		<content:encoded><![CDATA[<p>My comment about expense should have said &#8220;assume&#8221; not &#8220;presume.&#8221;  What I meant is that if it costs you and a phisher the same effort to validate an account, then dumping hundreds of fake accounts into the site might be a worthwhile thing because it absorbs lots of phisher time, and may help banks identify phishing data exploitation.<br />
Also the question of resolving (closing) the site isn&#8217;t the only question.<br />
Without any disrespect to the APWG or castlecops, I don&#8217;t think they have all the data we&#8217;d like to have.  For example, imagine that tomorrow, Congress asked the FBI how many agents they&#8217;d need to shut down this problem.  Do we have data to tell us how big it is? How many people are involved?    I haven&#8217;t seen such, and I&#8217;m interested in seeing if we can get that sort of data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JAF</title>
		<link>http://emergentchaos.com/archives/2007/07/should-we-stop-faking-phishing-data.html/comment-page-1#comment-3801</link>
		<dc:creator>JAF</dc:creator>
		<pubDate>Fri, 27 Jul 2007 14:46:05 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2438#comment-3801</guid>
		<description>Sorry for the delay .. things have been a bit hectic.
I can&#039;t tell you &#039;by the numbers&#039; how many sites are being hit with fake data of the type we&#039;re discussing.
...[ Firstly, JAF (seems to) presume that his work is roughly equivalent to the phisher&#039;s work, or more expensive ]...
Will you please explain this?
All phishing sites have a limited number of entries by those who recoginze it for what it is and fill out the requested data accordingly .. questioning the parental lineage of the scammer or other scatological commentary.
What I&#039;m addressing is the &#039;dump&#039; of hundreds of authentic-looking, but fake entries into a data file. In quantity, they&#039;re clearly recognizable. On several forums I have seen posted that this is something &#039;fun&#039; to do .. that somehow this &#039;teaches the scammer&#039; something not quite defined. It doesn&#039;t.
The &#039;wow, isn&#039;t this fun&#039; activity does nothing to resolve/remove that phishing site. Perhaps if those who consider this amusing would, instead, report the site to any number of anti-phishing groups such as:
CastleCops: &lt;a href=&quot;http://www.castlecops.com/pirt&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://www.castlecops.com/pirt&quot; rel=&quot;nofollow&quot;&gt;http://www.castlecops.com/pirt&lt;/a&gt;&lt;/a&gt;
Anti-Phishing Working Group: &lt;a href=&quot;http://apwg.org/report_phishing.html&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://apwg.org/report_phishing.html&quot; rel=&quot;nofollow&quot;&gt;http://apwg.org/report_phishing.html&lt;/a&gt;&lt;/a&gt;
..we&#039;d be able to investigate and terminate the sites in a better time frame and reduce the actual numbers of ID theft victims.
Thanks ...
&#039;JAF&#039;
</description>
		<content:encoded><![CDATA[<p>Sorry for the delay .. things have been a bit hectic.<br />
I can&#8217;t tell you &#8216;by the numbers&#8217; how many sites are being hit with fake data of the type we&#8217;re discussing.<br />
&#8230;[ Firstly, JAF (seems to) presume that his work is roughly equivalent to the phisher's work, or more expensive ]&#8230;<br />
Will you please explain this?<br />
All phishing sites have a limited number of entries by those who recoginze it for what it is and fill out the requested data accordingly .. questioning the parental lineage of the scammer or other scatological commentary.<br />
What I&#8217;m addressing is the &#8216;dump&#8217; of hundreds of authentic-looking, but fake entries into a data file. In quantity, they&#8217;re clearly recognizable. On several forums I have seen posted that this is something &#8216;fun&#8217; to do .. that somehow this &#8216;teaches the scammer&#8217; something not quite defined. It doesn&#8217;t.<br />
The &#8216;wow, isn&#8217;t this fun&#8217; activity does nothing to resolve/remove that phishing site. Perhaps if those who consider this amusing would, instead, report the site to any number of anti-phishing groups such as:<br />
CastleCops: <a href="http://www.castlecops.com/pirt" rel="nofollow"></a><a href="http://www.castlecops.com/pirt" rel="nofollow">http://www.castlecops.com/pirt</a><br />
Anti-Phishing Working Group: <a href="http://apwg.org/report_phishing.html" rel="nofollow"></a><a href="http://apwg.org/report_phishing.html" rel="nofollow">http://apwg.org/report_phishing.html</a><br />
..we&#8217;d be able to investigate and terminate the sites in a better time frame and reduce the actual numbers of ID theft victims.<br />
Thanks &#8230;<br />
&#8216;JAF&#8217;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin</title>
		<link>http://emergentchaos.com/archives/2007/07/should-we-stop-faking-phishing-data.html/comment-page-1#comment-3800</link>
		<dc:creator>Justin</dc:creator>
		<pubDate>Mon, 23 Jul 2007 13:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2438#comment-3800</guid>
		<description>Hey Adam!  I&#039;ve passed it on -- let&#039;s see if there&#039;s further comment.
</description>
		<content:encoded><![CDATA[<p>Hey Adam!  I&#8217;ve passed it on &#8212; let&#8217;s see if there&#8217;s further comment.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

