Welcome | Sign In
ECommerceTimes.com
Internet Fraud

Web Heavies Form Blockade Against Phishers

Print Version
E-Mail Article
Reprints
Web Heavies Form Blockade Against Phishers

Yahoo, eBay and PayPal are working together to deploy a tool designed to shield their users from vicious phishing scams. The new e-mail authentication technology developed by Yahoo allows e-mail providers to validate an e-mail's originating domain and makes blacklists and whitelists more effective.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Yahoo (Nasdaq: YHOO), eBay (Nasdaq: EBAY) and PayPal are teaming up to improve protections against phishing attacks, the companies announced Thursday.

The companies have adopted a new e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse authentication technology, developed by Yahoo and known as "DomainKeys Identified Mail" (DKIM), that uses cryptography to verify the domain of the sender.

By allowing e-mail providers to validate an e-mail's originating domain -- ensuring that an e-mail apparently from PayPal really is from PayPal, for instance -- the technology makes blacklists and whitelists more effective. It also makes phishing attacks easier to detect by helping to identify abusive domains, the companies said.

"eBay and PayPal's adoption of e-mail authentication technology and this aggressive move on the part of Yahoo Mail are significant steps forward in the fight to protect consumers against e-mail-based crimes," said Michael Barrett, chief information security officer at PayPal. "While there is clearly no silver bullet for solving the problems of phishing and identity theft, today's announcement is great news for our customers who rely on Yahoo Mail."

Reduced Risk

DKIM, which the Internet Engineering Task Force approved in May as a proposed Internet standard, allows Internet service providers (ISPs) determine if messages are genuine and whether they should be delivered to a customer's in-box. As a result of the technology, eBay and PayPal customers using Yahoo Mail will begin receiving fewer fake e-mails claiming to be sent by eBay and PayPal, the companies said, reducing their risk of falling for phishing attacks.

Yahoo Mail is the first Web mail service to block these types of malicious messages for eBay and PayPal, they added. Yahoo will roll out the upgrade globally over the next several weeks to all Yahoo Mail users.

"By reducing the risk of phishing scams, Yahoo Mail now offers a much safer Web mail service for eBay and PayPal users, and this protection will benefit the larger Yahoo Mail community as well," said John Kremer, vice president of Yahoo Mail.

Yahoo, eBay and PayPal are in the process of transitioning to DKIM, and expect to complete their implementation in the coming months, they said.

The More, the Better

"Today is a significant milestone for the added protection of millions of eBay and PayPal customers," said Dave Cullinane, chief information security officer at eBay. "Through industry cooperation, we can collectively try to stamp out phishing and other e-mail scams. We welcome Yahoo's commitment to this endeavor, applaud its leadership role within the Internet service provider community, and encourage others join in the fight to keep consumers safe from phishing attacks."

The fight against phishing and online fraud is a difficult one, but Yahoo, eBay and PayPal "have all been very good corporate citizens when it comes to protecting consumers," cybersecurity expert and lawyer Parry Aftab told the E-Commerce Times.

"They've all been working on phishing issues for a long time," Aftab said. "There's so much PayPal phishing and fraud, this is a great idea. Anything that any of these sites can do to step up security is wonderful -- I'm thrilled they're doing more."

A Few Big Users

The DKIM technology is a good system, Johannes Ullrich, chief technology officer at the SANS Institute, told the E-Commerce Times. Using domain keys assigned by the Domain Name System (DNS), the technology helps verify users cryptographically, he said.

Among the technology's downsides are that it can be difficult to implement, and also that verification can be hard to achieve for e-mails sent by employees through their home ISPs, Ullrich said. In addition, "right now, no one is really checking for domain keys yet," he explained.

That may change with the newly announced partnership, however. "It's a solid system," Ullrich said. "It needed some big users like Yahoo and PayPal to sign up for it."


Print Version E-Mail Article Reprints More by Katherine Noyes


More by Katherine Noyes

Does Wine Make Linux Too Loose?
November 05, 2009
For those Wine aficionados out there, beware of the remote possibility that your Linux system could be infected by Windows-seeking malware. "WINE running a Windows virus is nothing more than a 'stupid Linux trick' ... for now," said Slashdot blogger hairyfeet. But if the year of the Linux desktop ever arrives, he wonders, can Linux hold up to a "tidal wave of stupidity"?
PayPal Gets Friendly With Developers
November 04, 2009
PayPal is aiming to remove some of the obstacles to wider use of its service by giving developers the tools they need to embed its functionality directly in applications. That means a user could make a purchase without leaving a mobile game, for example. "The network is the platform on which the potential of digital money will be fully realized," said PayPal President Scott Thompson.
Firefox 3.6 Tweaks Are Mostly Under the Hood
November 03, 2009
For users, Mozilla's new Firefox 3.6 beta includes personas -- a new feature for changing Firefox skins -- and it sends alerts when it encounters out-of-date plug-ins. Developers may be more interested in some of the more subtle changes, however -- e.g., support for new CSS, DOM and HTML5 Web technologies, as well as support for image rendering and multiple background images.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network