Re: [Full-disclosure] Are consumers being misled by "phishing"?



n3td3v wrote:
I believe the industry coined up "phishing" to make more money out of
social engineering. Its obvious now that both are over lapping. Only
the other day Gadi Evron was trying to coin up a phrase for "voice
phishing". Why can't we cut to the chase and drop the (ph)rases and
call it straight forward SOCIAL ENGINEERING.
n3td3v, Phishing, in my opinion, is a form of social engineering.

What I would like to refer to as phishing has as main characteristic that is is usually not targeted or targeted at a group (e.g. a bunch of yahoo users). Like spam (another form of social engineering?) phishing relies on volume to work. It relies on the fact that there is a sucker born every minute and it you ask enough people you will encounter the sucker. The social engineering that has a higher risk profile for me (and the job I have to do) is more targeted and less opportunistic in nature. It is a targeted attack against layer 8 of the OSI model, the human.

Phishing also has the nasty property that it exposes an organization to a risk that is outside the scope of the organization (the customers). The only thing that really helps is to educate the user. Social engineering against employees (like against the Yahoo helpdesk) can also be solved by training elements under your own control (one hopes).

Anyway my 2 cents for what they are worth.

Schanulleke

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: [Full-disclosure] Are consumers being misled by "phishing"?
    ... > call it straight forward SOCIAL ENGINEERING. ... phishing phrase hadn't been coined, a lot of people wouldn't be ... people making voice-based social engineering attacks. ... theres a new threat, a new attack vector, when in fact their isn't. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Are consumers being misled by "phishing"?
    ... Most security researchers dont even bother looking for it. ... call it straight forward SOCIAL ENGINEERING. ... I guess when the annual revenuw from phishing for the mafia gets to 2 ... people making voice-based social engineering attacks. ...
    (Full-Disclosure)
  • [Full-disclosure] Are consumers being misled by "phishing"?
    ... I believe the industry coined up "phishing" to make more money out of ... call it straight forward SOCIAL ENGINEERING. ... When Yahoo had "paydirect" (an online bank in partnership with HSBC, ... partial Yahoo account info in exchange for a new password. ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Are consumers being misled by "phishing"?
    ... (just responding to the subject line. ... phishing phrase hadn't been coined, a lot of people wouldn't be ... Okay, maybe there are a couple I missed, attack me on that. ... corporate guy will extract another technique from SOCIAL ENGINEERING, ...
    (Full-Disclosure)
  • Re: [Full-disclosure] Are consumers being misled by "phishing"?
    ... Because it is not only social engineering. ... Does phishing have to satisfy both conditions in the definition, ... When Yahoo had "paydirect" (an online bank in partnership with HSBC, ... partial Yahoo account info in exchange for a new password. ...
    (Full-Disclosure)