Is My Credit Card Stolen? (A ruse to educate people about phishing)
ismycreditcardstolen.com
Is My Credit Card Stolen? (A ruse to educate people about phishing)
1–10 of 40 posts
Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#2Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#3You know what, this is a phisher's dream. Even if we could trust this website for not saving the data, the connection is a regular non-secure connection, so all somebody would have to do is catch some open wireless connections or similar.
they are both 'pending', since apparently, having 'credit card' in your domain is suspicious: http://ismycreditcardstolen.com/anti-phishing.jpg
Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#4You know what, this is a phisher's dream. Even if we could trust this website for not saving the data, the connection is a regular non-secure connection, so all somebody would have to do is catch some open wireless connections or similar.
Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#5Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#6Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#7I submitted no data and it still said I failed the test?
Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#8Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#9I'd remove the negativity from the start. Putting "This is a test, you have failed it" right in front of folks is an instant turn-off, and might lead people away from your page instead of to the helpful content below.
More bullet points. There's not a whole lot of text there now, but anything you can do to get the message across with fewer words is a win, especially when dealing with non-technical folks.
Under "look at the address bar", you have: A common phishing trick is to have a domain like amazon.com.not.ru, which steals your credentials when you try to log in. The actual domain in this example is "not.ru," but people often only check to see if the string "amazon.com" is anywhere in the address bar.
I'd change that to not use the word "string" since non-tech-folks don't parse that very well, and maybe include screenshots of an address bar containing the real Amazon.com and a phishing site disguised as Amazon.
Still though, good idea!
Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)
#10Interesting concept! I'd remove the negativity from the start. Putting "This is a test, you have failed it" right in front of folks is an instant turn-off, and might lead people away from your page instead of to the helpful content below. More bullet points. There's not a whole lot of text there now, but anything you can do to get the message across with fewer words is a win, especially when dealing with non-technica…
Edit: I used the "you fail" message because I think it makes people more likely to remember it. I wanted to say something like "your credit card has been stolen. kthxbye." but that would have caused some false alarms.
It's hard to have a memorable message without it causing offense or panic.
Also on my TODO: add a counter for those who put 16 digits in the credit card field.
Extra edit: nfriendly: Thanks for the styling suggestion.