Live data from Hacker News

Is My Credit Card Stolen? (A ruse to educate people about phishing)

ismycreditcardstolen.com

31–40 of 40 posts

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#32
post #28

1) Create an online form that doesn't take input, and call it "educational". 2) Get a bunch of educated people to review it for 3-5 days and approve of it. 3) Wait until the educated people send links of this to their non-internet literate friends, for education, shits and harmless giggles. 4) Switch to a live form that captures data.

Clever idea, but it's not hard to find out the identities of those behind this site. They'd get busted for fraud pretty quickly.

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#33

I havent particularly been following it, but is there any real solution to phishing? with punycode domains and arbitrary tld's, along with characters that look the same in a lot of fonts, l and I, people need a cs degree to figure out if they are being phished. I guess paypal and a small number of verified payment processors, (or real online banking) are about the only option.

Yes, Use bookmarks on a trusted computer or better yet type any sensitive domains. Typing www.paypal.com is easy.

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#34
post #2

You know what, this is a phisher's dream. Even if we could trust this website for not saving the data, the connection is a regular non-secure connection, so all somebody would have to do is catch some open wireless connections or similar.

View the HTML source. The credit card inputs aren't part of the form. They're never sent across the wire.

Another way this could be a good scheme is if people trust it and start sending it as a way to educate people, and when it starts getting momentum, it is changed and does start recording numbers.

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#36

I havent particularly been following it, but is there any real solution to phishing? with punycode domains and arbitrary tld's, along with characters that look the same in a lot of fonts, l and I, people need a cs degree to figure out if they are being phished. I guess paypal and a small number of verified payment processors, (or real online banking) are about the only option.

Yes, Use bookmarks on a trusted computer or better yet type any sensitive domains. Typing www.paypal.com is easy.

[deleted]

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#39
post #38

They are banned now... So anti-phishing folks got accused for phishing. Looks it was technically nice idea but terrible user experience. Unless of course there WAS a hidden agenda here.

Okay, that explains why I couldn't understand what you guys were talking about and all I got was a "Warning: Suspected phishing site!"

Re: Is My Credit Card Stolen? (A ruse to educate people about phishing)

#40

I havent particularly been following it, but is there any real solution to phishing? with punycode domains and arbitrary tld's, along with characters that look the same in a lot of fonts, l and I, people need a cs degree to figure out if they are being phished. I guess paypal and a small number of verified payment processors, (or real online banking) are about the only option.

Yes, and it's very simple. Don't type anything important unless you also typed the URL into the address bar. Plenty of real mail from reputable, very phishable, sites actually say exactly this in their real emails-to-customers sometimes.

Laziness, of course, is a problem also.

Post reply on HN