CNNMoney.com
Companies Economy International Corrections Pre-market Trading After-hours Trading Winners/Losers/Actives Bonds Currencies Commodities World Markets Money Magazine Real Estate Taxes Jobs Ask the Expert Money 101 Autos Mutual Funds The Help Desk Loan Center Best Places to Live Ask the Expert Ultimate Guide to Retirement Retirement Calculators Best Funds Best Places to Retire Fortune Brainstorm Tech Apple 2.0 Blog Big Tech Blog Sectors and Stocks Tech Talk Resource Guide Small Business Makeovers Questions & Answers Small Business Video 100 Best Places to Launch FSB 100 Fortune Small Business Fortune 500 Brainstorm Tech Investing Management C-Suite Rankings Main Create Portfolio Edit Portfolio Create Alerts Edit Alerts
 
New anti-"phishing" site may sink or swim
PhishTank, a new service from Internet-acceleration startup OpenDNS, wants to rid the Web of "phishing" emails - messages that pose as legitimate customer-service emails from banks and e-commerce websites and try to trick users into revealing their passwords. The site works by collecting examples of suspected phishing emails, and then relies on users to vote on them as legitimate or illegitimate.

The digerati are loving it: Georgia Tech student and former Yahoo intern Paul Stamatiou praises PhishTank for a simple phish-submission process and an open API, or application programming interface, which lets other websites and software makers tap into PhishTank's database of suspicious emails. "Once the PhishTank databases grows, other sites can harness the data using open APIs which will remain free," writes Digital Inspiration blogger Amit Agarwal.

We hate to rain on the PhishTank parade, but that's a mighty big if. What's the incentive for ordinary users to report phishing emails? They're busy enough just deleting spam - and for mere mortals, the distinction between phishing email and spam is exceedingly fine. Our suggestion: Rather than relying on consumers to take time to sort through their emails and report suspected phishes - let alone vote on them after they're submitted - PhishTank should focus on making alliances with big email providers like Microsoft, Google, and Yahoo, to act as a central clearinghouse for anti-"phishing" data.
Posted by Owen Thomas 12:02 PM 5 Comments comment | Add a Comment

What's the incentive? People will want to use the PhishTank API for their next web app, product or plugin, so they would help out community and report phishing sites they are aware of, thereby helping the PhishTank community and themselves as they use the service's API.
Posted By Paul Stamatiou, Atlanta, GA : 2:40 PM  

"What's the incentive for ordinary users to report phishing emails?"

Um, revenge? Phishers occupy an especially low strata on the SPAM totem pole. I for one would love to report phishing e-mail if I thought it would do any good...
Posted By Brian, New York, NY : 3:35 PM  

Owen,

Your points are well taken. One of the motivations behind PhishTank is that we already have people sending in phish emails to our support address at OpenDNS. At the very least, this gives them a place where we can manage their awesome enthusiasm in a scalable way. But I'm confident it'll be much more than that for the benefit of a much wider audience.

-david
Posted By David Ulevitch, San Francisco, CA : 4:28 PM  

I like the idea. I get so many fishing eMails that I would be happy to do a bit of voting if this helps to get rid of them in the future.
Posted By Stephanie, Melbourne, Australia : 9:33 PM  

To respond to Owen Thomas' point, "What's the incentive for ordinary users to report phishing emails?", it's the same idea as private citizens reporting crimes to law enforcement officials.

If someone writes an add-in that would let you simultaneously delete *and* report phishing mail, why not? With an API like this available, that's now possible.
Posted By Richard Hale Shaw, Cambridge, MA : 8:33 AM  

To send a letter to the editor about The Browser, click hereTop of page

Got a news tip? Send it to The Browser


© 2009 Cable News Network. A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Privacy Policy
Copyright © 2009 BigCharts.com Inc. All rights reserved. Please see our Terms of Use.
MarketWatch, the MarketWatch logo, and BigCharts are registered trademarks of MarketWatch, Inc.
Intraday data provided by Interactive Data Real-Time Services and subject to the Terms of Use.
Intraday data is at least 20-minutes delayed. All times are ET.
Historical, current end-of-day data, and splits data provided by Interactive Data Pricing and Reference Data.
Fundamental data provided by Morningstar, Inc..
SEC Filings data provided by Edgar Online Inc..
Earnings data provided by FactSet CallStreet, LLC.