11/12/2008

hosters and webservices should work with phishtank

Phishtank is becoming the central point where phished sites are being proposed, researched and proposed for closure. It has aside from the whole cavalery of individual volunteers organisational and informational deals wiith a whole lot of other commercial and open source inititiatives.

Altervista.org is a such a webhoster that works together with phishtank and uses the permanent instream (by rss) of new sites as a source they have to check up and eventually take action upon. This way phishing sites can be closed quite quickly, without any of the complicated procedures and timestealing contactsearching that accompany the closing down of a site at the demand of others.

There is nothing so simple as to close down a site because it is participating in phishing. You should mention this explicitly in your conditions if you are a serviceprovider, free or commercial.

It should sound something like this.

"If the service provided is being used - intentionally or not - to service or to redirect to financial fraud or other phishing sites, malware of rogue securitysoftware installations or has been defaced or is being used in malicious activity, it will be taken offline immediately without any prior notice by the security team. The owner will be informed within the next 4 business hours. It will only be brought back online if the owner of the site or service can prove that he has taken sufficient measures to enforce a better security of his site or service".

The insecurity of a few can bring down the good name (and business value) of your whole company.

08:40 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment