4 ms·
Like phishing awareness training, this is a good practice. We actually offer URL rewriting to our customers, but there are some UX downsides to it so not everyo
by dmbaggett 8y ago
Like phishing awareness training, this is a good practice. We actually offer URL rewriting to our customers, but there are some UX downsides to it so not everyone wants it.
One big issue with GSB, Phishtank, OpenPhish, etc. as "the solution" is that, again, it's trivial for attackers to thwart these threat feeds. Using the same approach spammers have been implementing for 20 years now, the attacker just needs to randomize the URL in each sent email. Then when you report the phishing link in your copy, it helps no one else.
One could imagine a system that reverses the patterns used by the URL generation scripts -- we actually do this for DGAs ("domain generation algorithms") -- but even trying to be clever like this just puts you back in an arms race with the attackers.
So I don't think URL "whack-a-mole" is the right answer either. I believe you need the software to straight-up identify fraudulent emails from first principles. (Not saying it's easy.)
- marmot777 8y agoYes, spammers learned to switch IP addresses very quickly. The email filters became more sophisticated ways of identifying your spam from a different IP addresss and even from a different domain name. Spammers could run but not hide. I think I see a LOT less spam that actually gets to my inbox than in years past. Hats off to those who worked hard on making an incredible amount of progress on hard provlems, and continue to plow ahead.