I am the ghost of groovymother.com. Woooooo!

This is an old page from Rod Begbie's blog.

It only exists in an attempt to prevent linkrot. No new content will be added to this site, and links and images are liable to be broken. Check out begbie.com to find where I'm posting stuff these days.

Filed under 'phishing'

January 5, 2009

Obama Phished?

Obama Phished?

Looks like the president-elect's Twitter credentials have been compromised.

Filed under : : : :

October 12, 2008

PayPal phishes itself

PayPal phishes itself

A genuine email I received from PayPal directs the user to "SECURE.UNINITIALIZED.REAL.ERROR.COM", an apparently common problem.

Oh, if I were only less scrupulous, I'm sure I could get the funding to purchase error.com

Filed under : :

March 8, 2008

A Question of Programming Ethics

Pretty much inevitable — An app that asked for your GMail username & password was harvesting them. One point to the “Why we need OAuth” party.

Filed under : : : : :
via |

April 12, 2007

slight paranoia: A Deceit-Augmented Man In The Middle Attack Against Bank of America's SiteKey Service

Those anti-phishing “pick a photo and a phrase that must be displayed when you login to your bank” systems? Work-aroundable by smart-enough phishers. Wonder where the arms race goes next?

Filed under : : :
via |

March 26, 2007

Beginner's guide to OpenID phishing

Good overview of the phishing risks inherit in OpenID — Is it essentially doomed by providers limiting authentication to easily stealable usernames & passwords?

Filed under : : :
via |

February 5, 2007

Study Finds Web Antifraud Measure Ineffective - New York Times

I’ve always suspected that these “Select your image and don’t enter your password if you don’t see it” systems were broken — Asking users to behave differently when something is *missing*, which they’re liable to forget even *existed*, is not security by any stretch.

Filed under : : :
via |

October 2, 2006

PhishTank | Join the fight against phishing

New open database of user-submitted Phishing URLs. Somewhat reminiscent of Mark Fletcher’s old “Trustic” startup. Not sure how well the submission/validation system will scale, or deal with gaming, but it could be interesting to watch.

Filed under : : :
via |

February 22, 2006

SANS - Internet Storm Center - Phollow the Phlopping Phish

All the info on a remarkably well-done phishing scam. Even users trained not to fall for scams could fall for this.

Filed under : : :
via |

December 15, 2005

Google Safe Browsing for Firefox

Extremely well-designed anti-phishing extension from Google.

Filed under : : : : :

About This Site

This is an archive of groovmother.com, the old blog run by Rod Begbie — A Scottish geek who lives in San Francisco, CA.

I'm the co-founder of Sōsh, your handy-dandy guide for things to do in San Francisco this weekend.