PDA

View Full Version : Phishing & the law


mercinary
March 24th, 2005, 09:04 AM
Over on <a href="http://www.matrixwatch.org/forums/showthread.php?p=20983#post20983">this</a> thread we were talking about Paypal and Phishing (and why it is allowed to happen).

The following article pertains to the matter, so I'm starting a new thread for discussion.

http://story.news.yahoo.com/news?tmpl=story&cid=1093&ncid=1093&e=2&u=/pcworld/20050307/tc_pcworld/119912


Proposed Law Aims to Fight Phishing
Mon Mar 7,12:00 PM ET
Grant Gross, IDG News Service

WASHINGTON-- A bill introduced in the U.S. Senate last week would allow prison time of up to five years and fines of up to $250,000 for people who design fake Web sites for the purposes of stealing money or credit card numbers.

• Senators Want Tax Breaks for Proper Computer Disposal
• New Copyright Protection Bills Likely in 2005
• Spyware Bill Finds New Life
• Congress Fails to Act on Copyright Bills
• Spyware Bill Passes House


More Than Mail
How to master the popular information manager. Plus, great Outlook alternatives, and apps to expand the program.



The Anti-Phishing Act of 2005, introduced by Senator Patrick Leahy (D-Vermont), would outlaw "phishing," in which scam artists design Web sites to look like real banking or e-commerce sites, then e-mail spam to people saying they need to re-enter their account or credit card numbers at the bogus site.

The bill, similar to one that failed to pass in 2004, would allow law enforcement officials another tool to fight phishing scams, by creating an opportunity to prosecute before the actual fraud takes place, says Julie Katzman, a legal advisor to Leahy on the Senate Judiciary Committee (news - web sites). The bill is intended to deter phishing scammers, she adds.

"It helps to have a crime that defines the conduct," Katzman says. "It does send [scammers] a signal."
Phishing and Pharming

Leahy's bill would also extend the same penalties to so-called "pharming," in which scammers redirect computer users' browsers and direct them to spoofed banking or e-commerce sites.

Leahy, in a statement, notes that the average phishing Web site is active for less than six days.

"Some phishers and pharmers can be prosecuted under wire fraud or identity theft statutes, but often these prosecutions take place only after someone has been defrauded," Leahy says in a statement. "For most of these criminals, that leaves plenty of time to cover their tracks. Moreover, the mere threat of these attacks undermines everyonea??s confidence in the Internet. When people cannot trust that Web sites are what they appear to be, they will not use the Internet for their secure transactions."

The number of new phishing messages climbed by an average of 38 percent a month during the last six months of 2004, according to the Anti-Phishing Working Group. The number of phishing e-mails grew by 42 percent, and the number of unique phishing Web sites grew by 47 percent in January, according to the group.

Leahy's bill requires that the spoofed Web sites be designed with the goal of committing fraud or identity theft. Parody Web sites, both commercial and political, are exempt from the penalties in the bill.


-Merc

jokach
March 24th, 2005, 10:32 AM
It would be great if this bill passed, but I think they have some work to do on it. My concern is in this statement:


Parody Web sites, both commercial and political, are exempt from the penalties in the bill.


This type of thing is open-ended and needs to be defined better, because its a matter of opinion whether its a parody or not, especially if nobody was yet defrauded on the site. (basically it sounds like a cop-out).

I personally think that they should start holding web-host providers with some accountablity in the scams that get run on their servers. This includes sites like ebay as well. If web-hosts know that the government was helping to police illegal activities on their servers, and hold them accountable, I think you would see abuse go down somewhat. This of course counts on enforcement of the bill.

I seem to think there are too many 'little' guy web-hosts out there who will sell space to anybody because the market is so flooded, and they want the business. If they know they are a needle in the haystack, they are more likely to look beyond potentially illegal scams, as some do for the matrix scams.

just my $.02

jokach