Tech companies team up to fight phishing

2012-01-30 22:52

New York - Google, Facebook and other big tech companies are jointly designing a system for combating e-mail scams known as phishing.

Such scams try to trick people into giving away passwords and other personal information by sending e-mails that look as if they come from a legitimate bank, retailer or other business.

When Bank of America customers see e-mails that appear to come from the bank, they might click on a link that takes them to a fake site mimicking the real Bank of America's. There, they might enter personal details, which scam artists can capture and use for fraud.

To combat that, 15 major technology and financial companies have formed an organisation to design a system for authenticating e-mails from legitimate senders and weeding out fakes.

The new system is called DMARC - short for Domain-based Message Authentication, Reporting and Conformance.

DMARC builds upon existing techniques used to combat spam. Those techniques are designed to verify that an e-mail actually came from the sender in question.

The problem is there are multiple approaches for doing that and no standard way of dealing with e-mails believed to be fake.

The new system addresses that by asking e-mail senders and the companies that provide e-mail services to share information about the e-mail messages they send and receive.

In addition to authenticating their legitimate e-mails using the existing systems, companies can receive alerts from e-mail providers every time their domain name is used in a fake message. They can then ask the e-mail providers to move such messages to spam folder or block them outright.

Recognise as legitimate

According to Google, about 15% of non-spam messages in Gmail come from domains that are protected by DMARC. This means Gmail users "don't need to worry about spoofed messages from these senders," Adam Dawes, a product manager at Google, said in a blog post.

"With DMARC, large e-mail senders can ensure that the e-mail they send is being recognised by mail providers like Gmail as legitimate, as well as set policies so that mail providers can reject messages that try to spoof the senders' addresses," Dawes wrote.

Work on DMARC started about 18 months ago. Beginning on Monday, other companies can sign up with the organisation, whether they send e-mails or provide e-mail services.

For e-mail users, the group hopes DMARC will mean fewer fraudulent messages and scams reaching their inbox.

The group's founders are email providers Microsoft, Yahoo, AOL and Google; financial service providers Bank of America, Fidelity Investments and eBay's PayPal; online service companies Facebook, LinkedIn and American Greetings and security companies Agari, Cloudmark, eCert, Return Path and the Trusted Domain Project.

Google uses it already, both in its e-mail sender and e-mail provider capacities. The heft of the companies that have already signed on to the project certainly helps, and its founders are hoping it will be more broadly adopted to become an industry standard.

Read more on:    google  |  facebook  |  us  |  online security

Join the conversation! encourages commentary submitted via MyNews24. Contributions of 200 words or more will be considered for publication.

We reserve editorial discretion to decide what will be published.
Read our comments policy for guidelines on contributions.

linking and moving

2015-04-22 07:36 publishes all comments posted on articles provided that they adhere to our Comments Policy. Should you wish to report a comment for editorial review, please do so by clicking the 'Report Comment' button to the right of each comment.

Comment on this story
1 comment
Comments have been closed for this article.

Inside News24


Book flights

Compare, Book, Fly

Traffic Alerts
There are new stories on the homepage. Click here to see them.


Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.

Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire network.


Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.

Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.