Day: April 13, 2008

Spoofing, Phishing, and other internet fraud

Spoofing, Phishing, and other internet fraud

This morning in my inbox was an e-mail purportedly from eBay saying that my account had been suspended because of a number of suspicious log-ins and requesting that I follow the link below to correct the problem.

The thing is, a quick look (with Thunderbird) showed that the IP address (that’s the 4-octet string that actually tells the internet where to find a domain name) pointed to someplace in India (this took some searching on my part, not difficult for me as I was a software guy).

So these guys were/are hoping to scare people into going to their fake site where they’ll pick up your eBay user ID and password and then use your account to buy stuff.

The troubling thing is that for eBay to go after these fraudsters will require eBay to want to go to the hassle of getting a lawyer in India and winding their way through the courts. I don’t know if India has a legal system that is more or less efficient nor how severely they prosecute this sort of fraud but I wouldn’t be surprised if there is one country, probably several, where the penalties for such a fraud were outweighed by the potential gains — making crime pay.

The simple rule is always be suspicious of e-mail that seems official and, instead of clicking on the link, go to the website yourself.

The Romans had a saying thousands of years ago, caveat emptor — “Let the buyer beware.” The saying is even more valid now on the internet than it ever was in the worst of Imperial Rome.