My bank (NatWest) and various other providers I have accounts with, are all in a tizzy about "email scams" and how we should be aware of them etc. NatWest have even suspended their online money transfer facility until further notice because (presumably) the scams are working rather well and there's a danger of fraudulent withdrawals.
But haven't the banks heard of server certificates and PKI? Why can't they just give us a certificate to import into our browser that will authenticate legitimate communications from them? Sure it won't stop complete idiots who will click "proceed" even when they see a notice saying the site/cert is not properly authenticated or whatever, but it sure would be a step in the right direction.
On a similar note, a friend of mine got a call from his bank the other day asking him to verify a couple of large purchases on his credit card. He asked them how he knew it was his bank calling - and they didn't know what to say. They were all ready with the "what's your mothers maiden name?" stuff, but the call centre had no script for authenticating *themselves* to the customer. In the end he had to call them, talk to a line manager, and "share" the authentication questions (he told them his day of birth, they told him his month, etc.)
No wonder these scams are working when there isn't even as basic attempt at using any real authentication system!
Jonathan
PS: I received what was pretty obviously a scam pretending to be from NatWest the other day, and looked at the source. All the links pointed to legitimate NatWest (RBS) sites, but the main one you were supposed click on looked like this:
http://www.nwolb.com:UserSession/4d0zzz899oakileikaiejs559875&userrstste=SecurityUpdate&StateLevelÊmeFrom@64.148.18.13/ (note I've changed the above a bit to protect the innocent)
What's that all about then? The IP address traces back to a netblock owned by "Brown And Toland" of 268 Bush St. #5000, San Fran. The NatWest logo itself was served from a website whos IP is owned by "Eugene L Rowe" of the same address. All the other assets referred to by the email were owned by NatWest (RBS).