15 October 2008

The Top 10 Tips to Avoid Phishing



Well. It’s pretty daunting when suddenly your bank account stated zero number once you’re clicking ATM machines number. Its all happen because of you just verified your account and pin number according to e-mail that you received few days ago.
That situation is not a flight of the imagination because it’s really going off nowadays as technology upward plus the deficient IT savvy among users.
I would like to give my token appreciation to Security Response Manager, F-Secure Security Labs Kuala Lumpur, Chia Wing Fei for sharing his TIPS to us to shun such thing transpire in our life


Please drop your contact in commentary box if you need assistance regarding this matter before its late and affecting your account number

By Chia Wing Fei

Security Response Manager

F-Secure Security Labs Kuala Lumpur




1. Always exercise caution when you receive an email asking you to confirm or update your details. Remember banks, auction sites, recruitment sites and other relevant websites do not send you such emails. Do not follow the link.
2. Manually type in the URL of in your web browser and double checking for any possible typos before you hit ENTER.
3. Look for the https:// at the beginning of the URL and the pad lock icon at the bottom of your browser to ensure that information submitted to the website is secure.
4. Check that the certificate of the website is genuine by double-clicking on the pad lock icon. Newer browsers like Firefox 3 does the checking for you automatically, if the certificate has expired, you will be prompted.
5. Especially for online banking, go with a bank provides you with at least two-factor based authentication mechanisms such as SMS transaction code or one-time password token.
6. Have a security suite that protects you from phishing installed on your computer and keep it updated all the time.
7. Install the latest patches and application updates to fix all vulnerabilities, have your firewall enabled and keep your security software updated always. This can be helpful in protecting you from banking Trojans or password stealers.
8. Never use a public or shared computer if you need to perform any such transactions.
9. Use an alternate browser such as Firefox 3 or Opera 9.5 which has better built-in features that protects and warns users from phishing or even harmful sites.
10. If you ever encounter a phishing site, immediately report this to the relevant authorities so that other users will not fall for it.

No comments: