Sponsored by
 |
|
|
|

PayPal Plans to Ban Unsafe Browsers
By Ryan Naraine
2008-04-17
Article Views: 30548
Article Rating:    / 28
| Rate This Article: |
|
| Add This Article To: |
|
|
PayPal Plans to Ban Unsafe Browsers (
Page 1 of 2 ) PayPal says allowing customers to make financial transactions on unsafe browsers "is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts."PayPal, one of the brands most spoofed in phishing attacks, is working on a plan to block its users from making transactions from Web browsers that don't provide anti-phishing protection.
The eBay-owned company, which runs a Web-based payment system that allows the transfer of funds between bank accounts and credit cards, said browsers that do not have support for blocking identity theft-related Web sites or for EV SSL (Extended Validation Secure Sockets Layer) certificates are considered "unsafe" for financial transactions.
"In our view, letting users view the PayPal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts," said PayPal Chief Information Security Officer Michael Barrett.
In a white paper that outlines a five-pronged action plan aimed at slowing the phishing epidemic, Barrett said there's a "significant set of [PayPal customers] who use very old and vulnerable browsers" and made it clear that any browser that falls into the "unsafe" category will be banned.
"At PayPal, we are in the process of reimplementing controls which will first warn our customers when logging in to PayPal of those browsers that we consider unsafe. Later, we plan on blocking customers from accessing the site from the most unsafe—usually the oldest—browsers," he declared.
Who are the most influential people in security? Find out here.
Barrett only mentioned old, out-of-support versions of Microsoft's Internet Explorer among this group of "unsafe browsers," but it's clear his warning extends to Apple's Safari browser, which offers no anti-phishing protection and does not support the use of EV SSL certificates.
The EV SSL certificates are meant to provide trust to Web-based transactions. For example, if you use Microsoft's IE 7 to visit a Web site secured with an EV SSL certificate, the URL address bar is displayed in green and offers the ability for the user to toggle between the organization name listed in the certificate and the issuing Certificate Authority.
Firefox and Opera have announced their intention to support EV SSL in upcoming releases.
Apple's Safari browser, which is being aggressively pushed to Windows users, could conceivably be banned from accessing PayPal.com under the plan outlined by Barrett.
EV Certificates Unproven, but Best Solution Yet
The jury is still out on the value of EV SSL certificates as a meaningful security utility but, in Barrett's mind, the green URL bar offers a visual cue that "makes it much easier for users to determine whether or not they're on the site that they thought they were visiting."
He said PayPal was one of the first companies to adopt EV certificates. "More or less all of the pages on our site are SSL encrypted, and they all use EV certificates. And after nine months of usage, [our] data suggests that there is a statistically significant change in user behavior. For example, we’re seeing noticeably lower abandonment rates on sign-up flows for IE 7 users versus other browsers. We believe that this correlates closely to the user interface changes triggered by our use of EV certificates," Barrett added.
PayPal is also recommending the use of blacklists and anti-fraud warning pages as effective technologies to help protect consumers from identity theft fraud. Microsoft and Mozilla have invested heavily in anti-malware blockers and anti-phishing technology.
| | Discuss PayPal Plans to Ban Unsafe Browsers | | | | | | | Guess that means no more using PayPal at work. Especailly since many companies,... | | | | | | How intelligent! Ban the user, not from a malicious site, but from a legitimate... | | | | | | A simple solution ....... use OpenDNS ... it's free and it works. Go to... | | | | | | I've bought a couple thousand dollars worth of stuff on eBay over the last year,... | | | | | | This is all about user control and nothing else, but being presented as a consumer... | | | | | | Isn't this anti competition and illegal. I think they could wind in trouble. They... | | | | | | I have IE, Safari, and Firefox. I think you should contact apple about this if... | | | | | | You raise valid points but problem is govt should deal with sites but not this... | | | | | | With respect, I understand that this can be easily construed as "mannying" or... | | | | | | No, its not anti-competitive or illegal. they are requiring certian security... | | | | | | It is long past the time when the companies that process online credit/debit card... | | | | | | You should have a blog (Lily) if you don't, from the looks of it. You have valuable... | | | | | | There are no laws against a company securing it's assets, and they have the right to... | | | | | | >>> Post your comment now! | | | | | |
|
 |
|
|
 |
 |
 |
| FEATURED CONTENT |
What Virtual Servers Need to Succeed
Virtualization shouldn't lower IT costs by sacrificing performance, reliability or business results. HP multiport network adapters built with Intel Ethernet technology can help eliminate network bottlenecks in a virtual machine environment. Learn More!
|
|
Sponsored by
| |
|
| DOWNLOADABLE ROI CALCULATORS & TOOLS FROM BASELINE |
Calculate Cost and ROI of Spam, VOIP, RFID, Sarbanes-Oxley and more...
Featured Calculators:
See More Tools!
By Category| Planners |Calculators | Quizzes
|
| | |
|
|
 |
EWEEK E-MAIL NEWSLETTERS bring you reliable, timely
information to stay on top of the business of technology -- and
technology in business -- and get more out of the Web.
Make your choices and start your subscriptions today!
| 
|
 |
EWEEK RSS NEWS FEEDS contain a daily feed of our latest stories from over 30 different categories including Enterprise Apps, Business Intelligence, Security, VOIP and more!
Subscribe to our RSS feeds today for free...
| 
| |
|