Audit Clears MS Phishing Filter as Privacy Risk

執筆者
Ryan Naraine
Ryan Naraine
Published: May 10, 2006
Updated: Feb 2, 2021
3 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

A third-party audit of the new phishing filter built into the Internet Explorer 7 browser and the MSN Toolbar has given the technology a thumbs up on the sensitive issue of user privacy.

Jefferson Wells International, an IT auditing group, has validated Microsofts assurances that the phishing filter does not transmit any personally identifiable information without explicit user consent and that any URL information sent from the users browser cannot be traced back to the surfers personal information.

The privacy thumbs up is a boost to Microsofts mission to market IE 7 as a major security overhaul with features to thwart identity theft and drive-by spyware and Trojan installations.

Microsoft has long insisted the technology does not present a risk to user privacy, but because it uses a mechanism that transmits data to a Microsoft Web service for authentication checks, the company felt the need to call in third-party auditors to verify its claims.

“We gave [the auditors] in-depth access to the technology and to the engineering team. After they studied the technology and interviewed the engineering team, they agreed that the claims we made about protecting your privacy are true and accurate,” said Rob Franco, lead program manager for IE security at Microsoft.

In a blog entry announcing the audit results, Franco said Microsoft will repeat the audit periodically so that even if the service changes in some way, surfers will still have proof that the Web service protects user privacy.

In the MSN Toolbar implementation, an IE user that is tricked into visiting a known phishing scam site will be automatically blocked from entering personal information on the site. This is done via a client-side whitelist that stores phishing site data.

In IE 7, when the filter is turned on, every URL a user visits that is not on the client-side whitelist is transmitted to Microsofts servers to be checked. In the tool bar add-in, the service serves as an “early warning system” for suspicious Web sites and will provide two levels of color-coded warnings.

Ziff Davis Media eSeminars invite: Join us on May 11 at 2 p.m. ET to learn critical best practices for e-mail and instant messaging applications, including tips on “hygiene” from Gartner.

Advertisement

Details on how the data is transmitted is not known, but according to the audit by Jefferson Wells, HTTP and HTTP Secure URLs transmitted for rating by the Phishing Filter client are limited to the domain and path only. “All other information in the URL is stripped,” company officials said.

The auditors confirmed that the phishing filter client only transmits URLs when the user wants to manually provide feedback on a URL, when the URL is not found in the Phishing Filter local data files, or when the phishing filter client heuristics determine a site as suspicious.

Transmission of any and all URL information by the Phishing Filter client is over SSL on the Internet, Jefferson Wells officials said.

Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

Ryan Naraine

Ryan Naraine

Content Writer

Ryan Naraine is a ServerWatch, eSecurity Planet, and eWEEK contributor.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。