About RSS
Search for: in 

Windows Watch - an XP & Vista blog

Users of older browsers will not be able to use PayPal
R E L A T E D   C O N T E N T

Free email newsletters




Jargon Buster

ADVERTISEMENT

Paypal to block older browsers

Plans to improve security include banning outdated browsers

Dinah Greek, Computeract!ve 18 Apr 2008
ADVERTISEMENT

Paypal plans to block older versions of popular browsers such as Internet Explorer as part of a wide range of measures to combat phishing.

Initially users of browser such as Internet Explorer (IE) 3 and IE4 will receive a warning message when they try to use Paypal. However later on the payment provider said it plans to block customers using those browsers it deems the most unsafe from using its site.

These browsers, the oldest of which was released nearly 10 years ago, lack some of the safety features of later browsers. Also flaws in the code that can be exploited by cybercriminals are not addressed with updates.

“In our view, letting users view the Paypal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seatbelts.

"The alarming fact is that there is a significant set of users who use very old and vulnerable browsers, such as Microsoft’s IE 4 or even IE 3. We argue that it’s critical to not only warn users about unsafe browsers, but also to disallow older and insecure browsers.

"At Paypal, we are in the process of re-implementing controls which will first warn our customers when logging in to Paypal from those browsers that we consider unsafe. Later, we plan on blocking customers from accessing the site from the most unsafe – usually the oldest – browsers"

The steps were outlined in a white paper, A Practical Approach to Managing Phishing, written by the firm's chief information security officer Michael Barrett and Dan Levy, director of risk management.

It described how Paypal is also supporting the use of Extended Validation SS L certificates, which were introduced a few months ago. These give consumers more confidence they are visiting a bona fide company’s site.

The latest versions of IE and Firefox support these certificates by turning the address bar green when the site visited is legitimate. They also display the company name and the certificate authority name. However Apple’s Safari browser for Mac and PCs does not.

The company said that there was “no silver bullet” for the problem of cybercrime but if the industry adopted multiple layers of defence they can make a huge difference.

“We have not identified any one solution that will single-handedly eradicate phishing; nor do we believe one will ever exist. Instead, our approach relies on a holistic 'defence in depth' model.

"In this approach, there are multiple layers of defence – while no single layer can defeat phishing on its own, in tandem they can make a huge difference, with each layer shaving off some percentage of crime that otherwise would have occurred."

See also:

Never part with your personal details when contacted via email  11 Jan 2008
New rules on cheque clearance reduce prospect of fraud  27 Nov 2007
Criminals main phishing menu goes for eBay and PayPal users  27 Jul 2006
Online payment service changes code to block phishing attack  19 Jun 2006

All Hacking and Cyber-crime
Tags: Internet

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | City of London
ICT Support Officer £27,320 - £33,370 pa inc. depending on experience (pay award pending) Maternity cover for up to one year Guildhall, London EC2 Bring your IT experience to one of the country's most prestigious ... more >
London, United Kingdom | The Crown Estate
 EDM Administrator - London - £22,300 to £24,200pa The Crown Estate is a unique organisation that manages a vast and varied property portfolio, comprising commercial, agricultural and marine interests throughout Britain. We are looking for an ... more >
Berkshire, Berkshire, United Kingdom | EDS
EDS are currently looking to recruit an experienced Core Infrastructure Project Manager to join our Project Management Defence team in one of the following locations: Reading or Bracknell (Berkshire) or Camberley (Surrey). Summary: Within DII ... more >
Inverness, United Kingdom | NHS Scotland
CORPORATE SERVICES E-HEALTH DEPARTMENT  RAIGMORE HOSPITAL INVERNESS TECHNICAL DEVELOPMENT TEAM IT TECHNICAL SPECIALIST  £24,103 to £32,653 PA An exciting opportunity has arisen to join the technical development team within the eHealth Department. We are looking ... more >
More job opportunities
Join our fight for a fair deal when shopping online
ADVERTISEMENT