<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: Phishing and the gaining of &#8220;clue&#8221;</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Thu, 18 Mar 2010 17:41:05 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: era</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/comment-page-1/#comment-24335</link>
		<dc:creator>era</dc:creator>
		<pubDate>Thu, 04 Oct 2007 07:46:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/#comment-24335</guid>
		<description>Somewhat late in the game, the Hong Kong registrar issues a PR release about this: https://www.hkdnr.hk/hkdnr/20070928/web-content/coverstory.html

(I'm linking directly to the content frame; the site maintainers would probably like you to &lt;strike&gt;suffer&lt;/strike&gt; visit https://www.hkdnr.hk/hkdnr/20070928/web-content/index.html where they show off all their bling, 1990s Geocities style.)</description>
		<content:encoded><![CDATA[<p>Somewhat late in the game, the Hong Kong registrar issues a PR release about this: <a href="https://www.hkdnr.hk/hkdnr/20070928/web-content/coverstory.html" rel="nofollow">https://www.hkdnr.hk/hkdnr/20070928/web-content/coverstory.html</a></p>
<p>(I&#8217;m linking directly to the content frame; the site maintainers would probably like you to <strike>suffer</strike> visit <a href="https://www.hkdnr.hk/hkdnr/20070928/web-content/index.html" rel="nofollow">https://www.hkdnr.hk/hkdnr/20070928/web-content/index.html</a> where they show off all their bling, 1990s Geocities style.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/comment-page-1/#comment-24261</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Sun, 30 Sep 2007 15:32:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/#comment-24261</guid>
		<description>We were trying to make the point that "gaining clue" is a general phenomenon that can be observed in several different situations. We chose Alice because it had recently been chosen by the phishers (probably a small number of attackers, possibly even just one) and hence we can measure the change in their response rates. The TLDs were again chosen because the phishers had chosen to start using them during the period we were making measurements -- though to be strict we are really measuring the response of a small number of registrars rather than registrys, but for some TLDs the difference is moot.</description>
		<content:encoded><![CDATA[<p>We were trying to make the point that &#8220;gaining clue&#8221; is a general phenomenon that can be observed in several different situations. We chose Alice because it had recently been chosen by the phishers (probably a small number of attackers, possibly even just one) and hence we can measure the change in their response rates. The TLDs were again chosen because the phishers had chosen to start using them during the period we were making measurements &#8212; though to be strict we are really measuring the response of a small number of registrars rather than registrys, but for some TLDs the difference is moot.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Davide Denicolo</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/comment-page-1/#comment-24260</link>
		<dc:creator>Davide Denicolo</dc:creator>
		<pubDate>Sun, 30 Sep 2007 15:24:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/#comment-24260</guid>
		<description>Hi Tyler interesting article.
Why do you compare in your research an Internet provider as Alice with a generic statistic of top level domain ?
Around Internet there are many Internet provider as Alice; why have you choose it?</description>
		<content:encoded><![CDATA[<p>Hi Tyler interesting article.<br />
Why do you compare in your research an Internet provider as Alice with a generic statistic of top level domain ?<br />
Around Internet there are many Internet provider as Alice; why have you choose it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler Moore</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/comment-page-1/#comment-23671</link>
		<dc:creator>Tyler Moore</dc:creator>
		<pubDate>Mon, 20 Aug 2007 10:25:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/#comment-23671</guid>
		<description>Susan,
There are a number of plausible reasons why there was an uptick in mid-June, and you listed a couple of them.  What's noteworthy is that site lifetimes are always quite volatile.  Even 'clued-up' providers inadvertently let sites slip through the cracks for many days before removing them.  Such high variation seems to be a fundamental characteristic of phishing site lifetimes.  

Tyler</description>
		<content:encoded><![CDATA[<p>Susan,<br />
There are a number of plausible reasons why there was an uptick in mid-June, and you listed a couple of them.  What&#8217;s noteworthy is that site lifetimes are always quite volatile.  Even &#8216;clued-up&#8217; providers inadvertently let sites slip through the cracks for many days before removing them.  Such high variation seems to be a fundamental characteristic of phishing site lifetimes.  </p>
<p>Tyler</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Susan W.</title>
		<link>http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/comment-page-1/#comment-23650</link>
		<dc:creator>Susan W.</dc:creator>
		<pubDate>Sat, 18 Aug 2007 21:08:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2007/08/16/phishing-and-the-gaining-of-clue/#comment-23650</guid>
		<description>Great visualization -- I like the idea of "clue" as a quantifiable characteristic.

I am curious what happened in mid-June in both .hk and .cn -- there was a small upwards blip.  Somebody in the abuse department on a summer holiday?  Innovative design by phishers that their abuse department didn't recognize?  Analysis of graphs like this could definitely lead to improvements in an abuse-reporting process, as well as internally by ISP's to examine their own abuse department's effectiveness.</description>
		<content:encoded><![CDATA[<p>Great visualization &#8212; I like the idea of &#8220;clue&#8221; as a quantifiable characteristic.</p>
<p>I am curious what happened in mid-June in both .hk and .cn &#8212; there was a small upwards blip.  Somebody in the abuse department on a summer holiday?  Innovative design by phishers that their abuse department didn&#8217;t recognize?  Analysis of graphs like this could definitely lead to improvements in an abuse-reporting process, as well as internally by ISP&#8217;s to examine their own abuse department&#8217;s effectiveness.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
