<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.4" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: When the community doesn&#8217;t reach a consensus</title>
	<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/</link>
	<description>A blog about and from PhishTank, a collaborative clearinghouse for data about phishing.</description>
	<pubDate>Thu, 21 Aug 2008 06:35:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.4</generator>

	<item>
		<title>by: MASA</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-241</link>
		<pubDate>Fri, 17 Nov 2006 07:23:29 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-241</guid>
					<description>It has to be a phish, see how it is asking for your SS number?

That's like asking for your CC # but worse.</description>
		<content:encoded><![CDATA[<p>It has to be a phish, see how it is asking for your SS number?</p>
<p>That&#8217;s like asking for your CC # but worse.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: micha</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-115</link>
		<pubDate>Sat, 21 Oct 2006 10:24:24 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-115</guid>
					<description>This page surely is scam but --&#62; NOT asking for any password. For me, the definition of "phishing" is still close to "password fishing". Thus, of course voted NOT a phish :D</description>
		<content:encoded><![CDATA[<p>This page surely is scam but &#8211;&gt; NOT asking for any password. For me, the definition of &#8220;phishing&#8221; is still close to &#8220;password fishing&#8221;. Thus, of course voted NOT a phish <img src='http://www.phishtank.com/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> 
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: jaded</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-107</link>
		<pubDate>Thu, 19 Oct 2006 22:24:35 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-107</guid>
					<description>It's not a phish.  It may be a spam, it may be a scam, it may be legitimate, but the one thing it's not is a phish.  It might help if there were voting options for "spam" or "scam".  That way people who don't like the content can label it as such, just not as a phish.

One of the things I do for every submission is compare the URL to the site's name.  If it looks like it might be legit, I google for the company.  I just had one for Five Thirds Bank and the URL was something like http://administrator-53.com.  When I googled for "five thirds bank", google instead took me to http://www.53.com.  That page looked exactly like the phish, so I knew it was a phish.  

In this case I googled for "great student loan payoff" and this URL was google's answer.  Therefore this site is not a phish.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not a phish.  It may be a spam, it may be a scam, it may be legitimate, but the one thing it&#8217;s not is a phish.  It might help if there were voting options for &#8220;spam&#8221; or &#8220;scam&#8221;.  That way people who don&#8217;t like the content can label it as such, just not as a phish.</p>
<p>One of the things I do for every submission is compare the URL to the site&#8217;s name.  If it looks like it might be legit, I google for the company.  I just had one for Five Thirds Bank and the URL was something like <a href='http://administrator-53.com.' rel='nofollow'>http://administrator-53.com.</a>  When I googled for &#8220;five thirds bank&#8221;, google instead took me to <a href='http://www.53.com.' rel='nofollow'>http://www.53.com.</a>  That page looked exactly like the phish, so I knew it was a phish.  </p>
<p>In this case I googled for &#8220;great student loan payoff&#8221; and this URL was google&#8217;s answer.  Therefore this site is not a phish.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Dougie Lawson</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-97</link>
		<pubDate>Wed, 18 Oct 2006 01:06:06 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-97</guid>
					<description>It's a lottery. Everyone gets a dollar. Everyone gets a salesman trying to sell a  student loan consolidation loan. Someone gets a hundred grand. It's sitting on a https site with a valid certificate issued by Verisign. It may not be wise to divulge all that personal data, but it's not phishing. I voted "not a phish".

My definition of phishing being a site that purports to be a legitimate bank or financial institution for the purpose of stealing your credentials for that bank or financial institution.

Perhaps someone needs to report this to your Federal Trade Commission.
https://rn.ftc.gov/pls/dod/wsolcq$.startup?Z_ORG_CODE=PU01

If this was in the United Kingdom I'd report this to the Financial Services Authority.</description>
		<content:encoded><![CDATA[<p>It&#8217;s a lottery. Everyone gets a dollar. Everyone gets a salesman trying to sell a  student loan consolidation loan. Someone gets a hundred grand. It&#8217;s sitting on a https site with a valid certificate issued by Verisign. It may not be wise to divulge all that personal data, but it&#8217;s not phishing. I voted &#8220;not a phish&#8221;.</p>
<p>My definition of phishing being a site that purports to be a legitimate bank or financial institution for the purpose of stealing your credentials for that bank or financial institution.</p>
<p>Perhaps someone needs to report this to your Federal Trade Commission.<br />
<a href='https://rn.ftc.gov/pls/dod/wsolcq$.startup?Z_ORG_CODE=PU01' rel='nofollow'>https://rn.ftc.gov/pls/dod/wsolcq$.startup?Z_ORG_CODE=PU01</a></p>
<p>If this was in the United Kingdom I&#8217;d report this to the Financial Services Authority.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Ilgaz</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-96</link>
		<pubDate>Tue, 17 Oct 2006 20:41:54 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-96</guid>
					<description>Benz it is not a "phish" by definition, it is a scam.

Phish means like, a legit looking mail from a respected organisation such as bank.

You should check http://www.fraudwatchinternational.com , they are interested in scams.</description>
		<content:encoded><![CDATA[<p>Benz it is not a &#8220;phish&#8221; by definition, it is a scam.</p>
<p>Phish means like, a legit looking mail from a respected organisation such as bank.</p>
<p>You should check <a href='http://www.fraudwatchinternational.com' rel='nofollow'>http://www.fraudwatchinternational.com</a> , they are interested in scams.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Benz</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-93</link>
		<pubDate>Tue, 17 Oct 2006 13:44:48 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-93</guid>
					<description>Fuggedaboudit! I ain't about to give out all my personal info to nobody! So what more does this no morals of a website want from a poor unsuspecting student? Geez! Go to a reliable source for the cash. Then, face to face, the loan officer will take down all the info they may need to make the loan. Not some jerk on the net who most likely doesn't arrainge loans anyhow. They should be viewed as phish for their approach and what they're up to. Avoid them like the plague!</description>
		<content:encoded><![CDATA[<p>Fuggedaboudit! I ain&#8217;t about to give out all my personal info to nobody! So what more does this no morals of a website want from a poor unsuspecting student? Geez! Go to a reliable source for the cash. Then, face to face, the loan officer will take down all the info they may need to make the loan. Not some jerk on the net who most likely doesn&#8217;t arrainge loans anyhow. They should be viewed as phish for their approach and what they&#8217;re up to. Avoid them like the plague!
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: astrogeek</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-87</link>
		<pubDate>Thu, 12 Oct 2006 17:38:51 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-87</guid>
					<description>Maybe this is a good case for a 3rd option - "Is Spam".  It is outside the scope of this project directly, but there are a number of posts that have come across that are 100% spam.  Of course, by definition if it's spam it's not a phish, which is what I voted.  It's marketing, pure and simple (heaven help if you if you click it).</description>
		<content:encoded><![CDATA[<p>Maybe this is a good case for a 3rd option - &#8220;Is Spam&#8221;.  It is outside the scope of this project directly, but there are a number of posts that have come across that are 100% spam.  Of course, by definition if it&#8217;s spam it&#8217;s not a phish, which is what I voted.  It&#8217;s marketing, pure and simple (heaven help if you if you click it).
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Blain</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-84</link>
		<pubDate>Thu, 12 Oct 2006 03:17:31 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-84</guid>
					<description>Unfortunately, the reliability of this system suffers when the rules get bent.  This is not the place to solve all the problems on the net -- this is a place to identify phishing schemes.  If it can do that reliably, then it will have value and will help make things better, and that's a good thing.  

Taking time to figure out if a non-phish thing is a good thing or a bad thing, and, if it's a bad thing, to identify it as phish when it isn't, doesn't really help anything IMO.  It's going to be a period of time before anybody's going to be able to figure out how to use this data to actually impact the amount of phishing going on and the harm that it's doing to people.  Let's not push that date back by giving reasons to doubt the reliability of the service.  The concern about false-positive is something that should concern everybody -- one false-positive is much more dangerous that 100 false-negatives.</description>
		<content:encoded><![CDATA[<p>Unfortunately, the reliability of this system suffers when the rules get bent.  This is not the place to solve all the problems on the net &#8212; this is a place to identify phishing schemes.  If it can do that reliably, then it will have value and will help make things better, and that&#8217;s a good thing.  </p>
<p>Taking time to figure out if a non-phish thing is a good thing or a bad thing, and, if it&#8217;s a bad thing, to identify it as phish when it isn&#8217;t, doesn&#8217;t really help anything IMO.  It&#8217;s going to be a period of time before anybody&#8217;s going to be able to figure out how to use this data to actually impact the amount of phishing going on and the harm that it&#8217;s doing to people.  Let&#8217;s not push that date back by giving reasons to doubt the reliability of the service.  The concern about false-positive is something that should concern everybody &#8212; one false-positive is much more dangerous that 100 false-negatives.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: someone1234</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-78</link>
		<pubDate>Wed, 11 Oct 2006 06:34:24 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-78</guid>
					<description>Yeah, it took me some time to vote on that one. I voted phish only because the target audience are students.
So, yeah, i slightly bent the rules.</description>
		<content:encoded><![CDATA[<p>Yeah, it took me some time to vote on that one. I voted phish only because the target audience are students.<br />
So, yeah, i slightly bent the rules.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Tim Wilde</title>
		<link>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-73</link>
		<pubDate>Tue, 10 Oct 2006 23:16:11 +0000</pubDate>
		<guid>http://www.phishtank.com/blog/2006/10/10/when-the-community-doesnt-reach-a-consensus/#comment-73</guid>
					<description>I wonder if more context might help in a situation like this - what did the e-mail that the link was contained in look like?  You've said you might be providing this information in past postings, and this would be a case that I think argues for it.  If the e-mail is consistent with the URL itself and the web site, then I'd agree (and in fact that confirms what I voted), not a phish.  But if the e-mail were to claim to be from someone other than this third party (such as if it claimed to be from the actual servicer of an indivdual's student loan(s)), that might make it cross the line into "this is a phish" territory.</description>
		<content:encoded><![CDATA[<p>I wonder if more context might help in a situation like this - what did the e-mail that the link was contained in look like?  You&#8217;ve said you might be providing this information in past postings, and this would be a case that I think argues for it.  If the e-mail is consistent with the URL itself and the web site, then I&#8217;d agree (and in fact that confirms what I voted), not a phish.  But if the e-mail were to claim to be from someone other than this third party (such as if it claimed to be from the actual servicer of an indivdual&#8217;s student loan(s)), that might make it cross the line into &#8220;this is a phish&#8221; territory.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
