Archive for September 16th, 2007

How NOT to Warn Your Customers About Phishing

Sunday, September 16th, 2007

Sometimes I’m amazed at how poorly big companies can be at executing upon the simplest things. Future Shop, a big-box retail chain in Canada, sent out an email on the 13th warning customers about an email phishing attempt. That’s nice of them, but they violated one very important rule that all companies should follow when they warn customers about phishing attempts: they made their email look like a phishing email. The small thing was the lack of a FROM name - the email came in with no information about who it was from. The bigger thing was the URLs they were using for linking. Check out the screen shot below:

futureshop-phising-email.png

The easiest way to determine if something is a phishing attempt is to look at what URL the links are going to send you to - if it’s anything other than the companyname.com, you should be slightly concerned. When you mouse over an URL that’s typed out as www.futureshop.ca, you should see an URL that says www.futureshop.ca. When I looked at this, I thought to myself “What the heck is DCM5.com?” That’s sure not Futureshop.ca! The length of the URL was also raising a red flag - it was linking to an unknown domain, sure, but it also looked like it was linking to a script that would do something. I tried going to DCM5.com in my browser to take a peek, but it didn’t load, which is also suspicious.

Eventually I just clicked on one of the links, trusting in Firefox and Vista to protect me from anything seriously bad happening, and wouldn’t you know, it ended up taking me to a legitimate Futureshop.ca page about phishing. I suspect the DCM5.com URL is some sort of click-tracking service, but guess what: when you’re emailing your customers about an issue of security, tracking their clicks should be the last thing on your list.

I’m Not in Hawk Nelson. Seriously.

Sunday, September 16th, 2007

It seems like it’s once again time for me to explain again on this blog that I’m not the Jason Dunn from Hawk Nelson. Below is an email exchange I had with someone this week. She (and it seems to be a “she” 95% of the time, and probably age 15 or under) had subscribed to my RSS to email feed (the box in the upper right corner) and saw my post about the Heroes disc two locking up where I said the words “my wife”. She then emailed me back expressing her shock that I was married. The screen shot below explains the rest.

this-is-getting-stupid.png

I suppose by now I shouldn’t be surprised by these types of messages, but I swear when I was 15 years old I was smart enough to realize that are “regular” people in the world that have the same names as the famous people, and when someone becomes famous the rest of the non-famous people in the world with the same name aren’t required to go to a lawyer and get their name changed. I also think that at age 15 I could read and understand what I was reading.

I couldn’t even respond back to this girl a second time because every response I wrote ended up sounding mean. I shielded her identity in the screen shot above, and unsubscribed her from my email feed, but I swear this is much less funny as it was a year ago. ;-)