Latest in Gear

Image credit:

Half of phishing sites trick you into thinking they're 'secure'

You can't assume the padlock means a site is legitimate.
Jon Fingas, @jonfingas
November 26, 2018
Share
Tweet
Share

Sponsored Links

inga via Getty Images

You can't assume that a site is honest because it has that "secure" padlock in the address bar, and PhishLabs just illustrated why. The anti-phishing company has determined that 49 percent of all known phishing sites used Secure Sockets Layer protection (and thus displayed the padlock) as of the third quarter of 2018. That's a sharp rise from 35 percent in the second quarter, and a steep climb from 25 percent a year earlier. They'll still try to trick you into handing over vital details -- it's just that their web traffic will be encrypted while they do it.

PhishLabs' John LaCour links the sharp rise to both the attackers themselves and their response to software decisions. Many phishers are buying web domains and promptly creating SSL certificates for them. And while Google was helpful when it started warning Chrome users about non-secure sites, that likely prompted phishers to secure their sites in an attempt to avoid those alerts.

To some extent, browser developers are tackling the issue by blocking known phishing sites regardless of whether or not they use encryption. They can't catch every site, though. To some extent, the best defense against the rise of 'secure' phishing sites is simply to dispel assumptions. You want to always question the legitimacy of unexpected requests for your sign-ins and personal info, even if they appear authentic on the surface.

In this article: gear, https, internet, phishing, scam, security, ssl
All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.
Comment
Comments
Share
Tweet
Share

Popular on Engadget

The 2020 Engadget Holiday Gift Guide

The 2020 Engadget Holiday Gift Guide

View
The best Cyber Monday tech deals that are worth your money

The best Cyber Monday tech deals that are worth your money

View
Scientists might know why astronauts develop health problems in space

Scientists might know why astronauts develop health problems in space

View
Toyota's second-generation Mirai has a 400-mile range

Toyota's second-generation Mirai has a 400-mile range

View
Sonos One drops to $150 for Cyber Monday

Sonos One drops to $150 for Cyber Monday

View

From around the web

Page 1Page 1ear iconeye iconFill 23text filevr