$bbtitle
AAPL: 189.73 ( 0.00 ) AppleInsider RSS Feed
Search:
AppleInsider.com Archives Reviews Anonymous Mailer Submit Story AppleInsider Forums Polls Advertise on AppleInsider Contact AppleInsider
Friday, April 18, 2008

PayPal may block Safari users

By Aidan Malley

Published: 06:20 PM EST

As part of a multi-tiered approach to guarding against online fraud on its site, PayPal says it will block the use of any web browser that doesn't provided added validation measures, potentially restricting the current version of Safari from the e-commerce site.

The money transfer service's Chief Information Security Officer, Michael Barrett, makes the new policy clear in a white paper (PDF) posted this week, which highlights the browser as a key means of putting an end to phishing (false website) scams alongside such steps as blocking fraudulent e-mail messages and criminal charges.

When addressing web access, Barrett argues that any user visiting a financial site such as PayPal should know not only that their browser will block fake sites meant to steal information, but also that the browser can properly indicate a legitimate site. Without either precaution, visitors may not only be victims of scams but may lose all trust in an otherwise safe business. This doubly harmful outcome is likened to a car crash without protection.

"In our view, letting users view the PayPal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seatbelts," the expert says.

To that end, PayPal is said to be implementing steps that will first provide warnings against, and eventually block, any browser that doesn't meet these criteria.

Most modern web browsers, including Firefox and newer versions of Microsoft's Internet Explorer, are able to support at least basic blocking of phishing sites. The newest, such as Internet Explorer 7 or the upcoming Firefox 3, also support a new feature known as an Extended Validation Secure Socket Layer (EV SSL) certificate. The measure of authenticity turns the address bar green and identifies the company running the site, letting the user know any secure transactions are genuine.

Safari, however, lacks either of these features and so could fall prey to the blocks and warning messages. Barrett doesn't mention the browser by name but notes that any "very old and vulnerable" software would ultimately be blacklisted from the future update to PayPal's service, placing Safari in the same category of dangerous clients as Microsoft's ten-year-old Internet Explorer 4.

Apple's approach to browser security has so far been tentative. The Mac maker has briefly incorporated Google's database of fraudulent sites into a beta builds of Mac OS X Leopard this past fall, only to pull the feature in later test versions. Release builds of the stand-alone browser for both Macs and Windows PCs have also gone without the anti-phishing warnings, but notably leave code traces inside the software that raise the possiblity of improvements through a later update.

Apple hasn't responded to the white paper but is likely to face pressure as PayPal and similar institutions ask for an all-encompassing approach to fighting scams that involves EV SSL and other software techniques. Internet Explorer 7's debut has already had a demonstrated effect on customers, who are more likely to finish signing up for PayPal knowing that the web browser has authenticated the registration page.

"We couldn’t eradicate this problem on our own – to make a dent in phishing, it would take collaboration with the Internet industry, law enforcement, and government around the world," Barrett explains.

Filed under : Mac OS X 45 Comments ] 
Story topics: Safari  [ Tell a Friend ] [ Print ] [ Story Link ] 

$150 rebates on all the new
Penryn-based MacBook Pros
$75-$100 rebates on all the new
Penryn-based MacBooks
$75-$125 rebates on all the new
MacBook Air sub-notebook
$50-$100 rebates on all the most
recent iMac desktops
Mac Poker players can play Full Tilt Poker for Mac and get 100% to $600 free with bonus code MP600, courtesy of Online Poker Mac
AppleInsider Features
Hot Forum Topics

Recent Articles
Orange to offer 3G iPhone in Africa, Mid East, and Europe
WSJ on touch BlackBerry; Intel 4-core; T-Mobile at 100K iPhones
Intel: Apple tablet comment simply untrue
Mac OS X 10.5.3 moving along, on course with iPhone 2.0?
Apple filing places iPhone networks at restaurants, zoos, concerts
Mexican iPhone, iTunes June rumor; Wall Street retail; Boston unveiled
WWDC sold out with over 5,000 attendees
Intel exec vouches for Atom-based Apple Newton tablet - report
AT&T now limiting iPhone sales to one, requiring plastic
O2 fuels 3G iPhone frenzy as Bharti says deal signed for India
AT&T to boost 3G speeds more than fivefold by 2009
Swiss iPhone announcement raises eyebrows given rumors
Swiss iPhone rumor; BlackBerry Thunder; Apple gay-friendly
Microsoft releases Office 2008 SP1, says VBA to make return
Steve Jobs to showcase OS X, iPhone platforms at WWDC
HBO shows arrive on iTunes starting at $1.99 an episode
QuarkXPress 8 to target Adobe's Creative Suite this August
BlackBerry Bold stands as 3G iPhone's chief rival
New Time Machine option in 10.5.3; Boston store opens Thursday
HBO shows coming to iTunes under new pricing structure?
New deals seen tripling Apple's addressable market for iPhone
AT&T now showing "iPhone Black" model in device listing [u]
SingTel to offer iPhone out East; TIM chief says 3G model in June
3G settings discovered in latest beta of iPhone firmware
Online Apple Stores run dry of iPhones
iTunes France TV job; .Mac refresh rumor; NYC shortages return
Apple settlements: Canadian iPod credit, notebook adapter refunds
Job listings hint at multi-carrier iPhone in Australia, Brazil
Briefly: Mac OS X 10.5.3; AT&T iPhone hotspot access; Vista sales
Apple developing 3D gaming controller for Apple TV
O2 says Apple's iPhone "no longer available" [updated x2]
NBC prefers Zune DRM [U]; VMware beta; iMac's 10th birthday
America Movil to sell Apple's next-gen iPhone in Mexico
Briefly: Spain, Poland iPhone talk; iPhone SDK beta 5; AT&T memo
Flash Wars: Adobe Fights for AIR with the Open Screen Project [Part 3 of 3]
NBC at iTunes UK; Caris and Piper outlooks; new '3G iPhone' photo
Apple to begin selling 3G iPhone in late June?
More unofficial Mac clones up for sale on eBay
Flash Wars: The Many Enemies and Obstacles of Flash [Part 2 of 3]
Apple to offer iPhone in Italy through multiple carriers

AppleInsider Market Place

Sell your Laptop - working or not. Free shipping.: Get an instant online quote and sell your laptop today !

Believe in Office: Save Up To 25% on Office 2004 For Mac. Visit Our Site for Details!

IBackup - SMB Online Backup: IBackup is the preferred online storage and backup service of choice for SMBs for its ease of use, security and value. Offers automated backup and restore, file selection and securiy.

Kredit auf Online Kredit Index - Here is some credit information for our German visitors.
Download free software - everyday updated freeware files

 
Advertisements







AppleInsider RSS Feed
AppleInsider © 1997-2008
Please review our Privacy Policy.
Written/Edited/Compiled by the AppleInsider Staff.