How Can SSL Certificates Keep You Safe From Phishing and Pharming
SSL Certificates help against Phishing and Pharming
Phishing and, recently, pharming pose constant threats to Internet users whose sensitive information is under siege by crackers and other cyber crooks. An SSL certificate from PerformanceHost.net can clip the wings of Internet criminals and help prevent Internet users from being victimized by phishing and pharming schemes when attempting to visit your Web site.
Phishing schemes – attempts to steal and exploit sensitive personal information – typically try to trick victims into accessing fraudulent sites that pose as legitimate, trusted entities, such as online businesses and banks. Because perpetrators of such attacks will be using and registering domains that resemble those of the spoofed sites, PerformanceHost.net, through its stringent fraud-prevention measures, will detect the schemes and deny certificate requests for suspicious domains.
More sophisticated than phishing, pharming revolves around the concept of hijacking an Internet Service provider’s (ISP) domain name server (DNS) entries. When a “pharmer” succeeds in such DNS “poisoning” every
computer using that ISP for Internet access is directed to the wrong site when the user types in a URL (e.g., www.ebay.com).
SSL certificate technology can help prevent pharming attacks, as well. In essence, a “pharmer” simply will not be able to obtain an SSL certificate from PerformanceHost.net, as he/she does not control the domain for which the certificate is requested.
By protecting your Web site with a PerformanceHost.net SSL certificate Internet users that attempt to access a site that poses as yours will be instantly alerted that there is a problem with the supposedly secure connection:
- No lock icon: Because CAs usually won’t issue a certificate to fraudulent phishing or pharming sites, such sites usually do not use SSL encryption. Internet users, therefore, are alerted by the absence of a padlock icon in their browser’s status bar.
- Name mismatch error: A pharming site could try to use a certificate issued by a CA for a domain owned by the attacker, but the user’s browser will warn the user that the visited URL does not match the certificate presented by the fake Web server.
- Untrusted CA: A pharming site might attempt to use a certificate issued by an untrusted CA. In this case, the user’s browser will generate the following warning: “the security certificate was issued by a company you have not chosen to trust.”
The alert Internet user will instantly abandon his/her activities/transactions when presented with such warnings. Thus, a PerformanceHost.net SSL certificate provides business owners and wary, savvy Internet users with an effective weapon against phishing, pharming and similar cyber swindles.