<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Users are &#8217;stupid&#8217; - Microsoft</title>
	<atom:link href="http://www.tomrafteryit.net/users-are-stupid-microsoft/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/</link>
	<description>Tom Raftery, social media consultant, speaker, blogger and podcaster</description>
	<pubDate>Tue, 02 Dec 2008 11:20:08 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Mark Dowling</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7332</link>
		<dc:creator>Mark Dowling</dc:creator>
		<pubDate>Wed, 05 Apr 2006 17:46:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7332</guid>
		<description>When &lt;a href="http://en.wikipedia.org/wiki/Kevin_Mitnick"&gt;Kevin Mitnick&lt;/a&gt; was hacking Vegas telephone exchanges, all he had to do was call someone, pretend to be IT or a supplier or someone and ask for passwords.  No-one ever thought to say, "I don't know you, can I have some verification/call you back on the IT number".

No phishing or zipping or whatever, just "social engineering" which is a nice way of saying "taking advantage of people who aren't security conscious" or, well, just plain stupid.</description>
		<content:encoded><![CDATA[<p>When <a href="http://en.wikipedia.org/wiki/Kevin_Mitnick">Kevin Mitnick</a> was hacking Vegas telephone exchanges, all he had to do was call someone, pretend to be IT or a supplier or someone and ask for passwords.  No-one ever thought to say, &#8220;I don&#8217;t know you, can I have some verification/call you back on the IT number&#8221;.</p>
<p>No phishing or zipping or whatever, just &#8220;social engineering&#8221; which is a nice way of saying &#8220;taking advantage of people who aren&#8217;t security conscious&#8221; or, well, just plain stupid.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian Delahunty</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7330</link>
		<dc:creator>Brian Delahunty</dc:creator>
		<pubDate>Wed, 05 Apr 2006 14:34:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7330</guid>
		<description>&lt;em&gt;I am not a developer so I donâ€™t personally have any solution to this - however, there are a series of toolbars listed on the Anti-Phishing.org website which do a good job - also, there is IE7â€™s anti-phishing capabilities to look forward to.

So software can make a good stab at minimising this problem Brian. &lt;/em&gt;

Yes. Plenty of solutions out there that help - but at the end of the day it's up to the user. As with most bad and "evil" things these days I think education is the key - educating people though is a challenge.

But, just to put your quote "the software which is stupid and not the user" into perspective - recently there was a *lovely* virus going around via email. The virus was an executable contained inside a password protected zip file - virus scanners can not scan inside password protected zip files as everything is encrypted. The user however could read the password from the email, open the zip file, and run the exe. Was the software stupid - most definitely not. Was the user - well I suppose that depends on your point of view.

It's almost impossible to write software to protect people when people still insist on doing silly things like above - once again, educating users is the key, but in the case above, whose responsibility is it to education the user? The company providing the email service to the user? The producer of their email client? The anti-virus company? The producer of the operating system? ... the government?

It's the same with phishing and anti-phishing software - it can help, but no one should rely on it 100%. If a person does, sooner or later they will be stung.</description>
		<content:encoded><![CDATA[<p><em>I am not a developer so I donâ€™t personally have any solution to this - however, there are a series of toolbars listed on the Anti-Phishing.org website which do a good job - also, there is IE7â€™s anti-phishing capabilities to look forward to.</p>
<p>So software can make a good stab at minimising this problem Brian. </em></p>
<p>Yes. Plenty of solutions out there that help - but at the end of the day it&#8217;s up to the user. As with most bad and &#8220;evil&#8221; things these days I think education is the key - educating people though is a challenge.</p>
<p>But, just to put your quote &#8220;the software which is stupid and not the user&#8221; into perspective - recently there was a *lovely* virus going around via email. The virus was an executable contained inside a password protected zip file - virus scanners can not scan inside password protected zip files as everything is encrypted. The user however could read the password from the email, open the zip file, and run the exe. Was the software stupid - most definitely not. Was the user - well I suppose that depends on your point of view.</p>
<p>It&#8217;s almost impossible to write software to protect people when people still insist on doing silly things like above - once again, educating users is the key, but in the case above, whose responsibility is it to education the user? The company providing the email service to the user? The producer of their email client? The anti-virus company? The producer of the operating system? &#8230; the government?</p>
<p>It&#8217;s the same with phishing and anti-phishing software - it can help, but no one should rely on it 100%. If a person does, sooner or later they will be stung.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7329</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Wed, 05 Apr 2006 14:22:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7329</guid>
		<description>&lt;a href="http://blogs.linux.ie/stuff/2005/12/16/nifty-technology-vmware-browser-applicance/"&gt;Virtual Appliances anyone?&lt;/a&gt;

If you can't make the software smarter, come up with ways to use it smarter.</description>
		<content:encoded><![CDATA[<p><a href="http://blogs.linux.ie/stuff/2005/12/16/nifty-technology-vmware-browser-applicance/">Virtual Appliances anyone?</a></p>
<p>If you can&#8217;t make the software smarter, come up with ways to use it smarter.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom Raftery</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7328</link>
		<dc:creator>Tom Raftery</dc:creator>
		<pubDate>Wed, 05 Apr 2006 14:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7328</guid>
		<description>@Larkin - agreed absolutely.

@Brian
&lt;blockquote&gt;If you think that it is easy or possible for software to be this intelligent at the moment Tom then why canâ€™t we please see your solution.&lt;/blockquote&gt;
I am not a developer so I don't personally have any solution to this - however, there are a series of &lt;a href="http://www.antiphishing.org/solutions.html#toolbars"&gt;toolbars listed on the Anti-Phishing.org&lt;/a&gt; website which do a good job - also, there is IE7's anti-phishing capabilities to look forward to.

So software can make a good stab at minimising this problem Brian.</description>
		<content:encoded><![CDATA[<p>@Larkin - agreed absolutely.</p>
<p>@Brian</p>
<blockquote><p>If you think that it is easy or possible for software to be this intelligent at the moment Tom then why canâ€™t we please see your solution.</p></blockquote>
<p>I am not a developer so I don&#8217;t personally have any solution to this - however, there are a series of <a href="http://www.antiphishing.org/solutions.html#toolbars">toolbars listed on the Anti-Phishing.org</a> website which do a good job - also, there is IE7&#8217;s anti-phishing capabilities to look forward to.</p>
<p>So software can make a good stab at minimising this problem Brian.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian Delahunty</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7327</link>
		<dc:creator>Brian Delahunty</dc:creator>
		<pubDate>Wed, 05 Apr 2006 13:13:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7327</guid>
		<description>&lt;em&gt;Personally, I believe that if the software allows people to be fooled into clicking on a phishing link (and some of the phishing emails I have received have been extremely convincing), then it is the software which is stupid and not the user.&lt;/em&gt;

And what would you suggest be done? Software is dumb. It always has been and will most definitely be for the foreseeable future. All a computer or piece of software can do is it what it has been programmed to do and it's is extremely difficult to program an intelligent piece of software - hence we don't have true AI.

Sure, there are some excellent pieces of software that use advanced heuristics to find patterns and/or identify and classify items it has never come across before but saying that software is stupid because it allows a user to click on a phising like is fairly stupid.

How is the software to know that it is a phishing link? Sure, heuristics - great - but heuristics are also known "best-guess" solutions - by definition they are not definitive. It IS the user who is stupid - maybe the person was just duped into the click the link, or maybe the person is not aware of these scams, or maybe the phishing is so good that even someone working for the "real" company can be fooled by it but it is still the person that is stupid (read as "unaware" or "lazy" or "just plain stupid").

However, Microsoft and other companies are tackling the problem straight on - the anti-phising features in IE 7 for example are fairly good, but once again they rely on a group or people (Microsoft employees in this case) actually checking reported sites to verify that they are, or are not, phishing sites.

If you think that it is easy or possible for software to be this intelligent at the moment Tom then why can't we please see your solution.

P.S. Love the blog. Keep up the good work - but I had to pull you up on this one. YOU ARE WRONG ;-)</description>
		<content:encoded><![CDATA[<p><em>Personally, I believe that if the software allows people to be fooled into clicking on a phishing link (and some of the phishing emails I have received have been extremely convincing), then it is the software which is stupid and not the user.</em></p>
<p>And what would you suggest be done? Software is dumb. It always has been and will most definitely be for the foreseeable future. All a computer or piece of software can do is it what it has been programmed to do and it&#8217;s is extremely difficult to program an intelligent piece of software - hence we don&#8217;t have true AI.</p>
<p>Sure, there are some excellent pieces of software that use advanced heuristics to find patterns and/or identify and classify items it has never come across before but saying that software is stupid because it allows a user to click on a phising like is fairly stupid.</p>
<p>How is the software to know that it is a phishing link? Sure, heuristics - great - but heuristics are also known &#8220;best-guess&#8221; solutions - by definition they are not definitive. It IS the user who is stupid - maybe the person was just duped into the click the link, or maybe the person is not aware of these scams, or maybe the phishing is so good that even someone working for the &#8220;real&#8221; company can be fooled by it but it is still the person that is stupid (read as &#8220;unaware&#8221; or &#8220;lazy&#8221; or &#8220;just plain stupid&#8221;).</p>
<p>However, Microsoft and other companies are tackling the problem straight on - the anti-phising features in IE 7 for example are fairly good, but once again they rely on a group or people (Microsoft employees in this case) actually checking reported sites to verify that they are, or are not, phishing sites.</p>
<p>If you think that it is easy or possible for software to be this intelligent at the moment Tom then why can&#8217;t we please see your solution.</p>
<p>P.S. Love the blog. Keep up the good work - but I had to pull you up on this one. YOU ARE WRONG <img src='http://www.tomrafteryit.net/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Larkin Cunningham</title>
		<link>http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7326</link>
		<dc:creator>Larkin Cunningham</dc:creator>
		<pubDate>Wed, 05 Apr 2006 13:06:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.tomrafteryit.net/users-are-stupid-microsoft/#comment-7326</guid>
		<description>That was a bit rich calling people who are tricked by phishing as being stupid.
I'm not surprised though because Microsoft have been treating users as idiots for years, e.g. that annoying assistant in Word that asks if you are writing a letter.

You are right, some of those phishing expeditions are very convincing and not everyone has an MSc in security and cryptography. How is a relatively new user supposed to know that banks or ebay or amazon do not ask for your password. I mean, I don't know the first thing about microbiology, but that doesn't make me stupid.

I have to agree that when a computer is infected either by malware or a rootkit, the first course of action should be to disconnect from any network and then reformat the hard drive before re-installing. That holds for all operating systems including windows, linux and mac osx. You just never know how clean your machine is after you attempt to remove the malicious executables. In fact, in many cases it is irresponsible not to reformat because attacks could continue to be launched from your PC or server without a full reformat.</description>
		<content:encoded><![CDATA[<p>That was a bit rich calling people who are tricked by phishing as being stupid.<br />
I&#8217;m not surprised though because Microsoft have been treating users as idiots for years, e.g. that annoying assistant in Word that asks if you are writing a letter.</p>
<p>You are right, some of those phishing expeditions are very convincing and not everyone has an MSc in security and cryptography. How is a relatively new user supposed to know that banks or ebay or amazon do not ask for your password. I mean, I don&#8217;t know the first thing about microbiology, but that doesn&#8217;t make me stupid.</p>
<p>I have to agree that when a computer is infected either by malware or a rootkit, the first course of action should be to disconnect from any network and then reformat the hard drive before re-installing. That holds for all operating systems including windows, linux and mac osx. You just never know how clean your machine is after you attempt to remove the malicious executables. In fact, in many cases it is irresponsible not to reformat because attacks could continue to be launched from your PC or server without a full reformat.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
