Users of older browsers will not be able to use PayPal

Paypal to block older browsers

Plans to improve security include banning outdated browsers

Written by Dinah Greek

Paypal plans to block older versions of popular browsers such as Internet Explorer as part of a wide range of measures to combat phishing.

Initially users of browser such as Internet Explorer (IE) 3 and IE4 will receive a warning message when they try to use Paypal. However later on the payment provider said it plans to block customers using those browsers it deems the most unsafe from using its site.

These browsers, the oldest of which was released nearly 10 years ago, lack some of the safety features of later browsers. Also flaws in the code that can be exploited by cybercriminals are not addressed with updates.

“In our view, letting users view the Paypal site on one of these browsers is equal to a car manufacturer allowing drivers to buy one of their vehicles without seatbelts.

"The alarming fact is that there is a significant set of users who use very old and vulnerable browsers, such as Microsoft’s IE 4 or even IE 3. We argue that it’s critical to not only warn users about unsafe browsers, but also to disallow older and insecure browsers.

"At Paypal, we are in the process of re-implementing controls which will first warn our customers when logging in to Paypal from those browsers that we consider unsafe. Later, we plan on blocking customers from accessing the site from the most unsafe – usually the oldest – browsers"

The steps were outlined in a white paper, A Practical Approach to Managing Phishing, written by the firm's chief information security officer Michael Barrett and Dan Levy, director of risk management.

It described how Paypal is also supporting the use of Extended Validation SS L certificates, which were introduced a few months ago. These give consumers more confidence they are visiting a bona fide company’s site.

The latest versions of IE and Firefox support these certificates by turning the address bar green when the site visited is legitimate. They also display the company name and the certificate authority name. However Apple’s Safari browser for Mac and PCs does not.

The company said that there was “no silver bullet” for the problem of cybercrime but if the industry adopted multiple layers of defence they can make a huge difference.

“We have not identified any one solution that will single-handedly eradicate phishing; nor do we believe one will ever exist. Instead, our approach relies on a holistic 'defence in depth' model.

"In this approach, there are multiple layers of defence – while no single layer can defeat phishing on its own, in tandem they can make a huge difference, with each layer shaving off some percentage of crime that otherwise would have occurred."

See also:

reader comments

related articles

PC help: New Paypal phishing scam?

Never part with your personal details when contacted via email 11 Jan 2008

 

More time to check your cheque

New rules on cheque clearance reduce prospect of fraud 27 Nov 2007

PayPal fixes phishing flaw

Online payment service changes code to block phishing attack 19 Jun 2006

Phishers target PayPal and Ebay users the most

Criminals main phishing menu goes for eBay and PayPal users 27 Jul 2006

PayPal to block old browsers

Payment service will warn and block old browsers as part of attempts to stop phishing attacks 21 Apr 2008

IT security teams must cooperate to defeat threats

Symantec report highlights the convergence of attack methods 17 Sep 2007

TechEd 2007: Security should be taught in schools

More user education and better collaboration needed to beat online threats 14 Nov 2007

latest news

Resellers hit by delivery disruption as Amtrak fails

UK courier company Amtrak has entered receivership due to financial difficulty 29 Aug 2008

Dell’s profits plunge 17 per cent

PC vendor's net profit takes a tumble as turf war with HP in EMEA hurts bottom line 29 Aug 2008

Avnet upgrades and expands Bracknell demo centre

Distributor refurbishes five-year-old centre to provide vastly expanded proof-of-concept opportunities 29 Aug 2008

poll

A new Linksys era?

A new Linksys era?

Will the Linksys brand fizzle out when Cisco folds it into its SME operation?

Previous poll results

In The Studio With CRN: Josh Claman, Dell

In an editorial coup for CRN, Josh Claman, vice president of EMEA channels at Dell, talks to CRN TV about the vendor's channel plans

CRN Fight Night bouts are LIVE!

ALL the bouts from CRN's first ever white collar boxing event at The Brewery in Chiswell Street, are now online in their full glory for CRN readers to watch.

events

CRN Golf Challenge 2008

CRN Channel Golf Challenge 2008

CRN's annual golfing day will this year be held on 16 September at a championship course in East Sussex

CRN Reseller Leadership Forum logo

CRN Reseller Leadership Forum

An exclusive channel conference from CRN, to be held over one action-packed day in September 2008

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories