26-05-2005, 10:49
|
#1
|
Apprentice Geriatric
Join Date: Jan 2004
Location: Darwen, Lancashire
Posts: 3,706
Liked: 0 times
Rep Power: 88
|
StormPay
We all KNOW that on-line payment processors DO NOT send their clients emails except in response to an enquiry. StormPay has broken that mould.
Dear StormPay admin,
I received an email (subject - StormPay.com - Did you know? 05/25/2005) today that allegedly comes from StormPay. I say allegedly because it appears to be genuine but we all know that appearances can be deceptive. If it is not genuine then someone is trying their luck, not with this email but trying to establish that similar emails from StormPay are genuine and these will be the phishers.
However we customers or clients of on-line payment processors like StormPay, PayPal, E-Gold etc KNOW that on-line payment processors DO NOT send their clients emails except in response to an enquiry. So if we receive an email that appears to come from an on-line payment processor we KNOW straight away that it is a fake regardless of how genuine it may appear – and some do.
If the email is genuine you have opened the door for would be phishers to exploit it for their own purposes because now that an on-line payment processor sends emails to their clients, the fake one could and probably will be indistinguishable from the genuine – for most people.
If StormPay has got regular news for their clients it would probably have been better to do it this way.
When a bona fide client of StormPay logs in successfully, instead of being taken to the client’s Account Page they would be taken to a page that displays the latest newsletter. Then after a suitable delay (say one minute) they could proceed to do their business on StormPay, either automatically, or by clicking a button at the bottom of the page and maybe also having to input a different password to the one that they used to log in with. A one minute delay would ensure that at least part of the news letter would be scanned and StormPay would maintain the “We do not send emails to our clients” ethic.
We the clients could then confidently ignore any emails that claim to be sent by StormPay and thus not put our accounts in jeopardy.
|
|
|