PayPal advises Mac users not to use Safari

“PayPal is warning users that they are better off using an alternative if they want to avoid fraud,” Julio Franco reports for TechSpot.

“Now, this doesn’t necessarily mean Safari is a bad option, not even an insecure browser, but in the eyes of PayPal it is lacking two important anti-phishing security features that ‘Internet Explorer 7 or 8 when it comes out, Firefox 2 or Firefox 3, and indeed Opera’ already pack in. The two features mentioned by Michael Barrett, PayPal’s chief information security officer, are a built-in phishing filter and an anti-phishing technology, called Extended Validation certificates,” Franco reports.

“PayPal happens to be in a very unique position for making an educated assessment regarding web security, but we don’t see either of those two technologies making miracles for saving users from fraudsters,” Franco reports. “At the end of the day, there is no better anti-phishing filter than yourself, being aware that scammers are out there and they are trying to get you.”

Full article here.

[Thanks to MacDailyNews Reader “Ampar” for the heads up.]

38 Comments

  1. Yes, Safari doesn’t have anti fishing filters and that is why I use it. The only anti fishing filter that works is the user. Everyone what to create software to protect the user for the user’s own stupidity.
    I say let the stupid learn the hard way, it’s called tough love. The ones that never learn the lessons, they really should be using the internet in the first place or their banks and Credit card companies should just not let them have to their account information or even access to spend anything on-line at all.

  2. An anti-phishing filter should be something very similar to the pop-up blocker on Safari. Shift-Cmd-K toggles it on or off when needed. Clearly, Apple can make a very smooth and elegant solution to this, which would be intuitive and unobtrusive to users, and provide the type of safety blanket that ignorant users (and with expanding Mac user base, greater and greater numbers of them) need very much.

    Telling us to point our DNS to openDNS is redundant. Those of us who are skilled enough to actually do it (practically everyone reading MDN) will never fall for a phishing lure.

    On that subject, I must say, I always click on those phishing links. Out of curiosity, I go to the root of the web server masquerading as a bank, ebay, paypal, etc. Oftentimes, it is an unsuspecting website for crocheting patterns, or some Guatemalan hiking, or some small, semi-amateur work where password was hacked and phisher’s site uploaded. I usually try to notify the site owner that they had been hacked. It doesn’t help much, though, since these phishing sites need no more than two days to stay up to collect what they’re looking for.

    Anyway, back on the subject; next rev of Safari will have to have a phishing filter.

  3. I’m a Mac user and I depend on PayPal for my income. There has never been a more-frustrating experience! But it is very difficult or impossible these days for a webmaster based outside the US, to get an account with a payment gateway. I’m trying very hard to set up an opposition company that will take its customers seriously and provide a professional service but potential investors don’t understand the situation and are unwilling to commit. So far! In the meantime, I recommend no one take seriously anything that PayPal says.

  4. I’ve read that PayPal owns the company that issues the EV Certs. Very self-serving announcement about Safari. Looks like their form of coercion: “We’re going to issue scary press releases about Safari, Apple, until you pay us some dough for one of certifications.”

  5. Don’t answer the fricken emails you get asking for your password.

    I use Paypal all the time and have never had one problem. I do get those phishing emails and just report them to “Spoof@paypal.com”.

    Am I missing something? Isn’t it just about engaging the brain a bit?

  6. So many people here on their high horse! Solutions like “Don’t use PayPal!” or, “Never click on links” are obviously never going to work. PayPal is the most popular money transfer site in the world for a good reason. They are cheap (as in: free for most users), they allow you what no other service does (instantly send money between two persons without highway robbery-type charges like Western Union or MoneyGram) and have presence in about 140 countries (out of 192 official UN members). You may choose not to use it, but there is a huge number of people who do and will continue.

    Same goes for people who don’t know what is phishing. If you have never heard of it, you can easily fall for the lure. While EV certification may be dubious, Apple can easily implement their own filtering solution and build it in. They should.

    As for iPhone, PayPal works on it (as well as eBay). As a matter of fact, PayPal has mobile site that works even with crappy WAP browsers on all other cellphones.

  7. The last time I used Paypal Safari wouldn’t work anyway so I had no choice but to use Firefox to complete the transaction. As the default browser on Macs, Apple needs to be much more active at keeping it up to date. The folks at Mozilla are doing a great job with Firefox, why can’t Apple keep up with Safari?

  8. I use Safari mostly out of habit — when I engage my brain I use Firefox. The anti-phishing pheature is nice but the coolest feature for me is its ability to return you to where you were before an OS crash which was a frequent event with Leopard 10.5.1.

  9. Does AllofMP3 and other Mafia-like orgs have a presence around the world too?
    Do I smell straw?

    Does the glorious view from your turret preoccupy you so, as to not notice the thousands of un-satisfied PP users — south of the tip of your nose?

    Which Phishing lures not to buy?
    Is an uninformed person, STUPID? Or, are they uninformed?
    Why not shake down a box or two of educational pellets?

  10. Hey ReD GRAPE,

    Did you ever use allofmp3.com? No, you’re just spouting IFPI/RIAA propaganda. I happily used the service for over two years and never had a problem, never lost a cent and on the occasion that I got damaged tracks they replaced them within 24 hours. In fact I’d argue that the service was actually superior to to Apple’s iTunes Store.

    Likewise, before you or others start up the “starving musicians’ story” 15 percent of allofmp3 sales were there for the IFPI to claim on behalf of the record companies. They never did make a claim because that would legitimise allofmp3, but it also meant they didn’t pass on the remittances to musicians

    ReD GRAPE, perhaps you stay off the grape before you start spouting BS. And for the record my spam levels never increased using allofmp3, just paypal!

  11. Just say no…,

    ReD GRAPE is an anagram. Well, almost ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

    Just because it’s not illegal for you to use a service, doesn’t mean it’s not run by a criminal organisation. [wink, wink, MS, nudge, nudge] If you feel confident giving your Visa number to AoM, good for you.

    BTW, where was the money for the IFPI held? Where did the RIAA have to get the cheque/check from? Do you really believe that the artists got 15% of each 10¢ per song that AoM sold? And, why would an org like AoM need to be ‘legitimised’, if they weren’t already? Why would an org like the RIAA be the ones to do so? Just because the RIAA are frauds, doesn’t mean AoM are ethical. Or, that they’re your friends. Two wrongs…

    As for your accusation that I’m an RIAA shill. Well, hardly. But, I understand your use of redirection?

    WRT what I actually wrote about, thanks for not addressing those ideas. And instead getting your knickers in a bunch because it took you more than 700 days to feel any misgivings with your association with AoM. Are you truly under some warped delusion that I could give a flying-fsck where you do business?

    “Hey-buddy-these-mp3s-fell-off-the-back-of-a-truck-and-I-can-let-them-go-for-cheap!”

    Anyway, I’m sorry that you got upset, but my post was in regards to PayPal. Your ravings are non-sequitor.

  12. When you address the issues I raised then I’ll make another reply to your logic. Thus far I don’t know WTF you’re on except that I don’t want any of it. My questions are:

    1. Why didn’t the IFPI take the money given to ROMS by allofmp3?
    2. Can you prove that allofmp3 are a criminal organisation when there have been no convictions under Russian law? You can allege criminality but nothing more than that.

  13. YOU go on about an off topic.

    YOU accuse me of being drunk or on drugs. — very weak

    My 1st post barely mentioned AoM. Look up the word: rhetorical.

    YOU made it an defendable issue. A raving non-sequitor.

    YOU demand that I answer your questions. Uh, after me — you’re first.

    Again, I could give a flying-fsck where you do business?

    Don’t bother to reply. I’ll ignore you, as I should have your first post.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.