<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Fundraising Widgets = Possible Phishing Attack</title>
	<atom:link href="http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack/feed" rel="self" type="application/rss+xml" />
	<link>http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=fundraising-widgets-possible-phishing-attack</link>
	<description>Confessions of a Non-Profit Executive Director</description>
	<lastBuildDate>Sat, 28 Jan 2012 12:36:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Idealware</title>
		<link>http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack/comment-page-1#comment-100862</link>
		<dc:creator>Idealware</dc:creator>
		<pubDate>Wed, 17 Mar 2010 04:44:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack#comment-100862</guid>
		<description>&lt;strong&gt;Resource Roundup 1/10...&lt;/strong&gt;

Technological Solutions for Progressive Organizations (Development Seed Blog)A detailed overview of an interesting open source project - the infrastructure (in Drupal) to allow groups to jointly aggregate news and articles of common interest, organize ...</description>
		<content:encoded><![CDATA[<p><strong>Resource Roundup 1/10&#8230;</strong></p>
<p>Technological Solutions for Progressive Organizations (Development Seed Blog)A detailed overview of an interesting open source project &#8211; the infrastructure (in Drupal) to allow groups to jointly aggregate news and articles of common interest, organize &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rachel</title>
		<link>http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack/comment-page-1#comment-100594</link>
		<dc:creator>Rachel</dc:creator>
		<pubDate>Fri, 11 Sep 2009 22:47:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack#comment-100594</guid>
		<description>Hi Ryan, 
Can you say more about how that could be done? 
Rachel </description>
		<content:encoded><![CDATA[<p>Hi Ryan,<br />
Can you say more about how that could be done?<br />
Rachel</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abenamer</title>
		<link>http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack/comment-page-1#comment-1520</link>
		<dc:creator>abenamer</dc:creator>
		<pubDate>Sun, 24 Dec 2006 17:48:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack#comment-1520</guid>
		<description>Agreed. It is still possible to create a fake site as part of your phishing campaign. The problem here is that people (including myself) immediately assume that these widgets are somehow safe despite the fact that they&#039;re hosted on other people&#039;s websites. So... the normal assumptions associated with fake phishing sites no longer apply. This is not a good thing. People will have to add yet another weapon to their phishing detection arsenal.</description>
		<content:encoded><![CDATA[<p>Agreed. It is still possible to create a fake site as part of your phishing campaign. The problem here is that people (including myself) immediately assume that these widgets are somehow safe despite the fact that they&#8217;re hosted on other people&#8217;s websites. So&#8230; the normal assumptions associated with fake phishing sites no longer apply. This is not a good thing. People will have to add yet another weapon to their phishing detection arsenal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Ozimek</title>
		<link>http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack/comment-page-1#comment-1514</link>
		<dc:creator>Ryan Ozimek</dc:creator>
		<pubDate>Sun, 24 Dec 2006 16:09:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/fundraising-widgets-possible-phishing-attack#comment-1514</guid>
		<description>Great points, but I wonder if it&#039;s the widgets themselves that are the issue here.  Seems like even in a time long ago, pre-widget era (somewhere between Web 1.0 and Web 2.0) you could make basic HTML Web pages that looked just like that of an official non-profit, and run your phising campaign.

It seems to me that what could really be used here is a &quot;Verified by XXX&quot; icon, dynamically generated on donation pages, much like those Verisign buttons you get when you go to make a payment on an SSL page verified by Verisign.  That way, no matter if someone is coming from a widget or a full Web site, when they land on the donation processing page they can be assured that the organization is legit.

Best,
Ryan</description>
		<content:encoded><![CDATA[<p>Great points, but I wonder if it&#8217;s the widgets themselves that are the issue here.  Seems like even in a time long ago, pre-widget era (somewhere between Web 1.0 and Web 2.0) you could make basic HTML Web pages that looked just like that of an official non-profit, and run your phising campaign.</p>
<p>It seems to me that what could really be used here is a &#8220;Verified by XXX&#8221; icon, dynamically generated on donation pages, much like those Verisign buttons you get when you go to make a payment on an SSL page verified by Verisign.  That way, no matter if someone is coming from a widget or a full Web site, when they land on the donation processing page they can be assured that the organization is legit.</p>
<p>Best,<br />
Ryan</p>
]]></content:encoded>
	</item>
</channel>
</rss>

