Monday, November 16, 2009

Are lovehappens.com and tagged.com doing such kinds of phising?

I got mails from my friends who invite me to join lovehappens.com and tagged.com. But, when i tried to register, i'm asked to fill my yahoo id and password. Was it kind of phising activity? I haven't filled it yet, but i feel pity to my friends who have. Help me please!

Are lovehappens.com and tagged.com doing such kinds of phising?
It could be phishing, it may not. In these cases, in all likeliness, no.





First, let's clarify our definition of "phishing." Phishing is generally a way for con artists to find out a user's password, credit card information, or other personal information. They pose as a legimate site or trusted third party. For example, I might put up a site at ebau.com and make my site look like ebay.com. When a user who has made a typo and isn't paying attention, they'll "give" me their password which I can use malicously.





So, the question is, what are lovehappens and tagged doing with your password? The same thing that myspace (i think) and a few other big sites (can't remember off the top of my head) are doing: using your login to fetch your address book to make it easy to send invites to your friends.





back in the day, a website would prompt: "Enter the e-mail addresses of friends and we'll tell them about this website." That would involve typing or copying and pasting e-mail addresses. Today, you tell them your e-mail account password, they'll go to your address book at your e-mail account and show you "Here are the addresses in your address book. click the checkbox next to the friends you would like us to tell about this website."





Giving them your login constituted agreeing to let them fetch your address book. Storing your password and using it beyond fetching your address book (essentially phishing) would definately be beyond what you've agreed to let them do and unethical if not illegal.





A legitimate company, especially one that's public and owned by a respected company (LoveHappens is owned by Monster, don't know about Tagged) you should be able to give trust in to not use your login for out-of-agreement purposes.


No comments:

Post a Comment