<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Iconix Phishing Protection</title>
	<atom:link href="http://www.infosecblog.org/2008/06/iconix-phishing-protection/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecblog.org/2008/06/iconix-phishing-protection/</link>
	<description></description>
	<lastBuildDate>Mon, 06 Feb 2012 07:04:18 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Roger</title>
		<link>http://www.infosecblog.org/2008/06/iconix-phishing-protection/comment-page-1/#comment-271</link>
		<dc:creator>Roger</dc:creator>
		<pubDate>Wed, 11 Jun 2008 17:53:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecblog.org/2008/06/iconix-phishing-protection/#comment-271</guid>
		<description>Thanks for the read.
You&#039;re right, I meant Thunderbird not Firefox, I did see you have support for accessing webmail through Firefox.   I&#039;ll update that.
I understand why you&#039;re doing it the way you are.   I&#039;d love it if you had a &quot;expert&quot; mode for people who do know what spf and domainkeys are for.   I understand that just because its from a authenticated sender (google) that doesn&#039;t mean its not phishing.  Some with your example, the spammers did widely adopt spf first.  That doesn&#039;t mean spf is broken.
I like the product.  I&#039;m using it and will recommend it to others.
</description>
		<content:encoded><![CDATA[<p>Thanks for the read.<br />
You&#8217;re right, I meant Thunderbird not Firefox, I did see you have support for accessing webmail through Firefox.   I&#8217;ll update that.<br />
I understand why you&#8217;re doing it the way you are.   I&#8217;d love it if you had a &#8220;expert&#8221; mode for people who do know what spf and domainkeys are for.   I understand that just because its from a authenticated sender (google) that doesn&#8217;t mean its not phishing.  Some with your example, the spammers did widely adopt spf first.  That doesn&#8217;t mean spf is broken.<br />
I like the product.  I&#8217;m using it and will recommend it to others.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: http://openid.aol.com/audian99</title>
		<link>http://www.infosecblog.org/2008/06/iconix-phishing-protection/comment-page-1/#comment-270</link>
		<dc:creator>http://openid.aol.com/audian99</dc:creator>
		<pubDate>Wed, 11 Jun 2008 16:52:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.infosecblog.org/2008/06/iconix-phishing-protection/#comment-270</guid>
		<description>Hi Roger,
Nice blog, thanks for the write up of Iconix!
Couple of notes:
1. We actually do support Firefox (versions 1.5, 2.0 and soon 3.0). Perhaps you were talking about lack of support for Thunderbird since you mentioned that at the end of your blog as well?
2. We currently mark messages for over 500 companies. The current list of companies intersects a lot of consumerÃ¢â‚¬â„¢s inboxes today. Look to see this list grow by the thousands soon!
3. We chose not to display authentication results alone as that can be deceiving. Bad guys can just as easily authenticate their mail. For instance, a bad guy could register and authenticate the domain www.paypalsecure.com and send email as security@paypalsecure.com and it will pass authentication, because it is actually from that (bad) domain. As a user, you still don&#039;t know if it is actually from the brand PayPal. That is why it is important that we take it a step further and make sure messages are from domains on our list.
By the way - PayPal, eBay and TrendMicro users are always asking for us to add their favorite company. Anyone can submit by going here:  &lt;a href=&quot;http://www.iconix.com/protectsites.php&quot; rel=&quot;nofollow&quot;&gt;http://www.iconix.com/protectsites.php&lt;/a&gt;
Regards,
Audian Paxson
Director, Product Management
ICONIX, Inc.
</description>
		<content:encoded><![CDATA[<p>Hi Roger,<br />
Nice blog, thanks for the write up of Iconix!<br />
Couple of notes:<br />
1. We actually do support Firefox (versions 1.5, 2.0 and soon 3.0). Perhaps you were talking about lack of support for Thunderbird since you mentioned that at the end of your blog as well?<br />
2. We currently mark messages for over 500 companies. The current list of companies intersects a lot of consumerÃ¢â‚¬â„¢s inboxes today. Look to see this list grow by the thousands soon!<br />
3. We chose not to display authentication results alone as that can be deceiving. Bad guys can just as easily authenticate their mail. For instance, a bad guy could register and authenticate the domain <a href="http://www.paypalsecure.com" rel="nofollow">http://www.paypalsecure.com</a> and send email as <a href="mailto:security@paypalsecure.com">security@paypalsecure.com</a> and it will pass authentication, because it is actually from that (bad) domain. As a user, you still don&#8217;t know if it is actually from the brand PayPal. That is why it is important that we take it a step further and make sure messages are from domains on our list.<br />
By the way &#8211; PayPal, eBay and TrendMicro users are always asking for us to add their favorite company. Anyone can submit by going here:  <a href="http://www.iconix.com/protectsites.php" rel="nofollow">http://www.iconix.com/protectsites.php</a><br />
Regards,<br />
Audian Paxson<br />
Director, Product Management<br />
ICONIX, Inc.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

