Quote:
Originally Posted by AlexanderHanff
Good job, did you read the paragraph I added to the end of my previous post. I added it after you quoted it so I just want to make sure you have seen it.
Actually, saying that, even if personal data given to third parties was protected under the constitution, I can't see even that would help a non US citizen, since the constitution would not apply afaik.
Alexander Hanff
|
I think I'll steer clear of the US Constitution if you don't mind and just stick to good old Magna Carta ;-)
---------- Post added at 21:44 ---------- Previous post was at 21:23 ----------
Quote:
Originally Posted by SelfProtection
Surely running any of the Trials through the BT Network & effectively performing the Trial(s) would automatically make them responsible for properly securing their Own Customers Data as the DPA currently stands!
|
That page purports to be a BT page. It bears the BT logo. It uses the BT page design and layout. It has identical links in the footer. It is the site that BT are sending customers to when they want information about webwise.
And of course it is identical to the BT hosted mirror BT Webwise site they put up when I asked them to at
http://www.productsandservices.bt.co...=CON-WEBWISE-I
A good question from a non BT enquirer could be to innocently ask what is the difference between
www.webwise.bt.com
and
http://www.productsandservices.bt.co...=CON-WEBWISE-I
and why the Contact page on the BT mirror leads to a different destination to the Contact Page on the
www.webwise.bt.com site even though they are otherwise identical
Contact Us link on webwise.bt.com - goes to webwise.bt.com/contactus.php which is a data collection form with only one option
Contact Us link on BT Webwise mirror site - goes to
http://www.productsandservices.bt.com/contactus
which is a quite different page offering a variety of normal BT departments for contact.
The data collection page asks for personal BT account inormation as well as other personally identifiable information and likewise does not make it clear that it is not a BT page. The mysterious message suggesting that you contact your ISP "direct" cos it's quicker is unexplained and doesn't make any sense to the innocent and ininphormed.
Nowhere is it made clear that it is anything other than a bona fide BT page.
I wonder whether the anti-phishing feature of BT Webwise will identify webwise.bt.com as a phishing site?
I think this one could be VERY interesting!!!
(Fondly imagines a few more BT execs hitting forehead and going Doh!)
---------- Post added at 21:55 ---------- Previous post was at 21:44 ----------
Sent to Emma Sanderson
Greetings.
Just to let you know that there a number of reports now on the web of a new phishing site.
This site purports to be that of a major ISP, and includes a contactus.php page which collects personal data, including the account number for the customer's phone bill.
The site uses the ISP parent company logo and is identical to the layout of normal ISP pages.
The contact page for the phishing site does not produce the same result as the contact page for the genuine page hosted by the ISP itself.
Investigation using WHOIS sites, and reverse lookups, has revealed that the pages and the domain that they are on, are in fact registered not to that ISP, and not hosted by that ISP. These pages are some of them hosted by FASTHIOSTS in Gloucester, some by Gryon, and some over in the USA by THEPLANET.COM
This phishing site is therefore collecting personal data from a UK ISP customer base, including customers phone account reference numbers, and sending it outside the EU.
Please add this site to the list of sites that your new Webwise antiphishing facility will warn us about.
You may already be aware of this site, which is starting to turn up on phishing alert lists all over the internet. Many people are reporting it, via google, firefox, IE7 and other antiphishing lists.
It is of course
http://webwise.bt.com as well as
www.webwise.bt.com
I am sending in a full report to the ICO about this site and obviously hope they take action immediately and appoint a case officer.
Can you get this site shut down?
Unless I hear to the contrary any reply to this email may be published on the internet.