Select or Set your Region  
... home / news
Newsflash #22 4th October 2005
Why Secure eMail Billingis Unphishable

'Phishing' is increasingly becoming a topic of conversation, with many companies and organizations feeling vulnerable to this very real security threat. This was overwhelmingly evident to us after various conversations with senior executives at some of the largest banks in North America.

Webopedia defines Phishing as: (fishing) (n.) The act of sending an email to a user, falsely claiming to be an established legitimate enterprise in an attempt to scam the user into surrendering private information that will be used for identity theft.

The email directs the user to visit a website where they are asked to update personal information, such as credit card, social security, and bank account numbers, as well as passwords, which the legitimate organization already has. The website, however, is bogus and set up only to steal the user's information.

'Why securely encrypted email billing is unphishable'

One of the fundamentals of 'push' email billing & statements is that the recipient is NOT required to visit or log-in to any website. This in itself is the major strategic reason why such a 'DELIVERY' mechanism cannot be phished.

There are however many additional and compelling reasons why a securely encrypted email bill / statement is unphishable:

  • Phishers only ever have your email address, however a secure email bill is fully personalized in many ways:
    • The subject line can contain your name. For example: "Mr. Paul Smith: Your January America Express Credit Card Statement"
    • Your name is also included in the greeting in the mail body: "Dear Paul"
    • The mail body can contain your full physical address, as well as the last four digits of your credit card number . E.g.: ****-***-1234
  • Striata secure emails are digitally signed to authenticate the 'sender'. Click here for more information on the 'Striata Signed' process.
  • Striata secure emails include a United States Postal Service Electronic Postmark (USPS EPM):
    • An EPM Trusted Transaction combines the digital signature of the sender with a unique official digital signature and timestamp issued by the USPS. The EPM is embedded cryptographically inside the graphical postmark certificate attached to the message. EPM Trusted Transactions bring together for the first time in a single solution all the attributes of a complete email authentication solution:
      • Trusted USPS Branding - The USPS brand is ubiquitous and trusted by consumers.
      • Accreditation - Senders must agree to abide by USPS guidelines, the federal Mail statutes, and the CAN-SPAM Act.
      • Authentication - All messages are signed cryptographically by the sender and by the USPS. The attributes of the email transaction are incorporated into the EPM certificate.
      • Verification - A variety of mechanisms are provided to verify the authenticity of incoming mail, including 'forward to verify' and 'click to verify'.
      • Enforcement - Should fraudulent use of USPS EPM be detected, the matter will be referred to the Postal Service Inspection Service for possible review and action consistent with all relevant federal statutes.
  • The securely encrypted email bill / statement is attached. It is not possible for a phisher to have this detailed information.
  • Authentication / decryption is an offline process with NO sensitive data passing over the Internet or being entered into a publicly accessible website.
  • Once decrypted, the bill or statement is viewed in an offline format on the user's local machine.
  • Should payment of a bill be required, the Striata BillPay functionality allows payment directly from within the encrypted document, without the need to enter any sensitive payment information into a website.

Financial institutions and other billers that rely on email notifications to drive their consumers to their websites will continue to be targets for phishing and other fraudulent activities. Secure email billing completely eliminates this threat whilst offering simple and convenient bill presentment & payment.

We'd welcome the opportunity to get your views and discuss this subject further. We look forward to hearing from you.

Regards,

Garin Toren
Chief Operating Officer

Toll free: +1 88 88 USAPAY

Striata ~ North, Central & South America
Messaging innovation

Striata.com | Contact us | Unsubscribe | Press Office | Past Newsflashes | Striata BillPay
Editorial: 48 Wall Street, Suite 1100, New York, NY, 10005. Visit our Press Office here

(c) 2005 Striata North America. You may forward this newsletter without cutting. All other rights reserved. Contact us for reprints/story use at usa @ striata.com, or call +1 88 88 USAPAY.

To unsubscribe: Send a blank email to leave-usanews @ usa.striata.com or call us at (877) 531 9666 for assistance.
Have you received this email from a friend or colleague? Why not get your own copy of our bi-monthly Newsflash about secure email 'Electronic Invoice Presentment & Payment'. To join now Go here
Quick Links
Demos »
Downloads »
MyStriata Login »
Partners »
Contact details »


Get our monthly NewsFlash... Join now »

The NewsFlash Editions
#71 -News-2008-09-30 »
#70 -News-2008-08-26 »
#69 -News-2008-07-29 »
#68 -News-2008-06-25 »
#67 -News-2008-05-27 »
#66 -News-2008-04-22 »
#65 -News-2008-03-25 »
#64 -News-2008-02-26 »
#63 -News-2008-01-29 »
#62 -News-2007-12-11 »
#61 -News-2007-11-13 »
#60 -News-2007-10-18 »
#59 -News-2007-08-14 »
#58 -News-2007-06-26 »
#57 -News-2007-06-06 »
#56 -News-2007-04-24 »
#55 -News-2007-03-20 »
#54 -News-2007-02-20 »
#53 -News-2007-01-23 »
#52 -News-2006-12-19 »
#51 -News-2006-12-05 »
#50 -News-2006-11-14 »
#49 -News-2006-10-31 »
#48 -News-2006-10-17 »
#47 -News-2006-10-03 »
#46 -News-2006-09-19 »
#45 -News-2006-09-05 »
#44 -News-2006-08-22 »
#43 -News-2006-08-08 »
#42 -News-2006-07-25 »
#41 -News-2006-07-11 »
#40 -News-2006-06-27 »
#39 -News-2006-06-13 »
#38 -News-2006-05-26 »
#37 -News-2006-05-16 »
#36 -News-2006-05-02 »
#35 -News-2006-04-18 »
#34 -News-2006-04-04 »
#33 -News-2006-03-21 »
#32 -News-2006-03-07 »
#31 -News-2006-02-21 »
#30 -News-2006-02-07 »
#29 -News-2006-01-24 »
#28 -News-2006-01-10 »
#27 -News-2005-12-13 »
#26 -News-2005-11-29 »
#25 -News-2005-11-15 »
#24 -News-2005-11-01 »
#23 -News-2005-10-18 »
#22 -News-2005-10-04 »
#21 -News-2005-09-20 »
#20 -News-2005-09-06 »
#19 -News-2005-08-23 »
#18 -News-2005-08-09 »
#17 -News-2005-07-26 »
#16 -News-2005-07-12 »
#15 -News-2005-06-28 »
#14 -News-2005-06-14 »
#13 -News-2005-05-30 »
#12 -News-2005-05-19 »
#11 -News-2005-05-04 »
#10 -News-2005-04-19 »
#09 -News-2005-04-05 »
#08 -News-2005-03-22 »
#07 -News-2005-03-07 »
#06 -News-2005-02-22 »
#05 -News-2005-02-07 »
#05 -News-2005-01-25 »
#04 -News-2005-01-11 »
#03 -News-2004-12-13 »
#02 -News-2004-11-30 »
#01 -News-2004-11-15 »

Why choose Striata?

  • Flexible
  • Configurable
  • Multi-channel
  • Cross platform
  • Levels of control
  • Extensive reporting

    Read further »