I have spent most of my professional career fighting the scourge of tech jargon. Mea culpa: I did write an internet jargon dictionary 30 years ago that included acronyms that I had invented, such as IBM (Iโm Buck Naked), but itโs probably best we forget that. Iโd also like to suggest that we forget the current round of cybersecurity-focused jargon that, in my never humble opinion, does more harm than good. Jargon such as mishing.
What the chuffing heck is mishing? Or what is missing, as my spellcheck insisted on correcting me, quite logically as it turns out: what is missing is common sense. Have you worked it out yet?
The context is an email I received informing me of a new threat intelligence report from Zimperium which, in and of itself, is a worthy piece of analysis, looking at malware variants that target mobile credential theft through login and 2FA compromise. Things took a ridiculous turn when Zimperium told me that โthese attacks are powered by mishing campaigns and sideloaded apps that silently harvest access keys from the very devices employees rely on every dayโ.
What are mishing campaigns, then?
Mishing campaigns, it turns out, are mobileโfocused phishing campaigns. Or, as I prefer to call them, phishing campaigns.ย
Whatโs wrong with good old-fashioned plain English, for goodnessโ sake? Mishing is as confusing as vishing (voice or video phishing, take your pick – see what I mean about confusing) or quishing (QR code phishing) or smishing (text message phishing, which begs the question why not tishing?) at the end of the day.
Sensational terms just add noise, said Paul Walsh, an internet security veteran who has been in the game as long as me. Walsh, CEO of MetaCert and Co-Founder of the W3C Mobile Web Initiative in 2004, told me that โQuishing is phishing. Smishing is phishing. PDF phishing is phishing. They all use the same trick. They impersonate something trusted, hide a link to a fake page or download and hope you tap it.โ
Phishing by another name…
And thatโs the point. Introducing new jargon to describe old threats doesnโt somehow make them easier to deal with. Iโd argue it makes it harder. Not least, as it is a distraction from the simple truth that, as Walsh said, all phishing is a one-trick pony.
โMassive breaches are no longer starting on desktops, theyโre starting in your pocket,โ said Nicolรกs Chiaraviglio, Chief Scientist at Zimperium. โOrganisations must take mobile security seriously to stop credentialโstealing malware before it compromises enterprise resources.โ That, I canโt argue with, but please, Nicolรกs, letโs keep the message clear and do away with unnecessary jargon.
Mic drop. Rant over. Youโre welcome.