Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
RE: Article - A solution to phishing Nov 26 2004 11:22AM
Michael Silk (michaelsilk gmail com) (2 replies)
RE: Article - A solution to phishing Nov 27 2004 04:18PM
lists dawes za net (4 replies)
Quoting Michael Silk <michaelsilk (at) gmail (dot) com [email concealed]>:

> Hi Christopher,
>
> Thanks for your feedback, let me address it.
>
> First let me say that many people have raised
> the issue (privately) of unecrypted emails not
> being good enough - and they have a point. So
> from now onwards let us assume that public
> key/private key exchange system is used to
> communicate the emails such that:
>

And if they are using a public key system, why would you bother with email then?
Just make them use the private key to authenticate to the website. There is
STILL no opportunity for phishing, as the user never types in any details. They
simply authenticate the SSL session using the cert, and there are no further
opportunities for information theft.

Sounds to me like you just want to use email in there somewhere! ;-)

Rogan

[ reply ]
Re: Article - A solution to phishing Nov 29 2004 01:50PM
Joseph Miller (joseph tidetamerboatlifts com)
Re: Article - A solution to phishing Nov 29 2004 01:50PM
Joseph Miller (joseph tidetamerboatlifts com)
Re: Article - A solution to phishing Nov 27 2004 10:05PM
Michael Silk (michaelsilk gmail com) (1 replies)
Re: Article - A solution to phishing Nov 30 2004 07:22AM
Rogan Dawes (discard dawes za net) (2 replies)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 27 2004 10:05PM
Michael Silk (michaelsilk gmail com) (1 replies)
Re: Article - A solution to phishing Nov 30 2004 07:22AM
Rogan Dawes (discard dawes za net) (2 replies)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
RE: Article - A solution to phishing Nov 27 2004 04:18PM
lists dawes za net (4 replies)
Quoting Michael Silk <michaelsilk (at) gmail (dot) com [email concealed]>:<br/>
<br/>
> Hi Christopher,<br/>
> <br/>
> Thanks for your feedback, let me address it.<br/>
> <br/>
> First let me say that many people have raised<br/>
> the issue (privately) of unecrypted emails not<br/>
> being good enough - and they have a point. So<br/>
> from now onwards let us assume that public<br/>
> key/private key exchange system is used to<br/>
> communicate the emails such that:<br/>
><br/>
<br/>
And if they are using a public key system, why would you bother with email then?<br/>
Just make them use the private key to authenticate to the website. There is<br/>
STILL no opportunity for phishing, as the user never types in any details. They<br/>
simply authenticate the SSL session using the cert, and there are no further<br/>
opportunities for information theft.<br/>
<br/>
Sounds to me like you just want to use email in there somewhere! ;-)<br/>
<br/>
Rogan

[ reply ]
Re: Article - A solution to phishing Nov 29 2004 01:50PM
Joseph Miller (joseph tidetamerboatlifts com)
Re: Article - A solution to phishing Nov 29 2004 01:50PM
Joseph Miller (joseph tidetamerboatlifts com)
Re: Article - A solution to phishing Nov 27 2004 10:05PM
Michael Silk (michaelsilk gmail com) (1 replies)
Re: Article - A solution to phishing Nov 30 2004 07:22AM
Rogan Dawes (discard dawes za net) (2 replies)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 27 2004 10:05PM
Michael Silk (michaelsilk gmail com) (1 replies)
Re: Article - A solution to phishing Nov 30 2004 07:22AM
Rogan Dawes (discard dawes za net) (2 replies)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)
Re: Article - A solution to phishing Nov 30 2004 04:08PM
Adam Shostack (adam homeport org) (1 replies)
Re: Article - A solution to phishing Dec 03 2004 05:06PM
Rogan Dawes (discard dawes za net)







 

Privacy Statement
Copyright 2009, SecurityFocus