Re: Fwd: Re: [Cryptography] Encryption opinion
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAG7xX7rUv+DvL7A=a06-Z1oYa_uLsb_Wgp+jyOiP2sMsJtkLPw@mail.gmail.com> |
On Aug 31, 2014 5:23 PM, "Karp, Alan H" <[email protected]> wrote: > A clickjacking attack. I had taken Ihab's comments to denote a more direct attack. ... Of course, the way Amazon works for me is that I get prompted for my password before I can spend any money. My original point was that there exist patterns of convenience in the current Web architecture that a principled ocap alternative would have to re-create. As I understand your response, these patterns are already no more convenient than the principled ocap alternatives would be. Perhaps that is correct. In any case, I'm sure we could design such alternatives. I'm doubly sure we can do it because the existing state of affairs is extremely inconvenient in many other ways. To design around it, we've had to invent XSRF tokens, for one thing. And any site worth its salt works around clickjacking by frame-busting, making legitimate embedding by authorized parties impossible. The challenge stands: If we want to create an ocap safe universe, we need to build out the stuff that people have built before and show that it works. That's all. Ihab _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk