Re: Fwd: Re: [Cryptography] Encryption opinion

<[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAG7xX7rUv+DvL7A=a06-Z1oYa_uLsb_Wgp+jyOiP2sMsJtkLPw@mail.gmail.com>
On Aug 31, 2014 5:23 PM, "Karp, Alan H" <[email protected]> wrote:
> A clickjacking attack.  I had taken Ihab's comments to denote a more
direct attack. ... Of course, the way Amazon works for me is that I get
prompted for my password before I can spend any money.

My original point was that there exist patterns of convenience in the
current Web architecture that a principled ocap alternative would have to
re-create.

As I understand your response, these patterns are already no more
convenient than the principled ocap alternatives would be. Perhaps that is
correct. In any case, I'm sure we could design such alternatives.

I'm doubly sure we can do it because the existing state of affairs is
extremely inconvenient in many other ways. To design around it, we've had
to invent XSRF tokens, for one thing. And any site worth its salt works
around clickjacking by frame-busting, making legitimate embedding by
authorized parties impossible.

The challenge stands: If we want to create an ocap safe universe, we need
to build out the stuff that people have built before and show that it
works. That's all.

Ihab

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.