Re: A new type of phishing attack

Sandro Magi <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
If some authentication step is required to obtain your root cap URL, 
this attack could still be successful against enough people to make it 
worth the effort. I don't think webkeys alone would suffice, unless caps 
are all that a user has, so a login prompt isn't even an option.

Sandro

On 12/09/2014 5:27 PM, Stiegler, Marc wrote:
> It is also yet another reminder that webkeys would fix these problems if people would just implement them. Or 2FACC if people would just implement that. Sigh.
>
> --marcs
>
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf Of Sandro Magi
> Sent: Friday, September 12, 2014 6:33 AM
> To: General discussions concerning capability systems.
> Subject: [cap-talk] A new type of phishing attack
>
> Interesting new phishing idea:
>
> http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/
>
> Basically exploiting a typical user's workflow where they have multiple tabs open. This highlights the real need for a functional petname system.
>
> As a trivial countermeasure, I wonder if it's really necessary for JavaScript to run on inactive tabs.
>
> Sandro
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
>
> _______________________________________________
> cap-talk mailing list
> [email protected]
> http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.