Re: A new type of phishing attack
Sandro Magi <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
If some authentication step is required to obtain your root cap URL, this attack could still be successful against enough people to make it worth the effort. I don't think webkeys alone would suffice, unless caps are all that a user has, so a login prompt isn't even an option. Sandro On 12/09/2014 5:27 PM, Stiegler, Marc wrote: > It is also yet another reminder that webkeys would fix these problems if people would just implement them. Or 2FACC if people would just implement that. Sigh. > > --marcs > > -----Original Message----- > From: [email protected] [mailto:[email protected]] On Behalf Of Sandro Magi > Sent: Friday, September 12, 2014 6:33 AM > To: General discussions concerning capability systems. > Subject: [cap-talk] A new type of phishing attack > > Interesting new phishing idea: > > http://www.azarask.in/blog/post/a-new-type-of-phishing-attack/ > > Basically exploiting a typical user's workflow where they have multiple tabs open. This highlights the real need for a functional petname system. > > As a trivial countermeasure, I wonder if it's really necessary for JavaScript to run on inactive tabs. > > Sandro > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk