Re: A new type of phishing attack
"James A. Donald" <jamesd-twz8Zj9/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 2014-09-13 19:43, Guido Witmond wrote: > On 09/13/14 01:03, Sandro Magi wrote: >> If some authentication step is required to obtain your root cap URL, >> this attack could still be successful against enough people to make it >> worth the effort. I don't think webkeys alone would suffice, unless caps >> are all that a user has, so a login prompt isn't even an option. > > > As long as people provide static credentials (like a password) to a > remote end of a socket, the phishing problem stays. > > Taking the login prompt away from the html page and into the browser is > a good thing to do. > > A capability is a static token that can be copied. Once copied by > someone who you don't intend to have it, it is game over. Zero knowledge password proof.