Re: A new type of phishing attack
Guido Witmond <guido-EBfTt96odT/[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <[email protected]> |
On 09/13/14 12:10, James A. Donald wrote: > On 2014-09-13 19:43, Guido Witmond wrote: >> On 09/13/14 01:03, Sandro Magi wrote: >>> If some authentication step is required to obtain your root cap URL, >>> this attack could still be successful against enough people to make it >>> worth the effort. I don't think webkeys alone would suffice, unless caps >>> are all that a user has, so a login prompt isn't even an option. >> >> >> As long as people provide static credentials (like a password) to a >> remote end of a socket, the phishing problem stays. >> >> Taking the login prompt away from the html page and into the browser is >> a good thing to do. >> >> A capability is a static token that can be copied. Once copied by >> someone who you don't intend to have it, it is game over. > > > Zero knowledge password proof. A ZKP solves password problem above. It stops people from handing over the credentials. It was not the problems that I addressed, Anyway the problem I addressed is this: I hold a capability to an item at a service, say an email at a mailbox. My problem is making sure I present it to the correct mailbox-service of all those billion hosts out there. If I connect to the wrong host, the email might end up at the front page of a newspaper... The question is: how do I identify the correct service before invoking the capability? My answer uses public key cryptography to provide a solution. There is another question: How can I be sure that a recipient of a capability I hold won't accidentally leak it after I gave it to them? For example: I hold a capability to a document. I trust Bob with it. However he is no too smart with computers (just a normal user). I ask him if he runs CromeZilla 15 that implements Guidos-Crazy-Crypto-Identity-Protocol. If so I'm reasonable assured he doesn't accidentally leak my document to phishers. Guido. _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk
signature.asc
(application/pgp-signature, 897 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Icedove - http://www.enigmail.net/ iQIcBAEBAgAGBQJUFIX2AAoJEHPd8GglaNRmKxYP/29acWntqw24S8mbJsCDYsIZ CVWxz/gKnDLOBmeXF1U96FoWAmhpkuWQmzQL4b3FdG/c7DHWB/r7ZEfPYeJFh6Va qDrPiYCcTXvu2rrC5UpmbhhJ/qy8khVuKC/ZVxkjymC80RjKzjQ+qh/Rtxx88ye7 od/3fGB2unNRaKSbRyPDFxHzxgUC0l8HutrFpUisb5uqwWoKhmG0Ysw3yQAKiQH2 dHdLc0Eazw0ANEP6Fl4CY9IThteQ4Z4b3rWCUA5Q6BwUjg0cni4IQyf588diSvXV wDuTrXTtdr/Nr2gNiV43RoHF6v7K2Z20BWdnWRxUqM9wvbvJka0akBk0JTqbC0BS FgHT1yqN/Zx21pe1jCfhhPiAM1tQi2c8QHWJj1+PSkObBn8ZLEzQjMmGLMZVlFHR tOx/r8bKSeWtrd5nxYCAupyha+g78KPGRY0DUtNHJ7aIyzsGycblUMtYjkf5Y9ER 9+OzAv3dO8Q5eOkBcJHwLTYGkUWr7qp6TmEdxIB7tEqGC3TGz5vN+Zv/N4+KSFta K/Y41HRfan/tS6wA284irJdract0NeTuDat2VcKZV0wE+y9faHH6N/3cRukLv4oS zM4MvWkzyobqKukfm51e+rXJl/dx0kAL66G8WdelKAZkjXNr1DT0ihjmUDz7Lqsm gZmObB+L/KFzZWGE2EfF =I1GL -----END PGP SIGNATURE-----