Re: A new type of phishing attack

Guido Witmond <guido-EBfTt96odT/[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <[email protected]>
On 09/13/14 12:10, James A. Donald wrote:
> On 2014-09-13 19:43, Guido Witmond wrote:
>> On 09/13/14 01:03, Sandro Magi wrote:
>>> If some authentication step is required to obtain your root cap URL,
>>> this attack could still be successful against enough people to make it
>>> worth the effort. I don't think webkeys alone would suffice, unless caps
>>> are all that a user has, so a login prompt isn't even an option.
>>
>>
>> As long as people provide static credentials (like a password) to a
>> remote end of a socket, the phishing problem stays.
>>
>> Taking the login prompt away from the html page and into the browser is
>> a good thing to do.
>>
>> A capability is a static token that can be copied. Once copied by
>> someone who you don't intend to have it, it is game over.
> 
> 
> Zero knowledge password proof.

A ZKP solves password problem above. It stops people from handing over
the credentials. It was not the problems that I addressed,


Anyway the problem I addressed is this:

I hold a capability to an item at a service, say an email at a mailbox.
My problem is making sure I present it to the correct mailbox-service of
all those billion hosts out there. If I connect to the wrong host, the
email might end up at the front page of a newspaper...

The question is: how do I identify the correct service before invoking
the capability?

My answer uses public key cryptography to provide a solution.


There is another question:

How can I be sure that a recipient of a capability I hold won't
accidentally leak it after I gave it to them?

For example: I hold a capability to a document. I trust Bob with it.
However he is no too smart with computers (just a normal user). I ask
him if he runs CromeZilla 15 that implements
Guidos-Crazy-Crypto-Identity-Protocol. If so I'm reasonable assured he
doesn't accidentally leak my document to phishers.


Guido.

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
signature.asc (application/pgp-signature, 897 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Icedove - http://www.enigmail.net/

iQIcBAEBAgAGBQJUFIX2AAoJEHPd8GglaNRmKxYP/29acWntqw24S8mbJsCDYsIZ
CVWxz/gKnDLOBmeXF1U96FoWAmhpkuWQmzQL4b3FdG/c7DHWB/r7ZEfPYeJFh6Va
qDrPiYCcTXvu2rrC5UpmbhhJ/qy8khVuKC/ZVxkjymC80RjKzjQ+qh/Rtxx88ye7
od/3fGB2unNRaKSbRyPDFxHzxgUC0l8HutrFpUisb5uqwWoKhmG0Ysw3yQAKiQH2
dHdLc0Eazw0ANEP6Fl4CY9IThteQ4Z4b3rWCUA5Q6BwUjg0cni4IQyf588diSvXV
wDuTrXTtdr/Nr2gNiV43RoHF6v7K2Z20BWdnWRxUqM9wvbvJka0akBk0JTqbC0BS
FgHT1yqN/Zx21pe1jCfhhPiAM1tQi2c8QHWJj1+PSkObBn8ZLEzQjMmGLMZVlFHR
tOx/r8bKSeWtrd5nxYCAupyha+g78KPGRY0DUtNHJ7aIyzsGycblUMtYjkf5Y9ER
9+OzAv3dO8Q5eOkBcJHwLTYGkUWr7qp6TmEdxIB7tEqGC3TGz5vN+Zv/N4+KSFta
K/Y41HRfan/tS6wA284irJdract0NeTuDat2VcKZV0wE+y9faHH6N/3cRukLv4oS
zM4MvWkzyobqKukfm51e+rXJl/dx0kAL66G8WdelKAZkjXNr1DT0ihjmUDz7Lqsm
gZmObB+L/KFzZWGE2EfF
=I1GL
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.