Re: Highly Effective Gmail Phishing
Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Organization | If you lived here, you'd be $HOME already. |
| Message-ID | <[email protected]> |
I wrote:
> No matter how credible the call from 'Customer Service' sounds, if you
> politely decline every time you're asked to provide sensitive
> information in an unexpected / unfamiliar context, and insist on using
> only familiar contexts under your control and by your initiative, you
> automatically default a very large percentage of such attacks.
^^^^^^^
'defeat'.
> If someone were to offer a pocket-sized security appliance with zero
> network capabilities, that is open source from the ground up, hey, I'd
> buy one. This is an untapped niche that smartphones are hogging --
> badly.[1]
> [1] [...]
> In my dreams, there would be a totally open design for a YubiKey
> equivalent with a strongly-encrypted credential (passwords, etc.) store
> and small LCD input/output screen. I'd pay a nice premium to get one.
After posting, I remembered why my idea of such a combo is dumb:
YubiKeys by design are used online (USB-connected for all use).
OK, so on reflection what the world needs is a good open-design,
airgapped, pocket-sized, strong-crypto, storage gadget for storing and
displaying authentication strings and similar human-readable security
data. Basically, a PDA + Keyring, but smaller and open source.
Available development boards for Rob Landley's j-core SoC
(http://j-core.org/) are almost small enough, for example:
http://numato.com/mimas-v2-spartan-6-fpga-development-board-with-ddr-sdram/
Will Ashford ([email protected]) wrote:
> I'll just leave this here: https://www.themooltipass.com/
Nice! Although it's intended to be used primarily online, I gather one
can use it as an airgapped device, instead, via the touchscreen.
(Hardware design isn't open, but it's an imperfect world.)