WebApp Sec mailing list archives

Re: Summary: Growing Bad Practice with Login Forms


From: Rogan Dawes <discard () dawes za net>
Date: Wed, 28 Jul 2004 17:20:31 +0200

David Telfer wrote:


I am unable to find the post, but the suggestion of pass phrases that the user holds would surely help. Showing characters x and y to a user and getting them to verify them against a given phrase (provided non-electronically, by normal post perhaps) would allow the user to verify in her own mind that the site is legitimate before entering login information.

If the site is being MITM'ed, that is worthless. It is trivial to relay whatever the genuine server sends to the user, with him being none the wiser.


David Telfer

Rogan
--
Rogan Dawes

*ALL* messages to discard () dawes za net will be dropped, and added
to my blacklist. Please respond to "lists AT dawes DOT za DOT net"


Current thread: