← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Particip ation

From
Elliotte Rusty Harold <>
To
Ralph Hilken <>
Date
2004-01-06T20:53:13Z
ID
<p06010204bc20d053142b@[192.168.254.4]>
Thread
RE: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Particip ation
At 1:51 PM -0500 1/6/04, Ralph Hilken wrote:


>In addition to HTTP authentication not being deployed due to lack of
>popularity or experience with it, there are the recent "phishing"
>exploits publicized, with warnings published by E-Week:
>  http://www.eweek.com/article2/0,4149,1409700,00.asp
>  http://www.eweek.com/article2/0,4149,1399670,00.asp
>
>and Microsoft:
>  http://support.microsoft.com/?id=833786


These appear to not be directly related to HTTP authentication. They 
simply fool the user into thinking they are at a different site than 
they actually are. HTTP authentication and cookie based 
authentication are equally vulnerable to this style of social 
engineering.
-- 

   Elliotte Rusty Harold
   
   Effective XML (Addison-Wesley, 2003)
   http://www.cafeconleche.org/books/effectivexml
   http://www.amazon.com/exec/obidos/ISBN%3D0321150406/ref%3Dnosim/cafeaulaitA
← Prev in month ← Prev in thread
Next in thread → Next in month →