ECP Newbie question
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 4 15:54:56 BST 2012
> Right, in both cases though it's not phishing in the traditional
> sense. The first case requires an attacker to get you to install
> malware before you'd be contacting any site. The second requires an
> attacker to get you to configure the client improperly. So, both are
> cases are still bad and still compromise things, but they aren't what
> I'd call a phishing attack.
I think you'll find that client issues are lumped in with phishing by most analysis today, so I have to go by what people define it to mean.
And the second issue is not a configuration issue. There's no configuration that solves the IdP trust problem. Nobody knows how to do it. Nobody has solved it. Not for any protocol. It may not *be* solvable in general, and we're only debating the best worst options that mitigate the risk to an acceptable degree.
There's no way for the user to have any role. No average user would have any way to make the decision correctly.
The good thing is that more people are finally working on the problem across a number of technologies, and ultimately there will be convergence on things to try.
-- Scott
More information about the users
mailing list