ECP Newbie question
Chad La Joie
lajoie at itumi.biz
Wed Apr 4 16:02:52 BST 2012
On Wed, Apr 4, 2012 at 10:54, Cantor, Scott <cantor.2 at osu.edu> wrote:
> I think you'll find that client issues are lumped in with phishing by most analysis today, so I have to go by what people define it to mean.
That's unfortunate. I don't think anyone is well served by conflating
phishing with downloading and installing malware. But okay, if that's
the new definition of the term not much I can do about it.
> And the second issue is not a configuration issue. There's no configuration that solves the IdP trust problem. Nobody knows how to do it. Nobody has solved it. Not for any protocol. It may not *be* solvable in general, and we're only debating the best worst options that mitigate the risk to an acceptable degree.
>
> There's no way for the user to have any role. No average user would have any way to make the decision correctly.
Yeah, okay, I think we're just talking about subtly different things
due to the way I was interpreting "phishing".
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the users
mailing list