ECP Newbie question

Cantor, Scott cantor.2 at osu.edu
Wed Apr 4 16:09:01 BST 2012


> That's unfortunate.  I don't think anyone is well served by conflating
> phishing with downloading and installing malware.  But okay, if that's
> the new definition of the term not much I can do about it.

It's an alternate phishing vector, I think is the point. The phishing issue is the same, you give your credentials to an attacker. One way is to attack the connection to the server, another the client.

> Yeah, okay, I think we're just talking about subtly different things
> due to the way I was interpreting "phishing".

Well, the trust problem is also how you phish the browser. If the browser had a way to verify the IdP, you wouldn't have the problem there. So I think they align pretty clearly. The main difference is that we have no real ability to influence the browser solution, but the client is entirely up to the people developing it.

-- Scott



More information about the users mailing list