<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body dir="auto">
<div>Hello,</div>
<div id="AppleMailSignature"><br>
</div>
<div id="AppleMailSignature">Not sure how you would implement this.. but some banks I've seen, have a user pick out their "image and phrase", that only they would know when setting up account profile. When a user revisits the login page, they first enter their
 username- then the page loads with their image and phrase.. which they need to verify is what they had selected when setting up the account.  </div>
<div id="AppleMailSignature"><br>
</div>
<div id="AppleMailSignature">The phishers wouldn't be able generate that image and phrase-hence securing the IdP login page. <br>
<br>
Thanks,
<div><br>
<div>Shweta</div>
</div>
<div><br>
</div>
</div>
<div><br>
On Mar 26, 2018, at 5:07 PM, Liam Hoekenga <<a href="mailto:liamr@umich.edu">liamr@umich.edu</a>> wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">> I had considered this, too, Liam. Not only is referrer not terribly reliable, but there’s nothing stopping the<br>
> hacker from grabbing the images and CSS when they grab the page course and hosting it, too.
<div><br>
</div>
<div>Right.</div>
<div><br>
</div>
<div>We also have a problem with phishers copying our login page for nefarious purposes.  <span style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">I
 know that our security group would be very interested in potential solutions. <span> </span></span></div>
<div><br>
</div>
<div>Liam</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Mon, Mar 26, 2018 at 3:05 PM, Wessel, Keith <span dir="ltr">
<<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div lang="EN-US" link="blue" vlink="purple">
<div class="m_3985879277345839130WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I had considered this, too, Liam. Not only is referrer not terribly reliable, but there’s nothing stopping the hacker from grabbing the images and CSS when they
 grab the page course and hosting it, too.<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Keith<u></u><u></u></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></p>
<p class="MsoNormal"><a name="m_3985879277345839130__MailEndCompose"><span style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"><u></u> <u></u></span></a></p>
<span></span>
<p class="MsoNormal"><b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span style="font-size:11.0pt;font-family:"Calibri",sans-serif"> users <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Liam Hoekenga<br>
<b>Sent:</b> Monday, March 26, 2018 2:52 PM<span class=""><br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: Any creative solution to make it harder for hackers to copy your IdP login page?<u></u><u></u></span></span></p>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">We had played with the idea of replacing all of the images or css files for the login page if the referrer wasn't the login page.. but referrer isn't the most reliable data.<u></u><u></u></p>
</div>
<div>
<div class="h5">
<div>
<p class="MsoNormal"><u></u> <u></u></p>
<div>
<p class="MsoNormal">On Mon, Mar 26, 2018 at 2:47 PM, Wessel, Keith <<a href="mailto:kwessel@illinois.edu" target="_blank">kwessel@illinois.edu</a>> wrote:<u></u><u></u></p>
<blockquote style="border:none;border-left:solid #cccccc 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">Hi, all,<br>
<br>
We've had a couple recent phishing attempts where hackers have hosted their own stolen copy of our IdP login page in order to trick users into giving them their usernames and passwords. Our move toward MFA is going to make this much more difficult (I'm not
 naive enough to say impossible), but we're hoping to make it harder for this trick to work in the meantime. Our security folks asked if we could add some javascript that would bring up an impossible-to-close pop-up if the hostname didn't match what it should
 be. This is, of course, possible but also easy for a hacker to remove.<br>
<br>
We already have text at the bottom of our IdP login page stating what the hostname should be in the address bar, but nobody reads that part. Amusingly, the hackers didn't even change that part in their login page knock-offs. But our security folks didn't even
 notice that text until I pointed it out to them.<br>
<br>
I'm wondering if anyone has come up with creative solutions to slow down hackers from doing this kind of thing.<br>
<br>
Thanks for any thoughts,<br>
Keith<br>
<span style="color:#888888"><br>
<span class="m_3985879277345839130hoenzb">--</span><br>
<span class="m_3985879277345839130hoenzb">For Consortium Member technical support, see
<a href="https://wiki.shibboleth.net/confluence/x/coFAAg" target="_blank">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a></span><br>
<span class="m_3985879277345839130hoenzb">To unsubscribe from this list send an email to
<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.<wbr>net</a></span></span><u></u><u></u></p>
</blockquote>
</div>
<p class="MsoNormal"><u></u> <u></u></p>
</div>
</div>
</div>
</div>
</div>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">
https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</blockquote>
</div>
<br>
</div>
</div>
</blockquote>
<blockquote type="cite">
<div><span>-- </span><br>
<span>For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg">
https://wiki.shibboleth.net/confluence/x/coFAAg</a></span><br>
<span>To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
</body>
</html>