<html>
<head>
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<div class="moz-cite-prefix">It's perfectly possible for the
attackers to show that image and phrase. <br>
<br>
The user inputs their username in to the attacker system<br>
Attacker system inputs the username into the real system<br>
Attacker system reads image and phrase from real system<br>
Attacker system displays image and phrase to use<br>
<br>
<br>
On 03/26/2018 04:20 PM, Shweta Kautia wrote:<br>
</div>
<blockquote type="cite"
cite="mid:90AEC2A9-FBB8-43A2-89B2-CB594A3E63F7@northcarolina.edu">
<meta http-equiv="Content-Type" content="text/html;
charset=windows-1252">
<div>Hello,</div>
<div id="AppleMailSignature"><br>
</div>
<div id="AppleMailSignature">Not sure how you would implement
this.. but some banks I've seen, have a user pick out their
"image and phrase", that only they would know when setting up
account profile. When a user revisits the login page, they first
enter their username- then the page loads with their image and
phrase.. which they need to verify is what they had selected
when setting up the account. </div>
<div id="AppleMailSignature"><br>
</div>
<div id="AppleMailSignature">The phishers wouldn't be able
generate that image and phrase-hence securing the IdP login
page. <br>
<br>
Thanks,
<div><br>
<div>Shweta</div>
</div>
<div><br>
</div>
</div>
<div><br>
On Mar 26, 2018, at 5:07 PM, Liam Hoekenga <<a
href="mailto:liamr@umich.edu" moz-do-not-send="true">liamr@umich.edu</a>>
wrote:<br>
<br>
</div>
<blockquote type="cite">
<div>
<div dir="ltr">> I had considered this, too, Liam. Not only
is referrer not terribly reliable, but there’s nothing
stopping the<br>
> hacker from grabbing the images and CSS when they grab
the page course and hosting it, too.
<div><br>
</div>
<div>Right.</div>
<div><br>
</div>
<div>We also have a problem with phishers copying our login
page for nefarious purposes. <span
style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">I
know that our security group would be very interested in
potential solutions. <span> </span></span></div>
<div><br>
</div>
<div>Liam</div>
</div>
<div class="gmail_extra"><br>
<div class="gmail_quote">On Mon, Mar 26, 2018 at 3:05 PM,
Wessel, Keith <span dir="ltr">
<<a href="mailto:kwessel@illinois.edu"
target="_blank" moz-do-not-send="true">kwessel@illinois.edu</a>></span>
wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
<div link="blue" vlink="purple" lang="EN-US">
<div class="m_3985879277345839130WordSection1">
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I
had considered this, too, Liam. Not only is
referrer not terribly reliable, but there’s
nothing stopping the hacker from grabbing the
images and CSS when they grab the page course
and hosting it, too.</span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Keith</span></p>
<p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></p>
<p class="MsoNormal"><a
name="m_3985879277345839130__MailEndCompose"
moz-do-not-send="true"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></a></p>
<span></span>
<p class="MsoNormal"><b><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif">
users <<a
href="mailto:users-bounces@shibboleth.net"
target="_blank" moz-do-not-send="true">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>Liam Hoekenga<br>
<b>Sent:</b> Monday, March 26, 2018 2:52 PM<span
class=""><br>
<b>To:</b> Shib Users <<a
href="mailto:users@shibboleth.net"
target="_blank" moz-do-not-send="true">users@shibboleth.net</a>><br>
<b>Subject:</b> Re: Any creative solution to
make it harder for hackers to copy your IdP
login page?</span></span></p>
<p class="MsoNormal"> </p>
<div>
<p class="MsoNormal">We had played with the idea
of replacing all of the images or css files for
the login page if the referrer wasn't the login
page.. but referrer isn't the most reliable
data.</p>
</div>
<div>
<div class="h5">
<div>
<p class="MsoNormal"> </p>
<div>
<p class="MsoNormal">On Mon, Mar 26, 2018 at
2:47 PM, Wessel, Keith <<a
href="mailto:kwessel@illinois.edu"
target="_blank" moz-do-not-send="true">kwessel@illinois.edu</a>>
wrote:</p>
<blockquote
style="border:none;border-left:solid
#cccccc 1.0pt;padding:0in 0in 0in
6.0pt;margin-left:4.8pt;margin-right:0in">
<p class="MsoNormal">Hi, all,<br>
<br>
We've had a couple recent phishing
attempts where hackers have hosted their
own stolen copy of our IdP login page in
order to trick users into giving them
their usernames and passwords. Our move
toward MFA is going to make this much
more difficult (I'm not naive enough to
say impossible), but we're hoping to
make it harder for this trick to work in
the meantime. Our security folks asked
if we could add some javascript that
would bring up an impossible-to-close
pop-up if the hostname didn't match what
it should be. This is, of course,
possible but also easy for a hacker to
remove.<br>
<br>
We already have text at the bottom of
our IdP login page stating what the
hostname should be in the address bar,
but nobody reads that part. Amusingly,
the hackers didn't even change that part
in their login page knock-offs. But our
security folks didn't even notice that
text until I pointed it out to them.<br>
<br>
I'm wondering if anyone has come up with
creative solutions to slow down hackers
from doing this kind of thing.<br>
<br>
Thanks for any thoughts,<br>
Keith<br>
<span style="color:#888888"><br>
<span
class="m_3985879277345839130hoenzb">--</span><br>
<span
class="m_3985879277345839130hoenzb">For
Consortium Member technical support,
see
<a
href="https://wiki.shibboleth.net/confluence/x/coFAAg"
target="_blank"
moz-do-not-send="true">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a></span><br>
<span
class="m_3985879277345839130hoenzb">To
unsubscribe from this list send an
email to
<a
href="mailto:users-unsubscribe@shibboleth.net"
target="_blank"
moz-do-not-send="true">users-unsubscribe@shibboleth.<wbr>net</a></span></span></p>
</blockquote>
</div>
<p class="MsoNormal"> </p>
</div>
</div>
</div>
</div>
</div>
<br>
--<br>
For Consortium Member technical support, see <a
href="https://wiki.shibboleth.net/confluence/x/coFAAg"
rel="noreferrer" target="_blank"
moz-do-not-send="true">
https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a
href="mailto:users-unsubscribe@shibboleth.net"
moz-do-not-send="true">
users-unsubscribe@shibboleth.<wbr>net</a><br>
</blockquote>
</div>
<br>
</div>
</div>
</blockquote>
<blockquote type="cite">
<div><span>-- </span><br>
<span>For Consortium Member technical support, see <a
href="https://wiki.shibboleth.net/confluence/x/coFAAg"
moz-do-not-send="true">
https://wiki.shibboleth.net/confluence/x/coFAAg</a></span><br>
<span>To unsubscribe from this list send an email to <a
href="mailto:users-unsubscribe@shibboleth.net"
moz-do-not-send="true">
users-unsubscribe@shibboleth.net</a></span></div>
</blockquote>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
</blockquote>
<p><br>
</p>
</body>
</html>