<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">It's perfectly possible for the
      attackers to show that image and phrase. <br>
      <br>
      The user inputs their username in to the attacker system<br>
      Attacker system inputs the username into the real system<br>
      Attacker system reads image and phrase from real system<br>
      Attacker system displays image and phrase to use<br>
      <br>
      <br>
      On 03/26/2018 04:20 PM, Shweta Kautia wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:90AEC2A9-FBB8-43A2-89B2-CB594A3E63F7@northcarolina.edu">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div>Hello,</div>
      <div id="AppleMailSignature"><br>
      </div>
      <div id="AppleMailSignature">Not sure how you would implement
        this.. but some banks I've seen, have a user pick out their
        "image and phrase", that only they would know when setting up
        account profile. When a user revisits the login page, they first
        enter their username- then the page loads with their image and
        phrase.. which they need to verify is what they had selected
        when setting up the account.  </div>
      <div id="AppleMailSignature"><br>
      </div>
      <div id="AppleMailSignature">The phishers wouldn't be able
        generate that image and phrase-hence securing the IdP login
        page. <br>
        <br>
        Thanks,
        <div><br>
          <div>Shweta</div>
        </div>
        <div><br>
        </div>
      </div>
      <div><br>
        On Mar 26, 2018, at 5:07 PM, Liam Hoekenga <<a
          href="mailto:liamr@umich.edu" moz-do-not-send="true">liamr@umich.edu</a>>
        wrote:<br>
        <br>
      </div>
      <blockquote type="cite">
        <div>
          <div dir="ltr">> I had considered this, too, Liam. Not only
            is referrer not terribly reliable, but there’s nothing
            stopping the<br>
            > hacker from grabbing the images and CSS when they grab
            the page course and hosting it, too.
            <div><br>
            </div>
            <div>Right.</div>
            <div><br>
            </div>
            <div>We also have a problem with phishers copying our login
              page for nefarious purposes.  <span
style="color:rgb(34,34,34);font-family:arial,sans-serif;font-size:small;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">I
                know that our security group would be very interested in
                potential solutions. <span> </span></span></div>
            <div><br>
            </div>
            <div>Liam</div>
          </div>
          <div class="gmail_extra"><br>
            <div class="gmail_quote">On Mon, Mar 26, 2018 at 3:05 PM,
              Wessel, Keith <span dir="ltr">
                <<a href="mailto:kwessel@illinois.edu"
                  target="_blank" moz-do-not-send="true">kwessel@illinois.edu</a>></span>
              wrote:<br>
              <blockquote class="gmail_quote" style="margin:0 0 0
                .8ex;border-left:1px #ccc solid;padding-left:1ex">
                <div link="blue" vlink="purple" lang="EN-US">
                  <div class="m_3985879277345839130WordSection1">
                    <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">I
                        had considered this, too, Liam. Not only is
                        referrer not terribly reliable, but there’s
                        nothing stopping the hacker from grabbing the
                        images and CSS when they grab the page course
                        and hosting it, too.</span></p>
                    <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></p>
                    <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d">Keith</span></p>
                    <p class="MsoNormal"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></p>
                    <p class="MsoNormal"><a
                        name="m_3985879277345839130__MailEndCompose"
                        moz-do-not-send="true"><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif;color:#1f497d"> </span></a></p>
                    <span></span>
                    <p class="MsoNormal"><b><span
                          style="font-size:11.0pt;font-family:"Calibri",sans-serif">From:</span></b><span
style="font-size:11.0pt;font-family:"Calibri",sans-serif">
                        users <<a
                          href="mailto:users-bounces@shibboleth.net"
                          target="_blank" moz-do-not-send="true">users-bounces@shibboleth.net</a>>
                        <b>On Behalf Of </b>Liam Hoekenga<br>
                        <b>Sent:</b> Monday, March 26, 2018 2:52 PM<span
                          class=""><br>
                          <b>To:</b> Shib Users <<a
                            href="mailto:users@shibboleth.net"
                            target="_blank" moz-do-not-send="true">users@shibboleth.net</a>><br>
                          <b>Subject:</b> Re: Any creative solution to
                          make it harder for hackers to copy your IdP
                          login page?</span></span></p>
                    <p class="MsoNormal"> </p>
                    <div>
                      <p class="MsoNormal">We had played with the idea
                        of replacing all of the images or css files for
                        the login page if the referrer wasn't the login
                        page.. but referrer isn't the most reliable
                        data.</p>
                    </div>
                    <div>
                      <div class="h5">
                        <div>
                          <p class="MsoNormal"> </p>
                          <div>
                            <p class="MsoNormal">On Mon, Mar 26, 2018 at
                              2:47 PM, Wessel, Keith <<a
                                href="mailto:kwessel@illinois.edu"
                                target="_blank" moz-do-not-send="true">kwessel@illinois.edu</a>>
                              wrote:</p>
                            <blockquote
                              style="border:none;border-left:solid
                              #cccccc 1.0pt;padding:0in 0in 0in
                              6.0pt;margin-left:4.8pt;margin-right:0in">
                              <p class="MsoNormal">Hi, all,<br>
                                <br>
                                We've had a couple recent phishing
                                attempts where hackers have hosted their
                                own stolen copy of our IdP login page in
                                order to trick users into giving them
                                their usernames and passwords. Our move
                                toward MFA is going to make this much
                                more difficult (I'm not naive enough to
                                say impossible), but we're hoping to
                                make it harder for this trick to work in
                                the meantime. Our security folks asked
                                if we could add some javascript that
                                would bring up an impossible-to-close
                                pop-up if the hostname didn't match what
                                it should be. This is, of course,
                                possible but also easy for a hacker to
                                remove.<br>
                                <br>
                                We already have text at the bottom of
                                our IdP login page stating what the
                                hostname should be in the address bar,
                                but nobody reads that part. Amusingly,
                                the hackers didn't even change that part
                                in their login page knock-offs. But our
                                security folks didn't even notice that
                                text until I pointed it out to them.<br>
                                <br>
                                I'm wondering if anyone has come up with
                                creative solutions to slow down hackers
                                from doing this kind of thing.<br>
                                <br>
                                Thanks for any thoughts,<br>
                                Keith<br>
                                <span style="color:#888888"><br>
                                  <span
                                    class="m_3985879277345839130hoenzb">--</span><br>
                                  <span
                                    class="m_3985879277345839130hoenzb">For
                                    Consortium Member technical support,
                                    see
                                    <a
                                      href="https://wiki.shibboleth.net/confluence/x/coFAAg"
                                      target="_blank"
                                      moz-do-not-send="true">https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a></span><br>
                                  <span
                                    class="m_3985879277345839130hoenzb">To
                                    unsubscribe from this list send an
                                    email to
                                    <a
                                      href="mailto:users-unsubscribe@shibboleth.net"
                                      target="_blank"
                                      moz-do-not-send="true">users-unsubscribe@shibboleth.<wbr>net</a></span></span></p>
                            </blockquote>
                          </div>
                          <p class="MsoNormal"> </p>
                        </div>
                      </div>
                    </div>
                  </div>
                </div>
                <br>
                --<br>
                For Consortium Member technical support, see <a
                  href="https://wiki.shibboleth.net/confluence/x/coFAAg"
                  rel="noreferrer" target="_blank"
                  moz-do-not-send="true">
                  https://wiki.shibboleth.net/<wbr>confluence/x/coFAAg</a><br>
                To unsubscribe from this list send an email to <a
                  href="mailto:users-unsubscribe@shibboleth.net"
                  moz-do-not-send="true">
                  users-unsubscribe@shibboleth.<wbr>net</a><br>
              </blockquote>
            </div>
            <br>
          </div>
        </div>
      </blockquote>
      <blockquote type="cite">
        <div><span>-- </span><br>
          <span>For Consortium Member technical support, see <a
              href="https://wiki.shibboleth.net/confluence/x/coFAAg"
              moz-do-not-send="true">
              https://wiki.shibboleth.net/confluence/x/coFAAg</a></span><br>
          <span>To unsubscribe from this list send an email to <a
              href="mailto:users-unsubscribe@shibboleth.net"
              moz-do-not-send="true">
              users-unsubscribe@shibboleth.net</a></span></div>
      </blockquote>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>