<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Simple way to avoid fake website logins</title>
	<atom:link href="http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/</link>
	<description>Ponderings of things that go "Ping!" by Jeff Pickell</description>
	<lastBuildDate>Wed, 18 Feb 2009 21:51:39 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Jeff</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-116</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Mon, 02 Feb 2009 03:08:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-116</guid>
		<description>Jennifer, What kind of details are you looking for? Are you referring to the previous comment by Antonio, or on the post itself?</description>
		<content:encoded><![CDATA[<p>Jennifer, What kind of details are you looking for? Are you referring to the previous comment by Antonio, or on the post itself?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jennifer Manson</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-115</link>
		<dc:creator>Jennifer Manson</dc:creator>
		<pubDate>Mon, 02 Feb 2009 02:51:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-115</guid>
		<description>I will appreciate if you provide more details on this. Thanks.</description>
		<content:encoded><![CDATA[<p>I will appreciate if you provide more details on this. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antonio</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-83</link>
		<dc:creator>Antonio</dc:creator>
		<pubDate>Thu, 18 Sep 2008 18:53:31 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-83</guid>
		<description>This is a stupid idea.  If the phishing site uses the credentials given it to log in to the real bank site in real time - it _can_ verify whether or not the credentials entered are valid.  And we&#039;ve seen sites doing exactly this for years now.  Sure this may work on some of the less advanced phishing sites but this is not good advice overall.

Want the real answer?  How about opening up a second tab/window and typing in the bank&#039;s website address by hand.  Won&#039;t help WRT DNS poisoning or other MiTM attacks but will prevent the entire class of obfuscation/redirection tricks.</description>
		<content:encoded><![CDATA[<p>This is a stupid idea.  If the phishing site uses the credentials given it to log in to the real bank site in real time &#8211; it _can_ verify whether or not the credentials entered are valid.  And we&#8217;ve seen sites doing exactly this for years now.  Sure this may work on some of the less advanced phishing sites but this is not good advice overall.</p>
<p>Want the real answer?  How about opening up a second tab/window and typing in the bank&#8217;s website address by hand.  Won&#8217;t help WRT DNS poisoning or other MiTM attacks but will prevent the entire class of obfuscation/redirection tricks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-81</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Thu, 18 Sep 2008 14:02:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-81</guid>
		<description>Shh!  Don&#039;t tell the bad guys!

Well,  the easiest thing to do would be to up the ante a bit on our end and just enter two bad passwords, then the good one.   Obviously this doesn&#039;t scale very well and eventually the phishers could just take the initial credentials and perform their own authentication against the legitimate site to verify whether or not their correct.  That would be the easiest way to foil this little anti-phishing scheme.   

So what is a robust, scalable solution that provides authentication of both the sender and reciever?  How about SSL?  What about single use passwords?  Before you start thinking that these are foolproof, allow me to introduce you to Dan Kaminsky and his work on DNS cache poisoning: https://www.blackhat.com/presentations/bh-usa-08/Kaminsky/08_bhb_od2_slides.m4v</description>
		<content:encoded><![CDATA[<p>Shh!  Don&#8217;t tell the bad guys!</p>
<p>Well,  the easiest thing to do would be to up the ante a bit on our end and just enter two bad passwords, then the good one.   Obviously this doesn&#8217;t scale very well and eventually the phishers could just take the initial credentials and perform their own authentication against the legitimate site to verify whether or not their correct.  That would be the easiest way to foil this little anti-phishing scheme.   </p>
<p>So what is a robust, scalable solution that provides authentication of both the sender and reciever?  How about SSL?  What about single use passwords?  Before you start thinking that these are foolproof, allow me to introduce you to Dan Kaminsky and his work on DNS cache poisoning: <a href="https://www.blackhat.com/presentations/bh-usa-08/Kaminsky/08_bhb_od2_slides.m4v" rel="nofollow">https://www.blackhat.com/presentations/bh-usa-08/Kaminsky/08_bhb_od2_slides.m4v</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manny</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-80</link>
		<dc:creator>Manny</dc:creator>
		<pubDate>Thu, 18 Sep 2008 10:15:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-80</guid>
		<description>Something I thought of this morning, though...  If this catches on big enough, the phishers could have the form reject first then accept the second time.</description>
		<content:encoded><![CDATA[<p>Something I thought of this morning, though&#8230;  If this catches on big enough, the phishers could have the form reject first then accept the second time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-77</link>
		<dc:creator>Jeff</dc:creator>
		<pubDate>Wed, 17 Sep 2008 19:34:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-77</guid>
		<description>If it has been broadcast before, I haven&#039;t heard it until today...  Maybe there&#039;s a flaw in the logic somewhere that somebody can point out, but as of now I&#039;m telling everyone I know!

I think that maybe it&#039;s one of those things that are so simple, we tend to overlook them.</description>
		<content:encoded><![CDATA[<p>If it has been broadcast before, I haven&#8217;t heard it until today&#8230;  Maybe there&#8217;s a flaw in the logic somewhere that somebody can point out, but as of now I&#8217;m telling everyone I know!</p>
<p>I think that maybe it&#8217;s one of those things that are so simple, we tend to overlook them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manny</title>
		<link>http://www.jeffpickell.com/security/simple-way-to-avoid-fake-website-logins/comment-page-1/#comment-76</link>
		<dc:creator>Manny</dc:creator>
		<pubDate>Wed, 17 Sep 2008 19:31:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.vxrs.com/?p=54#comment-76</guid>
		<description>Nice.  It&#039;s so simplistic and seems fail safe.  Wonder why it hasn&#039;t been broadcast more than it has?  (Or has it? ;) )</description>
		<content:encoded><![CDATA[<p>Nice.  It&#8217;s so simplistic and seems fail safe.  Wonder why it hasn&#8217;t been broadcast more than it has?  (Or has it? <img src='http://www.jeffpickell.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  )</p>
]]></content:encoded>
	</item>
</channel>
</rss>
