OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

 


 

   RE: [xml-dev] Re: Cookies at XML Europe 2004 -- Call for Particip ation

[ Lists Home | Date Index | Thread Index ]

At 1:51 PM -0500 1/6/04, Ralph Hilken wrote:


>In addition to HTTP authentication not being deployed due to lack of
>popularity or experience with it, there are the recent "phishing"
>exploits publicized, with warnings published by E-Week:
>  http://www.eweek.com/article2/0,4149,1409700,00.asp
>  http://www.eweek.com/article2/0,4149,1399670,00.asp
>
>and Microsoft:
>  http://support.microsoft.com/?id=833786


These appear to not be directly related to HTTP authentication. They 
simply fool the user into thinking they are at a different site than 
they actually are. HTTP authentication and cookie based 
authentication are equally vulnerable to this style of social 
engineering.
-- 

   Elliotte Rusty Harold
   elharo@metalab.unc.edu
   Effective XML (Addison-Wesley, 2003)
   http://www.cafeconleche.org/books/effectivexml
   http://www.amazon.com/exec/obidos/ISBN%3D0321150406/ref%3Dnosim/cafeaulaitA




 

News | XML in Industry | Calendar | XML Registry
Marketplace | Resources | MyXML.org | Sponsors | Privacy Statement

Copyright 2001 XML.org. This site is hosted by OASIS