Making Mobile BankID "phishsafe"

HI Guys,

What is your solution for making things like the Swedish and Norwegian Mobile BankID schemes "phishsafe"?
These schemes principally work as my QR-ID demo (although relying on hard-coded URLs):
https://mobilepki.org/webauth/home
https://cyberphone.github.io/openkeystore/resources/docs/QR-ID-presentation.pdf
A nice solution which in spite of using PKI is fully "phishable".

Anders

Received on Sunday, 29 November 2015 08:03:01 UTC