W3C home > Mailing lists > Public > public-wsc-wg@w3.org > February 2007

Better HTTP authentication scheme that's phish-proof?

From: Mike Beltzner <beltzner@mozilla.com>
Date: Tue, 13 Feb 2007 00:20:35 -0500
Message-Id: <29D70F06-5962-4EB2-86C3-117739393BDF@mozilla.com>
To: public-wsc-wg@w3.org

My colleague Robert Sayre has proposed that a lot of phishing  
problems could be solved if better HTTP authentication was used. I  
thought that this crowd might be interested:

http://www.franklinmint.fm/blog/archives/000843.html

There's also a proof-of-concept snippet of Python in this bug for  
those who want to get their hands dirty; the Python's pretty easy to  
read, and well commented:

https://bugzilla.mozilla.org/show_bug.cgi?id=356855

cheers,
mike
Received on Tuesday, 13 February 2007 05:20:48 GMT

This archive was generated by hypermail 2.2.0+W3C-0.50 : Tuesday, 5 February 2008 03:52:45 GMT