3 ms·
Absolutely. Which is why I think we still have a lot of work ahead of us, making users actually check the domain name, and the validated identity (for EV certs)
by phlo 10y ago
Absolutely. Which is why I think we still have a lot of work ahead of us, making users actually check the domain name, and the validated identity (for EV certs).
- afarrell 10y agoHaving them use a passsword manager is a better apporach. Checking the domain name is weak to keming probiems.
- phlo 10y ago...and password managers are weak to lots of problems [1], the least of which is malware stealing your password container plus the master key [2]. I'm still leaning towards the password manager side of the dilemma, but the situation isn't great on either. [1] https://twitter.com/taviso/status/769378052254015488 https://twitter.com/taviso/status/769378052254015488 [2] http://arstechnica.com/security/2014/11/citadel-attackers-aim-to-steal-victims-master-passwords/ http://arstechnica.com/security/2014/11/citadel-attackers-ai...