4 ms·
Phishing is the biggest risk/threat. An average user is typing in his username and password if presented with a decently familiar login form no matter what the
by markkum 15y ago
Phishing is the biggest risk/threat. An average user is typing in his username and password if presented with a decently familiar login form no matter what the browser address bar or the rest of the web page says. Unfortunately the PayPal and Verisign keyfob security codes can also be phished.
- jayfuerstenberg 15y agoThis is regrettably very true.
- peterwwillis 15y agoYes, but most authentication mechanisms I know of don't deal with phishing. There's probably some challenge-response authentication system you could use, like... a browser plug-in that talks to the keyfob smart card and does a couple challenges to verify the server is for real... but i'm talking out my ass because i'm not a crypto guy. Anyway, dual auth is still much better than just a password, assuming your user understands what phishing is or how to spot it.