3 ms·
Hmm.. so if my browser has integrated support, then any site I visit can add itself to my list of primarity authorities as evil-username@evil-domain. And I will
by extension 15y ago
Hmm.. so if my browser has integrated support, then any site I visit can add itself to my list of primarity authorities as evil-username@evil-domain. And I will be asked to choose one of these authorities to log in to other sites. And a rogue authority can impersonate me on the sites where I use it. Is this correct?
I can see a slight potential to trick the user into using a rogue authority. Imagine the evil email address is somehow tailored to a site the user is expected to log in to, in a way that makes it look like the "right" selection for that site, in the BrowserID dialog. I can't think of an explicit example right now, but when you allow untrusted parties to inject text into trusted dialogs, there are often many possibilities for trickery.
- icebraining 15y agoI'm not sure if "any site I visit can add itself to my list of primarity authorities as evil-username@evil-domain", but I do know that the login to the authority is done using Public Key authentication, which unlike passwords isn't subject to phishing. There's no risk in logging in to a rogue authority, since the key never actually leaves your machine.
- extension 15y agoI don't mean logging into an evil authority, I mean tricking the user into using an evil authority to log in to a relying party. There evidently is or will be a way for web sites to tell your browser that they can serve as a primary authority for some particular email address at their domain. When you visit the evil site, it would register some misleading email address, which your browser would then show in the list of identities whenever you log in to a relying party. At best, we will still need some way of filtering out junk from the identity list.