4 ms·
SiteKey is completely susceptible to Man-in-the-middle (unless the user is a scrupulous cookie-manager and refuses to re-authenticate a computer more than once)
by gerts 14y ago
SiteKey is completely susceptible to Man-in-the-middle (unless the user is a scrupulous cookie-manager and refuses to re-authenticate a computer more than once), so adds minimal value over regular SSL.
- jaylevitt 14y agoSiteKey is also trivially vulnerable to the attack known as "I bet you didn't remember that this page should show you a SiteKey."