[Fwd: BugTraq - how to coverup the security]

Sean Smith sws at cs.dartmouth.edu
Mon Jul 14 20:51:11 EDT 2003

Does this really surprise anyone?  

When I had some students try this out (providing content
that browsers render in a way that makes it look like security 
info from the browser) a few years ago, there was just no end
to the tricks one could play...

If you don't design a trusted path into the system, why should
you expect there to be one?


Sean W. Smith, Ph.D.                         sws at cs.dartmouth.edu   
http://www.cs.dartmouth.edu/~sws/       (has ssl link to pgp key)
Department of Computer Science, Dartmouth College, Hanover NH USA

