Fixing SSL (was Re: Dutch Transport Card Broken)

Taral taralx at gmail.com
Sat Feb 9 23:14:41 EST 2008


On 2/9/08, David Wagner <daw at cs.berkeley.edu> wrote:
> By the way, it seems like one thing that might help with client certs
> is if they were treated a bit like cookies.

I don't see how this helps with phishing. Phishers will just go after
the password or other secrets used to authenticate a new system or a
system that has lost its cert.

-- 
Taral <taralx at gmail.com>
"Please let me know if there's any further trouble I can give you."
    -- Unknown

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo at metzdowd.com



More information about the cryptography mailing list