Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Article - A solution to phishing |
|---|---|
| Date: | Sat, 27 Nov 2004 10:18:58 -0600 |
Quoting Michael Silk <michaelsilk@gmail.com>:
Hi Christopher,
Thanks for your feedback, let me address it.
First let me say that many people have raised
the issue (privately) of unecrypted emails not
being good enough - and they have a point. So
from now onwards let us assume that public
key/private key exchange system is used to
communicate the emails such that:
And if they are using a public key system, why would you bother with email then? Just make them use the private key to authenticate to the website. There is STILL no opportunity for phishing, as the user never types in any details. They simply authenticate the SSL session using the cert, and there are no further opportunities for information theft. Sounds to me like you just want to use email in there somewhere! ;-) Rogan
| Previous by Date: | Re: Article - A solution to phishing, focus |
|---|---|
| Next by Date: | Fwd: PHP Easter Eggs, Andi McLean |
| Previous by Thread: | RE: Article - A solution to phishing, Michael Silk |
| Next by Thread: | Re: Article - A solution to phishing, Joseph Miller |
| Indexes: | [Date] [Thread] [Top] [All Lists] |