Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: (secure email) Proposal to anti-phishing |
|---|---|
| Date: | Mon, 24 Jan 2005 18:26:40 +1100 |
-----Original Message----- From: Michael Silk [mailto:michaelsilk@gmail.com] Sent: Monday, 24 January 2005 3:24 PM To: lyal.collins@key2it.com.au; webappsec@securityfocus.com Subject: RE: (secure email) Proposal to anti-phishing Lyal said:The difference is that client-side SSL exists today in anindustrystandard platform independent manner that could be effectively deployed. (management is a different issue that I will be acoward andignore for now.)It's hard to see how changing the locaiton of a password verification actually makes any difference to accountholder security or phishing.Is it? Surely it's easy to see. Phishing requries the user to enter the password in a website. If they don't need to do this (or only enter partial password) because of certificate, then I think it's pretty easy to see how that is an advantage.
Seen the newer generaitons of phishing, where going to the faked bank site loads up the user's PC with spyware, keyloggers et al? Certificates are compromised as soon as any malware enters the machine - which is useless in this phishing scenario.
And then there's the pragmatic fact that people will payMicrosoftprotection-racket funds for Microsoft anti-spyware to protect themselves transparently in the background from thecrappy softwareMicrosoft *SOLD* them in the first place...and they will dothis longbefore they'll use any of the "secure email" solutions today that require user interaction & thought. But I'm all for an global standard secure email solution ifyou happento have one of those handy,Actually, my company does - if anyone wants to buy it.Global, is it? Who buys it then? How does it work? Care to share more details, because there is not much information on your site. Doesn't seem any different to what PGP would provide. It's also rather interesting that you claim it "encrypts" everything, but also analyses it for spam, viruses ... now just how does it do that :) ? And what is "content checked". Seems far to "big brother" for my liking.
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Proposal to anti-phishing, Lyal Collins |
|---|---|
| Next by Date: | Re: Content monitorting in Application Security, Martin Schapendonk |
| Previous by Thread: | RE: (secure email) Proposal to anti-phishing, Michael Silk |
| Next by Thread: | Re: (secure email) Proposal to anti-phishing, Michael Silk |
| Indexes: | [Date] [Thread] [Top] [All Lists] |