<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>@Lathi.net: Servers Identifying Themselves (Anti-Phishing)</title>
    <link>http://blog.lathi.net/articles/2005/07/01/servers-identifying-themselves-anti-phishing</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>On Life, Fatherhood, Christianity, and Computers</description>
    <item>
      <title>Servers Identifying Themselves (Anti-Phishing)</title>
      <description>Part of the problem with passwords is that users can be tricked into giving them to the wrong people.  &lt;a href="http://www.tygar.net/papers/Battle_against_phishing.pdf" target="_top"&gt;This (pdf)&lt;/a&gt; is a proposal to help combat that.  &lt;a href="http://www.schneier.com/blog/" target="_top"&gt;Bruce Schneier&lt;/a&gt;, my favorite security guru, &lt;a href="http://www.schneier.com/blog/archives/2005/07/security_skins.html" target="_top"&gt;points&lt;/a&gt; out a method developed by Rachna Dhamija and Doug Tygar of UC Berkeley for servers to identify themselves.  To be honest, I haven&amp;#8217;t read the paper from Dhamija and Tygar; just Bruce&amp;#8217;s summary.  However, it seems like a really cool idea.
&lt;p /&gt;
Basically, the server generates a unique abstract image to associate itself with each user.  When the server asks for authentication, it displays the image.  The user can visually determine if the right image is displayed to verify that the web page is authentic.  
&lt;p /&gt;
Of course, what users are supposed to do is examine the &lt;span class="caps"&gt;SSL&lt;/span&gt; certificate for the site.  No one does this.  In fact, browsers are making this harder to do.  So servers have it in their best interest to make sure that users know they are the legit server.  They suffer as much from phishing as the victim user does.
&lt;p /&gt;
I might try to figure out how to implement this nicely with some of my web sites.</description>
      <pubDate>Fri, 01 Jul 2005 13:14:00 -0500</pubDate>
      <guid isPermaLink="false">urn:uuid:a007b5aa42299d52d7c7a1fc24a68ac4</guid>
      <author>Doug</author>
      <link>http://blog.lathi.net/articles/2005/07/01/servers-identifying-themselves-anti-phishing</link>
      <category>Security</category>
    </item>
  </channel>
</rss>

