[114854] in cryptography@c2.net mail archive
Re: Fixing SSL (was Re: Dutch Transport Card Broken)
daemon@ATHENA.MIT.EDU (Taral)
Sat Feb 9 23:56:54 2008
Date: Sat, 9 Feb 2008 20:14:41 -0800
From: Taral <taralx@gmail.com>
To: "David Wagner" <daw@cs.berkeley.edu>
Cc: cryptography@metzdowd.com
In-Reply-To: <200802100104.m1A14S4a015492@taverner.cs.berkeley.edu>
On 2/9/08, David Wagner <daw@cs.berkeley.edu> wrote:
> By the way, it seems like one thing that might help with client certs
> is if they were treated a bit like cookies.
I don't see how this helps with phishing. Phishers will just go after
the password or other secrets used to authenticate a new system or a
system that has lost its cert.
--
Taral <taralx@gmail.com>
"Please let me know if there's any further trouble I can give you."
-- Unknown
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com