[132830] in cryptography@c2.net mail archive
"usable security" at www.usable.com
daemon@ATHENA.MIT.EDU (Alan Barrett)
Tue Sep 9 09:15:01 2008
Date: Tue, 9 Sep 2008 11:55:53 +0200
From: Alan Barrett <apb@cequrux.com>
To: cryptography@metzdowd.com
Reply-To: cryptography@metzdowd.com
www.usable.com has launched a new password management service intended
to make it easy to login to participating web sites. However, I don't
see any details of the protocols or algorithms. In particular, I don't
see any mention of whether or not the system even attempts to prevent
people with access to the servers at usable.com from having the ability
to impersonate users of the service.
--apb (Alan Barrett)
---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com