[OpenID] Phishing resistant policy of PAPE

Eric Norman ejnorman at doit.wisc.edu
Wed Oct 29 00:12:22 UTC 2008


On Oct 28, 2008, at 6:41 PM, Breno de Medeiros wrote:

> The phishing attack that you presented above is not a phishing attack
> that can be prevented.

Information cards seem to provide effective resistance.
Some argue that EV certificates provide such resistance.
Some even argue that regular old server certificates can
provide such resistance.

Eric Norman





More information about the general mailing list