RE: [dix] Re: [Ietf-http-auth] Notes on Web authenticationenhancements

"Hallam-Baker, Phillip" <pbaker@verisign.com> Tue, 11 July 2006 22:20 UTC

Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1G0Qay-0005FU-9q; Tue, 11 Jul 2006 18:20:45 -0400
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1G0QTk-0003kU-1W for dix@ietf.org; Tue, 11 Jul 2006 18:13:16 -0400
Received: from colibri.verisign.com ([65.205.251.74]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1G0QRg-0005uz-Ma for dix@ietf.org; Tue, 11 Jul 2006 18:11:09 -0400
Received: from MOU1WNEXCN02.vcorp.ad.vrsn.com (mailer2.verisign.com [65.205.251.35]) by colibri.verisign.com (8.13.6/8.13.4) with ESMTP id k6BMB6n9014491; Tue, 11 Jul 2006 15:11:07 -0700
Received: from MOU1WNEXMB04.vcorp.ad.vrsn.com ([10.25.13.157]) by MOU1WNEXCN02.vcorp.ad.vrsn.com with Microsoft SMTPSVC(6.0.3790.1830); Tue, 11 Jul 2006 15:11:06 -0700
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Subject: RE: [dix] Re: [Ietf-http-auth] Notes on Web authenticationenhancements
Date: Tue, 11 Jul 2006 15:11:12 -0700
Message-ID: <198A730C2044DE4A96749D13E167AD37BD61BD@MOU1WNEXMB04.vcorp.ad.vrsn.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [dix] Re: [Ietf-http-auth] Notes on Web authenticationenhancements
Thread-Index: AcalNIcKLSVo4LotT1SetO1+IFWl4QAAb/XQ
From: "Hallam-Baker, Phillip" <pbaker@verisign.com>
To: Dick Hardt <dick@sxip.com>
X-OriginalArrivalTime: 11 Jul 2006 22:11:06.0974 (UTC) FILETIME=[E83C97E0:01C6A536]
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 08170828343bcf1325e4a0fb4584481c
Cc: Digital Identity Exchange <dix@ietf.org>, ietf-http-auth@lists.osafoundation.org, Sam Hartman <hartmans-ietf@mit.edu>
X-BeenThere: dix@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: Digital Identity Exchange <dix@ietf.org>
List-Id: Digital Identity Exchange <dix.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/dix>, <mailto:dix-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/dix>
List-Post: <mailto:dix@ietf.org>
List-Help: <mailto:dix-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/dix>, <mailto:dix-request@ietf.org?subject=subscribe>
Errors-To: dix-bounces@ietf.org

> From: Dick Hardt [mailto:dick@sxip.com] 

> Just to clarify, phishers are spoofing Google and Blogger to 
> steal credentials? If so, I stand corrected.

Not in production yet.

However there are malware companies that use blogger for distributing trojans. It is a small step from that to phish credentials of blogger sites and drop hardcore crimeware onto machines that visit.





_______________________________________________
dix mailing list
dix@ietf.org
https://www1.ietf.org/mailman/listinfo/dix