[147356] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: [Cryptography] PRISM-Proofing and PRISM-Hardening

daemon@ATHENA.MIT.EDU (Salz, Rich)
Mon Sep 30 18:36:00 2013

X-Original-To: cryptography@metzdowd.com
From: "Salz, Rich" <rsalz@akamai.com>
To: Bill Frantz <frantz@pwpconsult.com>
Date: Mon, 30 Sep 2013 14:29:31 -0400
In-Reply-To: <r422Ps-1075i-3A51DFDC59B5484EB372BFE47B8F0DC6@Williams-MacBook-Pro.local>
Cc: "cryptography@metzdowd.com" <cryptography@metzdowd.com>
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com

Bill said he wanted a piece of paper that could help verify his bank's certificate.  I claimed he's in the extreme minority who would do that and he asked for proof.

I can only, vaguely, recall that one of the East Coast big banks (or perhaps the only one that is left) at one point had a third-party cert for their online banking and that it "encouraged" phishing of their customers.  See also http://en.wikipedia.org/wiki/Phishing#cite_note-87 and http://en.wikipedia.org/wiki/Phishing#cite_note-88 which say simple things like "show the right image" don't work.

	/r$

--  
Principal Security Engineer
Akamai Technology
Cambridge, MA
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography

home help back first fref pref prev next nref lref last post