identity in the browser or putting the cart before the
play

Identity in the Browser -or- Putting the Cart Before the Horse? - PowerPoint PPT Presentation

Identity in the Browser -or- Putting the Cart Before the Horse? Andy Steingruebl and Jeff Hodges {asteingruebl,jeff.hodges}@paypal.com PayPal Information Risk Management Position Paper for W3C Workshop on Identity in the Browser May 24


  1. Identity in the Browser -or- Putting the Cart Before the Horse? Andy Steingruebl and Jeff Hodges {asteingruebl,jeff.hodges}@paypal.com PayPal Information Risk Management Position Paper for W3C Workshop on Identity in the Browser May 24 and 25, 2011 – Mountain View, CA

  2. Given that... ● Online user credentials today are typically ● Reusable ● employ shared secrets (aka “passwords”) ● Users will enter their credentials into most any online form ● People can and will divulge their credentials when nominally prompted

  3. Then... ● Phishing is fun and profitable!

  4. Also, since... ● Mobile handheld ubiquitously Internet- connected third-party programmable devices == “smartphones” ● Smartphones are a different sort of computer ● Smaller keyboards and screens ● Power limitations ● Social connotations ● Smartphone adoption is skyrocketing

  5. Then... ● We really need to think differently about user authentication on smartphone platforms, otherwise... ● Phishing will be even more fun and profitable!

  6. And since... ● All sorts of boxes/things feature a web server... ● ...hosting configuration/management interfaces ● E.g... ● Network middleboxes ● Appliances ● Industrial control systems ● Vehicles (soon?) ● Vulnerable to Cross-Site Request Forgery (CSRF)

  7. Then... ● Might be even more fun than phishing...

  8. Present Workshop Goal... ● Solutions to be explored are effective enhancements to Web browsers that lead to trustworthy benefits that can be realized in the near term

  9. Rethink/Refine Our Goals... ● User authentication without phishable credentials? ● How to mitigate CSRF? ● Get heads around new world of smartphones? ● New paradigms for security indicators? ● More consistent security characteristics across major browsers?

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend