<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Fighting phishing with counter-passwords</title>
	<atom:link href="http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/feed" rel="self" type="application/rss+xml" />
	<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords</link>
	<description>It's all spinning wheels and self-doubt until the first pot of coffee.</description>
	<lastBuildDate>Thu, 11 Mar 2010 12:23:09 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0-alpha</generator>
	<item>
		<title>By: dieter.ca/blog &#187; Blog Archive &#187; Links, Week 41/05</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-10318</link>
		<dc:creator>dieter.ca/blog &#187; Blog Archive &#187; Links, Week 41/05</dc:creator>
		<pubDate>Thu, 27 Apr 2006 20:09:25 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-10318</guid>
		<description>&lt;p&gt;[...] An interesting counter-phishing idea. [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] An interesting counter-phishing idea. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dougal Campbell</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2503</link>
		<dc:creator>Dougal Campbell</dc:creator>
		<pubDate>Fri, 14 Oct 2005 21:31:50 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2503</guid>
		<description>&lt;p&gt;Several sites I deal with already do something along these lines. For example, many banks and credit card companies will start the messages with something like &quot;This message is in regard to your account ending with 9876&quot;. And some other sites will include your full name and/or login name. Which may or may not be useful, depending on how public that information is on that particular site (or in general).&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Several sites I deal with already do something along these lines. For example, many banks and credit card companies will start the messages with something like &#8220;This message is in regard to your account ending with 9876&#8243;. And some other sites will include your full name and/or login name. Which may or may not be useful, depending on how public that information is on that particular site (or in general).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Saltation</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2499</link>
		<dc:creator>Saltation</dc:creator>
		<pubDate>Fri, 14 Oct 2005 13:55:26 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2499</guid>
		<description>&lt;p&gt;gads, someone who knows what &quot;shibboleth&quot; means&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>gads, someone who knows what &#8220;shibboleth&#8221; means</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bhiv</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2490</link>
		<dc:creator>bhiv</dc:creator>
		<pubDate>Thu, 13 Oct 2005 20:40:47 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2490</guid>
		<description>&lt;p&gt;How about entering a serious of gibberish into the phisher&#039;s database? This way, when they try out their database the institution (say paypal.com) can notice that there are many failed logins from them? Or even automate it (amavis flags phishing attempts)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>How about entering a serious of gibberish into the phisher&#8217;s database? This way, when they try out their database the institution (say paypal.com) can notice that there are many failed logins from them? Or even automate it (amavis flags phishing attempts)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Seitz</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2488</link>
		<dc:creator>Bill Seitz</dc:creator>
		<pubDate>Thu, 13 Oct 2005 19:26:08 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2488</guid>
		<description>&lt;p&gt;Wouldn&#039;t it be simpler to generate a custom From address which you could add to your AddressBook/WhiteList? Of course, you have to worry about having multiple computers with unsynched WhiteLists...&lt;/p&gt;

&lt;p&gt;Then of course there&#039;s the custom RSS feed to get you to subscribe to...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it be simpler to generate a custom From address which you could add to your AddressBook/WhiteList? Of course, you have to worry about having multiple computers with unsynched WhiteLists&#8230;</p>
<p>Then of course there&#8217;s the custom RSS feed to get you to subscribe to&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Brubeck</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2487</link>
		<dc:creator>Matt Brubeck</dc:creator>
		<pubDate>Thu, 13 Oct 2005 18:53:20 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2487</guid>
		<description>&lt;p&gt;This has the &lt;a href=&quot;http://usablesecurity.com/2005/07/23/simon-says/&quot; rel=&quot;nofollow&quot;&gt;Simon Says problem&lt;/a&gt;:  It requires users to notice when something is &lt;em&gt;not&lt;/em&gt; present.  For the same reason that users don&#039;t notice the absense of the SSL &quot;lock&quot; icon, they won&#039;t notice the absence of the counter-password or passmark or whatever -- at least not enough of the time.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>This has the <a href="http://usablesecurity.com/2005/07/23/simon-says/" rel="nofollow">Simon Says problem</a>:  It requires users to notice when something is <em>not</em> present.  For the same reason that users don&#8217;t notice the absense of the SSL &#8220;lock&#8221; icon, they won&#8217;t notice the absence of the counter-password or passmark or whatever &#8212; at least not enough of the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2486</link>
		<dc:creator>Nick</dc:creator>
		<pubDate>Thu, 13 Oct 2005 18:43:59 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2486</guid>
		<description>&lt;p&gt;&lt;i&gt;&lt;b&gt;Psycho:&lt;/b&gt; The name&#039;s Francis Sawyer, but everybody calls me Psycho. Any of you guys call me Francis, and I&#039;ll kill you.&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&lt;b&gt;Leon:&lt;/b&gt; Ooooooh.&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&lt;b&gt;Psycho:&lt;/b&gt; You just made the list, buddy. Also, I don&#039;t like no one touching my stuff. So just keep your meathooks off. If I catch any of you guys in my stuff, I&#039;ll kill you. And I don&#039;t like nobody touching me. Any of you homos touch me, and I&#039;ll kill you.&lt;/i&gt;&lt;/p&gt;

&lt;p&gt;&lt;i&gt;&lt;b&gt;Sergeant Hulka:&lt;/b&gt; Lighten up, Francis. &lt;/i&gt;

I notice that the Bank of America website calls it a passmark.  I like that.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><i><b>Psycho:</b> The name&#8217;s Francis Sawyer, but everybody calls me Psycho. Any of you guys call me Francis, and I&#8217;ll kill you.</i></p>
<p><i><b>Leon:</b> Ooooooh.</i></p>
<p><i><b>Psycho:</b> You just made the list, buddy. Also, I don&#8217;t like no one touching my stuff. So just keep your meathooks off. If I catch any of you guys in my stuff, I&#8217;ll kill you. And I don&#8217;t like nobody touching me. Any of you homos touch me, and I&#8217;ll kill you.</i></p>
<p><i><b>Sergeant Hulka:</b> Lighten up, Francis. </i></p>
<p>I notice that the Bank of America website calls it a passmark.  I like that.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2485</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Thu, 13 Oct 2005 18:13:12 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2485</guid>
		<description>&lt;p&gt;Ummm why fool around with stenography when we&#039;ve got such an abundance of public key schemes? And no I don&#039;t think &#039;lightweight&#039; or &#039;too hard for aunt minnie&#039; count as reasonable answers. If it&#039;s worth doing it&#039;s worth doing well.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ummm why fool around with stenography when we&#8217;ve got such an abundance of public key schemes? And no I don&#8217;t think &#8216;lightweight&#8217; or &#8216;too hard for aunt minnie&#8217; count as reasonable answers. If it&#8217;s worth doing it&#8217;s worth doing well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sencer</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2484</link>
		<dc:creator>Sencer</dc:creator>
		<pubDate>Thu, 13 Oct 2005 18:01:39 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2484</guid>
		<description>&lt;p&gt;Actually that&#039;s already being done by some banks in a slightly different way. Schneier was writing on hos blog about it a while back. Here is an example of it:&lt;/p&gt;

&lt;p&gt;http://www.bankofamerica.com/privacy/passmark/&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Actually that&#8217;s already being done by some banks in a slightly different way. Schneier was writing on hos blog about it a while back. Here is an example of it:</p>
<p><a href="http://www.bankofamerica.com/privacy/passmark/" rel="nofollow">http://www.bankofamerica.com/privacy/passmark/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dorothea</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2482</link>
		<dc:creator>Dorothea</dc:creator>
		<pubDate>Thu, 13 Oct 2005 17:53:41 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2482</guid>
		<description>&lt;p&gt;The credit union I used in Madison (uwcu.org) does this. I gave their system an incredibly silly but highly memorable phrase from a college roleplaying campaign, and they include it in the email they send me.&lt;/p&gt;

&lt;p&gt;Which never fails to make me grin. Added bonus.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The credit union I used in Madison (uwcu.org) does this. I gave their system an incredibly silly but highly memorable phrase from a college roleplaying campaign, and they include it in the email they send me.</p>
<p>Which never fails to make me grin. Added bonus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roger Benningfield</title>
		<link>http://decafbad.com/blog/2005/10/13/fighting-phishing-with-counter-passwords/comment-page-1#comment-2481</link>
		<dc:creator>Roger Benningfield</dc:creator>
		<pubDate>Thu, 13 Oct 2005 17:23:20 +0000</pubDate>
		<guid isPermaLink="false">http://decafbad.com/blog/?p=735#comment-2481</guid>
		<description>&lt;p&gt;How about &quot;lightweight credentials&quot;?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>How about &#8220;lightweight credentials&#8221;?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
