<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: MyOpenID: New anti-phishing tools available</title>
	<atom:link href="http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/feed/" rel="self" type="application/rss+xml" />
	<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/</link>
	<description>Father, entrepreneur, pizza maker &#38; bacon lover</description>
	<lastBuildDate>Mon, 22 Feb 2010 20:18:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: The Security Roundtable &#187; Blog Archive &#187; The Security Roundtable for February 2007 - OpenID</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-14900</link>
		<dc:creator>The Security Roundtable &#187; Blog Archive &#187; The Security Roundtable for February 2007 - OpenID</dc:creator>
		<pubDate>Thu, 15 Mar 2007 19:55:56 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-14900</guid>
		<description>[...] Ideas to respond: http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Ideas to respond: <a href="http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/" rel="nofollow">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID的安全性问题 &#124; OpenID Planet-OpenID动态，关注网站身份验证服务</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-11964</link>
		<dc:creator>OpenID的安全性问题 &#124; OpenID Planet-OpenID动态，关注网站身份验证服务</dc:creator>
		<pubDate>Thu, 01 Mar 2007 05:27:44 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-11964</guid>
		<description>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</description>
		<content:encoded><![CDATA[<p>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID的安全性问题 &#124; OpenID Planet</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-9739</link>
		<dc:creator>OpenID的安全性问题 &#124; OpenID Planet</dc:creator>
		<pubDate>Tue, 13 Feb 2007 03:42:35 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-9739</guid>
		<description>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</description>
		<content:encoded><![CDATA[<p>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID的安全性问题 at OpenID Planet</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-9695</link>
		<dc:creator>OpenID的安全性问题 at OpenID Planet</dc:creator>
		<pubDate>Mon, 12 Feb 2007 17:02:44 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-9695</guid>
		<description>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</description>
		<content:encoded><![CDATA[<p>[...] 这些办法之中的任何一个都不可能完全的解决OpenID的安全问题，但是如果把这些办法都综合起来成为一个工具，那是否可以解决部分问题呢？ [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charles Darke</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-8607</link>
		<dc:creator>Charles Darke</dc:creator>
		<pubDate>Tue, 06 Feb 2007 22:39:28 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-8607</guid>
		<description>I&#039;ve put up proof of concept code which validates against IP instead of using passwords so there is no opportunity to phish.

See http://digitalconsumption.com/forum/A-simple-solution-to-OpenID-phishing-attacks</description>
		<content:encoded><![CDATA[<p>I&#8217;ve put up proof of concept code which validates against IP instead of using passwords so there is no opportunity to phish.</p>
<p>See <a href="http://digitalconsumption.com/forum/A-simple-solution-to-OpenID-phishing-attacks" rel="nofollow">http://digitalconsumption.com/forum/A-simple-solution-to-OpenID-phishing-attacks</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID And Phishing on iface thoughts</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-7823</link>
		<dc:creator>OpenID And Phishing on iface thoughts</dc:creator>
		<pubDate>Fri, 02 Feb 2007 05:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-7823</guid>
		<description>[...] Well, one of the solutions is to tell the provider to not ask for a password when redirected from other sites. What you do is whenever you start surfing, first log into your OpenID provider. Now you are not redirected to your provider for entering your password. MyOpenID.com has implemented this anti-phishing technique. [...]</description>
		<content:encoded><![CDATA[<p>[...] Well, one of the solutions is to tell the provider to not ask for a password when redirected from other sites. What you do is whenever you start surfing, first log into your OpenID provider. Now you are not redirected to your provider for entering your password. MyOpenID.com has implemented this anti-phishing technique. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clipperz</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-7766</link>
		<dc:creator>Clipperz</dc:creator>
		<pubDate>Thu, 01 Feb 2007 16:16:05 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-7766</guid>
		<description>&lt;strong&gt;OpenID, before you get too excited...&lt;/strong&gt;

In the last months OpenID definitely gained momentum. Everyone is running to provide support and integration.

But what about OpenID phishing risks?

It&#8217;s undeniably true that OpenID makes life easier to phishers: they no longer have to mimic Pay...</description>
		<content:encoded><![CDATA[<p><strong>OpenID, before you get too excited&#8230;</strong></p>
<p>In the last months OpenID definitely gained momentum. Everyone is running to provide support and integration.</p>
<p>But what about OpenID phishing risks?</p>
<p>It&#8217;s undeniably true that OpenID makes life easier to phishers: they no longer have to mimic Pay&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jack Mottram</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-6926</link>
		<dc:creator>Jack Mottram</dc:creator>
		<pubDate>Thu, 25 Jan 2007 13:24:14 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-6926</guid>
		<description>Nice one. It&#039;s especially good to see how quickly the MyOpenID folk reacted to the phishing concerns.

Also, that&#039;s a good point you made about OpenID being vulnerable to phishing, but also having a certain degree of protection built in thanks to user familiarity with their login page.</description>
		<content:encoded><![CDATA[<p>Nice one. It&#8217;s especially good to see how quickly the MyOpenID folk reacted to the phishing concerns.</p>
<p>Also, that&#8217;s a good point you made about OpenID being vulnerable to phishing, but also having a certain degree of protection built in thanks to user familiarity with their login page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luis</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-6868</link>
		<dc:creator>Luis</dc:creator>
		<pubDate>Wed, 24 Jan 2007 16:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-6868</guid>
		<description>Well, pass on the congrats to them, then. I&#039;m sure they&#039;ve been hearing a lot of it, of course.</description>
		<content:encoded><![CDATA[<p>Well, pass on the congrats to them, then. I&#8217;m sure they&#8217;ve been hearing a lot of it, of course.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kveton</title>
		<link>http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/comment-page-1/#comment-6867</link>
		<dc:creator>kveton</dc:creator>
		<pubDate>Wed, 24 Jan 2007 16:35:54 +0000</pubDate>
		<guid isPermaLink="false">http://kveton.com/blog/2007/01/24/myopenid-new-anti-phishing-tools-available/#comment-6867</guid>
		<description>I&#039;m just the guy that does the blog posts ... :-) ... its the team of dedicated developers here at &lt;a href=&quot;http://janrain.com&quot; rel=&quot;nofollow&quot; rel=&quot;nofollow&quot;&gt;JanRain&lt;/a&gt; that is doing the hard work ... glad it worked for you!</description>
		<content:encoded><![CDATA[<p>I&#8217;m just the guy that does the blog posts &#8230; :-) &#8230; its the team of dedicated developers here at <a href="http://janrain.com" rel="nofollow" rel="nofollow">JanRain</a> that is doing the hard work &#8230; glad it worked for you!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
