Friday 4th July 2008

OpenID Guerrillas: Day Five

March 7th, 2008 at 16:22 by Kelly Dorset

Yes we did meet up last night :)

  • Tam continued is work on some prototypes for how we’d model the login boxes for the community site with OpenID in mind. You can take a look at his current prototype concepts.
  • Colin has resurrected his work with combining OpenID with Cryptocard’s two part auth system. He’s been struggling with getting the RADIUS client working.
  • Paul consulted with Nigel (one of our architects) about how to get OpenID into our portal authentication system. There’s a convenient spot for it to go in, a gotcha to do with accessing a PlusNet identity provider from a PlusNet webserver and the necessity of a security review of any code added intended for live.

What did I do? I refreshed myself on the phishing stuff following last weeks Cryptocard conversation. I was mostly working through the examples talked about in Marco Slot’s Beginners Guide to OpenID Phishing.
He describes 3 different ‘levels of phishing’ which openID is susceptible to. I’ve made the links available to our developers internally to make sure they are aware of thinking of these things.

I can’t help but wonder if you can get around the ‘level 2′ phishing approach via the use of some sort of referrer checking. I.e. are the images being loaded on this page being called from the correct OpenID login form. If not, display phishing warnings. Is that simple to get around? Or does it add a sufficient level of difficulty for the phishermen to not warrant the effort?

Feel free to debate below :D

Kelly

This entry was posted by Kelly Dorset on Friday, March 7th, 2008 at 4:22 pm and is tagged with and is posted in the category OpenID Guerrillas, Web Development. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.


3 comments on "OpenID Guerrillas: Day Five"

Tamlyn

Referrer checking on images is easily overcome by changing the image source to point to a proxy on the phishing server which loads the correct images from the identity provider by sending a fake referer header.

Kelly

Does that add enough faff to the phish attempt to discourage it? Or is it dead simple ™?

Tamlyn

Seems fairly simple. In effect the attacker is indistinguishable from a genuine user so there’s no way of preventing it from loading all the relevant content (text, images, stylesheets, scripts) from the identity provider. From that point it’s just a case of spitting it out again to the victim of the attack. It’s a tricky one.

Add a Comment




Photos

photo photo photo photo photo photo

View More

Forums

Users online: 95

  • Total Topics: 65539
  • Total Posts: 527876
  • Total Members: 8850

Visit the Forums

PlusNet

Force9

Metronet

Free-Online

PAYH

Site Links

Related Sites

Community Apps

Here at PlusNet we're always trying to use clever open source things to make our lives easier. Sometimes we write our own and make other people's lives easier too!

View the PlusNet Open Source applications page

About PlusNet

Winner of 9 out of 11 Categories in the 2008 USwitch survey. Winner of "Best Consumer ISP" at 2008 ISPA awards. Voted number 1 in the Broadband Choices 2008 survey.

PlusNet Broadband

© PlusNet plc All Rights Reserved. E&OE

Community Site News is powered by WordPress

Add to Technorati Favourites