Re: [dix] Re: [Ietf-http-auth] New draft on anti-phishing requirements
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [dix] Re: [Ietf-http-auth] New draft on anti-phishing requirements



On Thu, May 25, 2006 at 08:20:46AM -0700, Eric Rescorla wrote:
> Chris Drake  <christopher at pobox.com> writes:
> > How do you propose to protect my privacy in this scenario?  I do not
> > want the same credentials of mine revealed when I log in to
> > "shame-your-boss.com" as when I log in to my sourceforge account, but
> > I would like to avoid having to remember multitudes of different
> > usernames and passwords for every web site I visit, as well as enjoy
> > phishing defences... 
> 
> And you'd prefer to have your identity provider have a record
> of every site you've visited?

If you're your own IdP...  Or if your ISP is your IdP... (your ISP
already knows what sites you visit)

_______________________________________________
dix mailing list
dix at ietf.org
https://www1.ietf.org/mailman/listinfo/dix




Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.