On Thu, 16 Oct 2014 11:22:59 -0700 (PDT) Andrew Morgan <mor...@orst.edu> wrote:
> The pictures would be displayed after the user has entered their username > and password (if I understand this correctly). I don't think so: quoting Bryan, "will be presented with multiple pictures and must select the correct one before being prompted for their password". I think it tries to stop automated abuse with phished credentials rather than prevent MITM attacks. -- Alberto Cabello Sánchez <albe...@unex.es> -- You are currently subscribed to cas-user@lists.jasig.org as: arch...@mail-archive.com To unsubscribe, change settings or access archives, see http://www.ja-sig.org/wiki/display/JSG/cas-user