Bill said he wanted a piece of paper that could help verify his bank's certificate. I claimed he's in the extreme minority who would do that and he asked for proof.
I can only, vaguely, recall that one of the East Coast big banks (or perhaps the only one that is left) at one point had a third-party cert for their online banking and that it "encouraged" phishing of their customers. See also http://en.wikipedia.org/wiki/Phishing#cite_note-87 and http://en.wikipedia.org/wiki/Phishing#cite_note-88 which say simple things like "show the right image" don't work. /r$ -- Principal Security Engineer Akamai Technology Cambridge, MA _______________________________________________ The cryptography mailing list cryptography@metzdowd.com http://www.metzdowd.com/mailman/listinfo/cryptography