[oauth] Re: OAuth Security Advisory

2009-04-25 Thread Mike Panchenko
lar to the way banks show the user some small thumbnail to verify that it is indeed their site you're looking at to combat phishing." Mike. On Sat, Apr 25, 2009 at 11:46 AM, Mike Panchenko wrote: > Pardon me if this seems naive, but if we're considering a solution in which >

[oauth] Re: OAuth Security Advisory

2009-04-27 Thread Mike Panchenko
Pardon me if this seems naive, but if we're considering a solution in which the user enters a pin at both ends, perhaps a better solution to use an image instead, the way banks make show you some small thumbnail to verify that it is indeed their site you're looking at. Perhaps the provider could ma