[oauth] Re: OAuth Security Advisory

2009-04-27 Thread Mike Panchenko
Pardon me if this seems naive, but if we're considering a solution in which the user enters a pin at both ends, perhaps a better solution to use an image instead, the way banks make show you some small thumbnail to verify that it is indeed their site you're looking at. Perhaps the provider could

[oauth] Re: OAuth Security Advisory

2009-04-25 Thread Mike Panchenko
to the way banks show the user some small thumbnail to verify that it is indeed their site you're looking at to combat phishing. Mike. On Sat, Apr 25, 2009 at 11:46 AM, Mike Panchenko drwol...@gmail.com wrote: Pardon me if this seems naive, but if we're considering a solution in which the user enters