Locked Cookies: Web Authentication Security Against Phishing, Pharming, and Active Attacks
File Size:
1KB
Developer:
Description:
This paper proposes new methods for web authentication that are secure against phishing and pharming attacks. We explore the use of browser cookies as authenticators that cannot inadvertently be given away by users, and introduce locked cookies, which are cookies that are bound to the originating server¡¯s public key.