View Single Post
  #4 (permalink)  
Old 08-22-2006, 06:23 PM
David's Avatar
David David is offline
Senior Member
 

Join Date: Apr 2003
Location: Portland, OR
Posts: 5,288
David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)David is a name known to all (400)
Send a message via AIM to David
That's utterly useless.

Bank of America's online banking application has been using this for quite a while now, but they used a server-basesd solution. it's called a SiteKey, and you select it once, and it's shown regardless of the browser.

The very fact that it's cookies based makes it just as easy for the phishing site to say "oh, your cookie is gone, create a new seal."

Great concept, horrible implementation.
Reply With Quote