Centralized and even federated identity schemes could certainly become a goldmine for phishers and keyloggers. It seems such schemes will require hardware 2 factor authentication to be viable and relatively immune to such attacks.
Has anyone put much thought into vulnerabilities that Microsoft's proposed InfoCard system might face?
Posted by Dave Jevans at July 20, 2005 12:45 PM