Re: Understanding response protocols2004-09-17 17:01:51Keith Moore wrote: But there's another wrinkle in that the ability to redirect replies is arguably a security risk.[*] Say an attacker forges a message from someone's boss that tells its recipient to do something costly and irreversible.[...] Alerts are little more than a band-aid -- the real issue is the need for authentication, avoiding the forgery in the first place.
|
|