<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Warning About ZeuS Attack Used as Lure</title>
	<atom:link href="http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Sat, 11 Feb 2012 19:29:31 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: patrick</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-10743</link>
		<dc:creator>patrick</dc:creator>
		<pubDate>Wed, 29 Sep 2010 06:16:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-10743</guid>
		<description>This just came to my attention. Is WOT which places a little green circle beside the links while browsing in google. But i heard that WOT is a spyware is this ture.

Mr Kreds</description>
		<content:encoded><![CDATA[<p>This just came to my attention. Is WOT which places a little green circle beside the links while browsing in google. But i heard that WOT is a spyware is this ture.</p>
<p>Mr Kreds</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-10743" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('10743', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-10743-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-10743" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('10743', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-10743-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: warning. fake e-mail &#171; What&#39;s Up</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2993</link>
		<dc:creator>warning. fake e-mail &#171; What&#39;s Up</dc:creator>
		<pubDate>Sun, 28 Feb 2010 17:11:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2993</guid>
		<description>[...] I received this fake e-mail. I will be asked to fill in your username and password. This email should go in [...]</description>
		<content:encoded><![CDATA[<p>[...] I received this fake e-mail. I will be asked to fill in your username and password. This email should go in [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2993" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2993', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2993-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2993" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2993', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2993-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: An Information Security Place Podcast &#187; Blog Archive &#187; An Information Security Place Podcast &#8211; Episode 32</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2309</link>
		<dc:creator>An Information Security Place Podcast &#187; Blog Archive &#187; An Information Security Place Podcast &#8211; Episode 32</dc:creator>
		<pubDate>Thu, 18 Feb 2010 13:25:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2309</guid>
		<description>[...] Kreb&#8217;s has blog post used by scammers - Link here and Sophos article link [...]</description>
		<content:encoded><![CDATA[<p>[...] Kreb&#8217;s has blog post used by scammers - Link here and Sophos article link [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2309" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2309', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2309-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2309" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2309', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2309-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: An Information Security Place &#187; An Information Security Place Podcast &#8211; Episode 32</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2307</link>
		<dc:creator>An Information Security Place &#187; An Information Security Place Podcast &#8211; Episode 32</dc:creator>
		<pubDate>Thu, 18 Feb 2010 13:24:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2307</guid>
		<description>[...] Kreb&#8217;s has blog post used by scammers - Link here and Sophos article link [...]</description>
		<content:encoded><![CDATA[<p>[...] Kreb&#8217;s has blog post used by scammers - Link here and Sophos article link [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2307" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2307', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2307-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2307" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2307', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2307-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Usan como señuelo una advertencia sobre ataque de ZeuS &#124; ooo la la la la : ) HACKED ! by ! mOmiX ! Sory Security Team :(((</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2144</link>
		<dc:creator>Usan como señuelo una advertencia sobre ataque de ZeuS &#124; ooo la la la la : ) HACKED ! by ! mOmiX ! Sory Security Team :(((</dc:creator>
		<pubDate>Wed, 17 Feb 2010 12:10:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2144</guid>
		<description>[...] los ataques .mil y .gov.    Traducción: Raúl Batista &#8211; Segu-info Autor: Brian Krebs Fuente: Krebs on Security [...]</description>
		<content:encoded><![CDATA[<p>[...] los ataques .mil y .gov.    Traducción: Raúl Batista &#8211; Segu-info Autor: Brian Krebs Fuente: Krebs on Security [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2144" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2144', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2144-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2144" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2144', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2144-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: IT Ninja</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2134</link>
		<dc:creator>IT Ninja</dc:creator>
		<pubDate>Wed, 17 Feb 2010 07:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2134</guid>
		<description>people should just accept the fact that nowadays nothing is impossible anymore specially online. its that simple.

Btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful reasons. Here’s the link :

http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html</description>
		<content:encoded><![CDATA[<p>people should just accept the fact that nowadays nothing is impossible anymore specially online. its that simple.</p>
<p>Btw, the National Security Agency was recently hacked. Yes hacked! But it was downplayed to the media for obvious shameful reasons. Here’s the link :</p>
<p><a href="http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html" rel="nofollow">http://pinoysecurity.blogspot.com/2010/02/wwwnsagov-hacked.html</a></p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2134" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2134', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2134-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2134" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2134', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2134-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: MichaelFigueroa</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2099</link>
		<dc:creator>MichaelFigueroa</dc:creator>
		<pubDate>Tue, 16 Feb 2010 19:07:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2099</guid>
		<description>It depends on what kind of authenticity check you leverage.  What I&#039;m proposing is a publicly-available infrastructure that enables people and organizations to verify that the email source is legitimate.  Imagine it as a background level certificate authority that provides trusted certs that businesses can integrate into their email servers and that public email systems can integrate into their services.  Verification can be done at an organizational level without the need to distribute user certs (though, that extension would be nice for those of us who know what we&#039;re doing).  It would definitely require changes in server software (Microsoft) and the deployment of the infrastructure (Google) and may also require protocol changes.

Can it be attacked?  Sure, but the likelihood of a successful root-level attack against a savvy adversary, such as Google, is unlikely and would be limited.  The more likely attack would be an internal organization attack, but then the organization could be held liable by its user population to a much greater degree than it can today.</description>
		<content:encoded><![CDATA[<p>It depends on what kind of authenticity check you leverage.  What I&#8217;m proposing is a publicly-available infrastructure that enables people and organizations to verify that the email source is legitimate.  Imagine it as a background level certificate authority that provides trusted certs that businesses can integrate into their email servers and that public email systems can integrate into their services.  Verification can be done at an organizational level without the need to distribute user certs (though, that extension would be nice for those of us who know what we&#8217;re doing).  It would definitely require changes in server software (Microsoft) and the deployment of the infrastructure (Google) and may also require protocol changes.</p>
<p>Can it be attacked?  Sure, but the likelihood of a successful root-level attack against a savvy adversary, such as Google, is unlikely and would be limited.  The more likely attack would be an internal organization attack, but then the organization could be held liable by its user population to a much greater degree than it can today.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2099" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2099', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2099-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2099" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2099', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2099-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2094</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Tue, 16 Feb 2010 18:25:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2094</guid>
		<description>Correct me if I&#039;m wrong here Michael but I don&#039;t think an authenticity check would have stopped this exploit.

Sophos said that the email &quot;appeared to have been sent by the National Security Council&quot;. I doubt that they, zeus, tried to use an existing valid email address belonging to the National Security Council but rather made up an address that looked similar. Therefore, there would have been no authentification error.

One thing most email servers do do well is check for known viruses. So once that link for the &#039;security update&#039; was reported it would probably not make it through many email servers.

I found this out the hard way by informing a friend about a malicious url and was naive enough to put the entire url in my email. The email servers picked up on that, my friend never received the email, and I got put on an email black list!

So, let that be a warning to others. If you are discussing fraud with people by email DO NOT put the fraudulent URL involved in the body of your email. Replace the dots with spaces or whatever so that it will not be interpreted as a link!</description>
		<content:encoded><![CDATA[<p>Correct me if I&#8217;m wrong here Michael but I don&#8217;t think an authenticity check would have stopped this exploit.</p>
<p>Sophos said that the email &#8220;appeared to have been sent by the National Security Council&#8221;. I doubt that they, zeus, tried to use an existing valid email address belonging to the National Security Council but rather made up an address that looked similar. Therefore, there would have been no authentification error.</p>
<p>One thing most email servers do do well is check for known viruses. So once that link for the &#8216;security update&#8217; was reported it would probably not make it through many email servers.</p>
<p>I found this out the hard way by informing a friend about a malicious url and was naive enough to put the entire url in my email. The email servers picked up on that, my friend never received the email, and I got put on an email black list!</p>
<p>So, let that be a warning to others. If you are discussing fraud with people by email DO NOT put the fraudulent URL involved in the body of your email. Replace the dots with spaces or whatever so that it will not be interpreted as a link!</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2094" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2094', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2094-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2094" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2094', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2094-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Connors</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2093</link>
		<dc:creator>Patrick Connors</dc:creator>
		<pubDate>Tue, 16 Feb 2010 18:04:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2093</guid>
		<description>That is a nice idea, but since infiltration and overriding of security systems is part of the general discussion here, do you think that this background authentication system would eventually come under attack or misuse also?

I think they all will. (Theoretically at least.)</description>
		<content:encoded><![CDATA[<p>That is a nice idea, but since infiltration and overriding of security systems is part of the general discussion here, do you think that this background authentication system would eventually come under attack or misuse also?</p>
<p>I think they all will. (Theoretically at least.)</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2093', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2093-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2093" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2093', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2093-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: MichaelFigueroa</title>
		<link>http://krebsonsecurity.com/2010/02/warning-about-zeus-attack-used-as-lure/comment-page-1/#comment-2091</link>
		<dc:creator>MichaelFigueroa</dc:creator>
		<pubDate>Tue, 16 Feb 2010 16:50:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1078#comment-2091</guid>
		<description>One thing to note, however, is that these types of reputation attack are largely successful due to the poor design of modern email systems.  As a commodity that has been around for far longer than the browser, email systems have had a remarkably poor rate of evolution by comparison.

A key failure (largely shared with modern http design) is the general inaccessibility of email authenticity verification.  You would think that we could have solved the signature problems by now, but the industry has largely ignored it in light of historical PKI/PGP distribution and use difficulties.  With no method of assessing authenticity, users cannot trust anything that comes into their inbox.  As such, they simply choose to trust everything.  It&#039;s a shame, but what choice do they truly have?

This is an area that I think Lotus Notes has always done well (though...admittedly one of the few things).  Every user on a Lotus infrastructure receives a verifiable credential.  They&#039;re not told that it&#039;s a digital certificate or anything, but they gain all of the benefits in the background.

I would love to see Google, Yahoo!, or Microsoft deploy a similar &quot;background&quot; authenticity system.  With the power of either of them behind such an innovation, I bet that we would make a lot of progress on really defeating both reputation attacks and phishing attacks in general.</description>
		<content:encoded><![CDATA[<p>One thing to note, however, is that these types of reputation attack are largely successful due to the poor design of modern email systems.  As a commodity that has been around for far longer than the browser, email systems have had a remarkably poor rate of evolution by comparison.</p>
<p>A key failure (largely shared with modern http design) is the general inaccessibility of email authenticity verification.  You would think that we could have solved the signature problems by now, but the industry has largely ignored it in light of historical PKI/PGP distribution and use difficulties.  With no method of assessing authenticity, users cannot trust anything that comes into their inbox.  As such, they simply choose to trust everything.  It&#8217;s a shame, but what choice do they truly have?</p>
<p>This is an area that I think Lotus Notes has always done well (though&#8230;admittedly one of the few things).  Every user on a Lotus infrastructure receives a verifiable credential.  They&#8217;re not told that it&#8217;s a digital certificate or anything, but they gain all of the benefits in the background.</p>
<p>I would love to see Google, Yahoo!, or Microsoft deploy a similar &#8220;background&#8221; authenticity system.  With the power of either of them behind such an innovation, I bet that we would make a lot of progress on really defeating both reputation attacks and phishing attacks in general.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-2091" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('2091', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-2091-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-2091" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('2091', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-2091-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 4/18 queries in 0.011 seconds using memcached
Object Caching 956/964 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 23:48:27 -->
