Identity in the Browser -or- Putting the Cart Before the Horse? - - PowerPoint PPT Presentation

identity in the browser or putting the cart before the
SMART_READER_LITE
LIVE PREVIEW

Identity in the Browser -or- Putting the Cart Before the Horse? - - PowerPoint PPT Presentation

Identity in the Browser -or- Putting the Cart Before the Horse? Andy Steingruebl and Jeff Hodges {asteingruebl,jeff.hodges}@paypal.com PayPal Information Risk Management Position Paper for W3C Workshop on Identity in the Browser May 24


slide-1
SLIDE 1

Identity in the Browser

  • or-

Putting the Cart Before the Horse?

Andy Steingruebl and Jeff Hodges

{asteingruebl,jeff.hodges}@paypal.com

PayPal Information Risk Management

Position Paper for W3C Workshop on Identity in the Browser May 24 and 25, 2011 – Mountain View, CA

slide-2
SLIDE 2

Given that...

  • Online user credentials today are typically
  • Reusable
  • employ shared secrets (aka “passwords”)
  • Users will enter their credentials into most any
  • nline form
  • People can and will divulge their credentials

when nominally prompted

slide-3
SLIDE 3

Then...

  • Phishing is fun and profitable!
slide-4
SLIDE 4

Also, since...

  • Mobile handheld ubiquitously Internet-

connected third-party programmable devices == “smartphones”

  • Smartphones are a different sort of computer
  • Smaller keyboards and screens
  • Power limitations
  • Social connotations
  • Smartphone adoption is skyrocketing
slide-5
SLIDE 5

Then...

  • We really need to think differently about user

authentication on smartphone platforms,

  • therwise...
  • Phishing will be even more fun and profitable!
slide-6
SLIDE 6

And since...

  • All sorts of boxes/things feature a web server...
  • ...hosting configuration/management interfaces
  • E.g...
  • Network middleboxes
  • Appliances
  • Industrial control systems
  • Vehicles (soon?)
  • Vulnerable to Cross-Site Request Forgery

(CSRF)

slide-7
SLIDE 7

Then...

  • Might be even more fun than phishing...
slide-8
SLIDE 8

Present Workshop Goal...

  • Solutions to be explored are effective

enhancements to Web browsers that lead to trustworthy benefits that can be realized in the near term

slide-9
SLIDE 9

Rethink/Refine Our Goals...

  • User authentication without phishable

credentials?

  • How to mitigate CSRF?
  • Get heads around new world of smartphones?
  • New paradigms for security indicators?
  • More consistent security characteristics across

major browsers?