Given the method of attack and the fact that the user never gets to SSL connection, this article is wrong kind of alarm.
Once more this exploit is a trust based attack on the assumed actions of unencrypted HTML.
Specifically this attack is easily defeated by NEVER opening plain HTTP:// pages -- which should really be the modern browsing standard.
Discussion on:
Message 8 of 1
IBM Sponsored Resources
Resources from our Sponsor
- Oracle Exadata vs IBM: Netezza Compared
- Forrester TEI Report
- CIA Whitepaper
- Harnessing the Power of Advanced Analytics
- Tapping into Unleashed Business Potential with Advanced Analytics
- Unlock Analytic Performance with Revolution R for Enterprise and IBM: Netezza Data Warehouse Appliance
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox




