Feed Sign in with OpenID OpenID

Simon Willison’s Weblog

Cronto. I saw a demo of this the other day—it’s a neat anti-phishing scheme that also protects against man in the middle attacks. It works using challenge/response: an image is shown which embeds a signed transaction code; the user then uses an application on their laptop or mobile phone to decode the image and enters the resulting code back in to the online application.

Tagged , , , , , ,

2 comments

  1. They did a demo for us at work as well. Seems quite cool, although it's not all that cheap considering what it does -- I knocked up a quick demo version of a similar concept in a couple of hours to prove that it's perhaps not worth the money. Nice idea, though.

    sil - 2nd October 2007 08:03 - #

  2. Many thanks for such positive comments. We did put lots of effort into trying to "hide" all complications of the security protocol behind deceivingly simple front end so that it looks extremely straightforward and intuitive for the end user - after all, the majority of the security solutions failed not because they were bad but because they were perceived as "too complicated" by users :-)

    Elena Punskaya, Cronto Ltd - 3rd October 2007 23:41 - #

Sign in with OpenID

Auto-HTML: Line breaks are preserved; URLs will be converted in to links.

Manual XHTML: Enter your own, valid XHTML. Allowed tags are a, p, blockquote, ul, ol, li, dl, dt, dd, em, strong, dfn, code, q, samp, kbd, var, cite, abbr, acronym, sub, sup, br, pre

A django site