<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://weblogs.asp.net/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx</link><description>Last week I was in Boise, speaking to their .NET User Group , with INETA.org. The group leader, Cory Isakson , was talking about his PayPal Security Key. This is the key chain fob that has a tiny screen and a single button on it. Press the button, get</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP1 (Build: 20510.895)</generator><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#6967464</link><pubDate>Mon, 16 Mar 2009 06:04:21 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:6967464</guid><dc:creator>Me too</dc:creator><author>Me too</author><description>&lt;p&gt;In response to &amp;nbsp;Angus: Yes, this why authentication should never be done in the clear. If your authentication is done via HTTPS, you should be only susceptible to trojans that live on your own PC and they probably cannot process the information (send it somewhere else) in 30 seconds, unless it was designed to do exactly this. Then your theory has one other issue, the both that will use your credentials presu,ably will run them against the same resource (web site). Usually most web sites do not allow the same persson to be logged in twice. Unless the session is coming from the same instance of your own web browser, which is a bigger problem. Usually it leads to one session invalidating the other.&lt;/p&gt;
&lt;p&gt;Also I believe the YubiKey I mentioned is not susceptible to this issue, since the OTP it generates is combined with a counter and you definitely cannot use the same OTP twice.&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=6967464" width="1" height="1"&gt;</description></item><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#5735362</link><pubDate>Fri, 08 Feb 2008 05:47:54 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:5735362</guid><dc:creator>Josh</dc:creator><author>Josh</author><description>&lt;p&gt;Also worth noting -- Verisign will sell you this same device for $30 from their own website. Given it&amp;#39;s cross-compatible, very much worth getting it through PayPal, even if the device comes branded. Now, how to get access to their authentication service without OpenID? :P&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=5735362" width="1" height="1"&gt;</description></item><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#5438451</link><pubDate>Tue, 11 Dec 2007 17:37:47 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:5438451</guid><dc:creator>cyberjack</dc:creator><author>cyberjack</author><description>&lt;p&gt;Does this mean that if I&amp;#39;m at my buddy&amp;#39;s place and don&amp;#39;t have my key fob I can&amp;#39;t pay for anything with Paypal?&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=5438451" width="1" height="1"&gt;</description></item><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#4739963</link><pubDate>Thu, 25 Oct 2007 10:54:22 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:4739963</guid><dc:creator>Angus</dc:creator><author>Angus</author><description>&lt;p&gt;Makes for an interesting read. Alas, I believe that the phishing attacks will just adapt/evolve. There&amp;#39;s simply too much money stake. It&amp;#39;s conceivable that a sophisticated phishing scheme could grab the login details + key code and instead of using them at a later date, the info would be used to make a login immediately via a zombie. &amp;nbsp;Once a login had been made, then a session can easily be kept alive for a few hours giving the fraudsters a much larger window to run amok.&lt;/p&gt;
&lt;p&gt;Granted, it makes the phishing attacks much less accessible to the likes of script kiddies. However if recent press is to be believed, then the kinds of gangs behind these schemes are well organised criminals with the resources to pull something like this off.&lt;/p&gt;
&lt;p&gt;The key fob is a good counter measure, but nothing is 100% safe - don&amp;#39;t be lured into a false sense of security and NEVER LET YOUR GUARD DOWN.&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=4739963" width="1" height="1"&gt;</description></item><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#4336444</link><pubDate>Thu, 04 Oct 2007 19:28:53 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:4336444</guid><dc:creator>Dan Hounshell</dc:creator><author>Dan Hounshell</author><description>&lt;p&gt;Thanks for the tip, Scott. Ordered. This might turn out to be better than free CueCats from Radio Shack!&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=4336444" width="1" height="1"&gt;</description></item><item><title>re: PayPal.com - OpenID - VeriSign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#4324373</link><pubDate>Wed, 03 Oct 2007 21:07:52 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:4324373</guid><dc:creator>scott cate</dc:creator><author>scott cate</author><description>&lt;p&gt;If you're adding support to subtext, consider looking at @JasonA dot net open id project. &lt;a rel="nofollow" target="_new" href="http://code.google.com/p/dotnetopenid/"&gt;code.google.com/.../dotnetopenid&lt;/a&gt;&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=4324373" width="1" height="1"&gt;</description></item><item><title>re: Paypal.com - OpenId - Verisign - ScottCate.com</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#4324344</link><pubDate>Wed, 03 Oct 2007 21:02:30 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:4324344</guid><dc:creator>Steven Harman</dc:creator><author>Steven Harman</author><description>&lt;p&gt;I just ordered mine as well. I suppose this will be the motivation to finally add OpenId Support to Subtext. :)&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=4324344" width="1" height="1"&gt;</description></item><item><title>Paypal Security Key</title><link>http://weblogs.asp.net/scottcate/archive/2007/10/03/paypal-com-openid-verisign-scottcate-com.aspx#4323296</link><pubDate>Wed, 03 Oct 2007 19:02:09 GMT</pubDate><guid isPermaLink="false">c06e2b9d-981a-45b4-a55f-ab0d8bbfdc1c:4323296</guid><dc:creator>British Inside</dc:creator><author>British Inside</author><description>&lt;p&gt;Wow, I just LOVE this idea. Ordered . [include:blogad]&lt;/p&gt;
&lt;img src="http://weblogs.asp.net/aggbug.aspx?PostID=4323296" width="1" height="1"&gt;</description></item></channel></rss>