Min Wu, Robert C. Miller, and Greg Little: Web Wallet
Friday, July 14th, 2006Read the paper here.
Phishing is a semantic attack: it exploits the gap between user’s intentions and the system’s operation (in particular when submitting data). The key factors are: what is the data and where will it go?
The Web Wallet is a browser sidebar that users open by pressing a secure attention key (F2). [...]