CC shared secret

Igor Mozolevsky ukcrypto at chiark.greenend.org.uk
Wed, 6 Aug 2008 15:20:12 +0100


2008/8/6 James Firth <james2@jfirth.net>:

>
> The architecture and mechanism is called 3D, and the issuing bank must
> support a 3D Secure interface.
>

I've recently been wondering how easy it would be for a malicious site
to overlay their own controls over the 3D secure frame and store the
password...


--
Igor