Re: Person to Person Security and Privacy InfringementThe Famous Brett Watson – Jan 03, 2005 9:46 PM PST
I hate to say it, but this article is at best highly unclear, particularly to the extent that it proposes a solution. On re-reading the last two paragraphs several times, I came no closer to understanding how the solution addresses the problem, or even precisely what it is that the proposed solution is doing. If the threat model includes the possibility of a keylogger as installed by something like "Fizzer", then surely an application-specific gateway fails to address the problem. Can the application-specific gateway tell the difference between a legitimate client and a compromised one? If so, then how?
I hate to say it, but this article is at best highly unclear, particularly to the extent that it proposes a solution. On re-reading the last two paragraphs several times, I came no closer to understanding how the solution addresses the problem, or even precisely what it is that the proposed solution is doing. If the threat model includes the possibility of a keylogger as installed by something like "Fizzer", then surely an application-specific gateway fails to address the problem. Can the application-specific gateway tell the difference between a legitimate client and a compromised one? If so, then how?
I'm afraid I just don't get it.