TrustBar 0.4 beta 9.3.1, with Hey! Training Mode - please help test usability

2005-08-10 Thread Amir Herzberg
- by real usage!! Comments welcome... Thanks and best regards, Amir Herzberg Dept. of Computer Science, Bar Ilan University http://AmirHerzberg.com ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla

Re: Is there a Mozilla security process?

2005-07-03 Thread Amir Herzberg
that was the cause of your problem? BTW, these sites work fine for TrustBar (now using our 0.4 alpha version which also lets me `rename` them in the bar directly, like `petname`; but I'm quite sure they worked also in the current 0.31 release). Best, Amir Herzberg Hope it helps

Re: new anti-fraud mailing list for discussing improving browser security UI

2005-06-29 Thread Amir Herzberg
clearly indicates his personal preference for more open process. Anyway, considering Mozilla are currently pursueing a different, `closed` approach, the technical discussion moved to the new list Duane made (see original post). Best, Amir Herzberg

Re: new anti-fraud mailing list for discussing improving browser security UI

2005-06-29 Thread Amir Herzberg
Gervase Markham wrote: Amir Herzberg wrote: It is not an issue of fairness, it is an issue of open process. I am indeed disappointed to find that Mozilla is not acting openly. As a believer in open process, I am concerned that the result may be suboptimal. I would like the process

Checking URL against black list - privacy and efficiency concerns

2005-06-29 Thread Amir Herzberg
. I've put it in the appropriate priority of my `to-do` list. Coding to other platforms is a bit higher, though. Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla-security

new list for open discussion of anti-phishing

2005-06-28 Thread Amir Herzberg
the case). Best, Amir Herzberg See the new TrustBar homepage at http://AmirHerzberg.com/TrustBar ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla-security

new anti-fraud mailing list for discussing improving browser security UI

2005-06-28 Thread Amir Herzberg
of open process. I am indeed disappointed to find that Mozilla is not acting openly. As a believer in open process, I am concerned that the result may be suboptimal. This is not the way to encourage innovation. Best, Amir Herzberg See the new TrustBar homepage at http://AmirHerzberg.com/TrustBar

Re: Is there a Mozilla security process?

2005-06-27 Thread Amir Herzberg
that was the cause of your problem? BTW, these sites work fine for TrustBar (now using our 0.4 alpha version which also lets me `rename` them in the bar directly, like `petname`; but I'm quite sure they worked also in the current 0.31 release). Best, Amir Herzberg Hope it helps

Re: Criteria for an antiphishing tool

2005-06-26 Thread Amir Herzberg
Ian Grigg responded to Gerv: Amir Herzberg wrote: So, Mozilla plays `follow the leader`? Nice to know. Not exactly the original goal of the project, was it? Up to this point, our discussions have been reasonably civil, but now you are just throwing clearly ridiculous assertions around

Re: Criteria for an antiphishing tool

2005-06-23 Thread Amir Herzberg
(trying to get this resolved). Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla-security

Re: Criteria for an antiphishing tool

2005-06-23 Thread Amir Herzberg
. and the CA was supposed to be named as the one who you could rely upon. I don't recall it myself, but Bob Relyea mentioned it. Yes, but I think that was only in the pre-release. Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security

Re: Installing Trust Bar

2005-06-22 Thread Amir Herzberg
Doug Ludy wrote: I am new at this, but have been following the discussion of phishing at the n.p.m.security newsgroup for the past month. I would like to try the trustbar extension but when I try to download the program from http://trustbar.mozdev.org I cannot do so because I have JavaScript

Re: Criteria for an antiphishing tool

2005-06-22 Thread Amir Herzberg
she likes. Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla-security

Cooperating and communicating on antiphising / improved security indicators

2005-06-21 Thread Amir Herzberg
and specific solutions. Is there sufficient interest to create an (informal/Mozilla/...) forum/mailinglist to pursue this? Any volunteer to take care of it? Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security@mozilla.org http

Re: Criteria for an antiphishing tool

2005-06-21 Thread Amir Herzberg
could elaborate 5th a lot: trivially easy to use, idiot-proof, fail safely, ... Our usability experiments show TrustBar meets this as well. Best, Amir Herzberg ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org

Re: new citibank site uses wrong URL, certificate ?

2005-06-19 Thread Amir Herzberg
Oops, sorry, my mistake, I typed citybank.com instead of citibank.com... Amir p.s. Citybank is a community bank (and yes, _they_ use unprotected login... but CitiBank is Ok). Amir Herzberg wrote: Hi, I noted that Citibank changed their login form at http://CitiBank.com. It now points you

Re: do extensions compromise the security of mozilla/firefox?

2004-11-09 Thread Amir Herzberg
Mike Henley wrote: Hi. I'm using mozilla and mozilla firefox. I often install extensions though only through the usual websites (mozilla.org, mozdev, texturizer). Today though I tried to install an extension from http://jgillick.nettripper.com/ and as such found myself wondering if extensions

Re: [Fwd: more comments on the protecting naive browsers paper]

2004-08-02 Thread Amir Herzberg
Ian Grigg wrote: Amir, here are comments, not particularly well reviewed. http://www.cs.biu.ac.il/~herzbea//Papers/ecommerce/spoofing.htm Thanks! Mozilla people (2nd try), Please provide more comments... Here are some responses to your comments: Right, that idea. A couple of things - it's called

Re: Security Hole Found in PayPal Registration !

2004-07-26 Thread Amir Herzberg
!` Best, Amir Herzberg Interested in phishing / spoofing / spamming and their prevention? See `Current research` in my homepage http://AmirHerzberg.com ___ Mozilla-security mailing list [EMAIL PROTECTED] http://mail.mozilla.org/listinfo/mozilla-security

Re: Protecting (even) Naïve Web Users from Spoofing and Phishing

2004-07-15 Thread Amir Herzberg
much like to incorporate these mechanisms into the Firefox browser. I'd appreciate feedback on the concepts as well as implementation advice or assistance. We appreciate your (and others) feedback. So far, we manage the implementation Ok. Best, Amir Herzberg

Re: Protecting (even) Naïve Web Users from Spoofing and Phishing

2004-07-14 Thread Amir Herzberg
Frank Hecker wrote: Amir Herzberg wrote: We have created a Mozilla extension that creates a secure, Trusted Logo and Credentials Area, which displays logos and other credentials The proposal is described at: Protecting (even) Naïve Web Users, or: Preventing Spoofing and Establishing

protecting (even naive) web users against spoofing and phishing

2004-07-13 Thread Amir Herzberg
to begin providing it to others soon; in the meanwhile, if you are interested, we'll love to hear your comments. The proposal is described at: Protecting (even) Naïve Web Users, or: Preventing Spoofing and Establishing Credentials of Web Sites, by Amir Herzberg and Ahmad Gbara PDF at http