Given the recent PR regarding Bank of America's SiteKey (which seems to me to be susceptible to MIM attacks), I'd appreciate any feedback on this anti-phishing approach:
http://directorblue.blogspot.com/2005/06/making-phishers-solve-captcha-problem.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/