Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As far as I understand http://lloyd.io/how-browserid-works , the browser will hold a "certificate of ownership of the email". Since browser do not yet implement Persona, it is done in javascript with https://login.persona.org/include.js .

I do not yet understand what prevent me to steal these 'certificate of ownership of the email' by creating a web site with my own version of 'include.js'. In this malicious version, the "Assertion Generation" also send the private key to the server. After that, the server can uses the user login as he wants. It seems there is a timeout, but it allow the malicious server to log so long the time out is not ellapsed. Where I'am wrong?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: