Yahoo has introduced a new approach to improve the security of user login. "Prevent password theft" link will be showed in the login dialog if you didn't setup the seal. Follow the link, you can create a sign-in seal for your computer. It could be a text message, or a image.

After reading their help content of this new anti-phishing method, I guess it's based on cookie, and I confirm my idea by a simple test.

The principal of Sign-in Seal should be:

The user upload an image or send some text, with a color choosed.
Yahoo server will produced a small gif image(less than 4KB) from those info.

Yahoo will create a long unique codes in a long-live cookie (expire after 30 years) on your computer, and everytime your browser visit Yahoo, it will be send back to Yahoo, and Yahoo will find your image from the unique codes and show it in the login page.
评论
发表评论

您还没有登录,请登录后发表评论

hax
搜索本博客
我的相册
12383b0c-e5fd-3183-8eed-8329d5a9c627-thumb
milk-ad
共 1 张
存档
最新评论
  • 信任何存
    北京的警察极端恶心,我亲身经历
    -- by zuroc
  • 信任何存
    hax 写道xieye 写道有困难找警察,曾是这里官方宣传的口号。 基本上也还行 ...
    -- by jiyanliang
  • 信任何存
    xieye 写道有困难找警察,曾是这里官方宣传的口号。 基本上也还行。 我所谓 ...
    -- by hax
  • 信任何存
    不知道农行的指纹支付推行的怎么样了。。。
    -- by 叶子
  • 信任何存
    有困难找警察,曾是这里官方宣传的口号。基本上也还行。
    -- by xieye