LiveID Protection from Spoofers; A must-have feature requestSince it's relatively easy for anyone to create a [Sign in] link on their web page and redirect you to a bogus authentication page has anyone in the LiveID team put any thought into how to protect against this?<br><br>For example, a user goes to a company site and mistypes the url... say company.co.uk instead of company.com.  Well company.co.uk is a spoofing site that looks like company.com except that the sign-in page sends you to some ASPX page that visually looks like a Federated or LiveID page, but it's saving whatever the user types in there (user/pass) to a local txt file.  <br><br>What is to prevent the ASPX page from transparently redirecting the user to the real site using a .js form post?<br><br>Can we get some kind of standard published from <a href="mailto:secure@microsoft.com">secure@microsoft.com</a> that says &quot;Hey enduser, look at the URL up top and make sure it says xxx.yyy.zzz, if not call your it security department&quot;  or some other validation... <br><br>One possible solution is to have the authenticating server respond with the cryptographically signed IP address of the requesting user and use this for validation.<br><br>-Chris© 2009 Microsoft Corporation. All rights reserved.Tue, 03 Feb 2009 06:49:14 Z0ce1a03a-215b-43b9-bfa0-73708f51bc0chttp://social.msdn.microsoft.com/Forums/en-US/liveframework/thread/0ce1a03a-215b-43b9-bfa0-73708f51bc0c#0ce1a03a-215b-43b9-bfa0-73708f51bc0chttp://social.msdn.microsoft.com/Forums/en-US/liveframework/thread/0ce1a03a-215b-43b9-bfa0-73708f51bc0c#0ce1a03a-215b-43b9-bfa0-73708f51bc0cChris Lamont Mankowski - Testhttp://social.msdn.microsoft.com/Profile/en-US/?user=Chris%20Lamont%20Mankowski%20-%20TestLiveID Protection from Spoofers; A must-have feature requestSince it's relatively easy for anyone to create a [Sign in] link on their web page and redirect you to a bogus authentication page has anyone in the LiveID team put any thought into how to protect against this?<br><br>For example, a user goes to a company site and mistypes the url... say company.co.uk instead of company.com.  Well company.co.uk is a spoofing site that looks like company.com except that the sign-in page sends you to some ASPX page that visually looks like a Federated or LiveID page, but it's saving whatever the user types in there (user/pass) to a local txt file.  <br><br>What is to prevent the ASPX page from transparently redirecting the user to the real site using a .js form post?<br><br>Can we get some kind of standard published from <a href="mailto:secure@microsoft.com">secure@microsoft.com</a> that says &quot;Hey enduser, look at the URL up top and make sure it says xxx.yyy.zzz, if not call your it security department&quot;  or some other validation... <br><br>One possible solution is to have the authenticating server respond with the cryptographically signed IP address of the requesting user and use this for validation.<br><br>-ChrisMon, 02 Feb 2009 00:53:44 Z2009-02-02T00:53:44Zhttp://social.msdn.microsoft.com/Forums/en-US/liveframework/thread/0ce1a03a-215b-43b9-bfa0-73708f51bc0c#8bb45425-e61f-495c-8165-e85ac71386ebhttp://social.msdn.microsoft.com/Forums/en-US/liveframework/thread/0ce1a03a-215b-43b9-bfa0-73708f51bc0c#8bb45425-e61f-495c-8165-e85ac71386ebVikas-Ahujahttp://social.msdn.microsoft.com/Profile/en-US/?user=Vikas-AhujaLiveID Protection from Spoofers; A must-have feature request Hi Chris -<br><br>Appropriate forum to discuss this issue would be <a href="http://social.msdn.microsoft.com/forums/en-US/wliddev/threads">Windows Live ID: Development</a> forum. <br>however, few resource links are provided here to give you an idea on what is available from Windows Live ID team:<br><br><a href="http://dev.live.com/blogs/devlive/archive/2008/04/07/254.aspx">Windows Live ID and phising</a><br><br><a href="http://winliveid.spaces.live.com/blog/cns!AEE1BB0D86E23AAC!991.entry">Windows Live ID adopts extended validation SSL certificates</a><br><br><a href="http://blogs.msdn.com/angus_logan/archive/2008/03/09/please-take-my-credentials-no-really-take-them.aspx">Please take my credentials, no really take them</a><br><br><a href="http://www.thearchitect.co.uk/weblog/archives/2008/03/first_law_of_password_hygiene.html">First law of password hygiene</a><br><br><a href="http://dev.live.com/blogs/devlive/archive/2008/03/25/237.aspx">Microsoft partners with Top Social networks to put users at the center of their data</a><br><br><br>Hope this helps, more detailed information would be available in Windows Live ID forum.<hr class="sig">This posting is provided &quot;AS IS&quot; with no warranties, and confers no rights.Mon, 02 Feb 2009 02:24:27 Z2009-02-02T02:24:27Z