| Possible mitigation measure: 1. If identity providers start offering a dynamic, trusted element within the critical pages (login, password prompt, 2FA/OTP verification etc) 2. if such dynamic element is from a known range/set of customer/trusted-party supplied identity elements. Ex. During my account creation, say I am prompted to select some "secret identity themes", and I choose { batman, bike, carrots } At the login/password/OTP prompt, I am shown a 3x3 grid of pics / words / hints, which have at least 3 (or whatever configurable number, in my account preferences) that are somehow connected to my "secret identity theme". This way, I know I can trust this page. The grid also has many unrelated ones acting as decoys elements, so that any malicious spoofing party cannot really figure them out. I believe you get the general idea. Do y'all feel this can possibly help, in mitigating this very serious & very harmful threat? I intend to write a short post on this soon. |