Re: Re: Most common keystroke loggers?From: Michael Holstein <michael.holstein () csuohio edu> Date: Thu, 01 Dec 2005 16:26:05 -0500
If the user is passed to a phishing site that ask for the OTP, the user
enters it, the phishing site can return a error and instruct the user to
use the next OTP password, hence giving the attacker any number of
OTP....the OTP ones that are list based anyways.
Social Darwinism :
Try to make something idiot-proof, nature will provide you with a better
idiot.