Re: TPM against XSS and Phishing



On Thu, May 15, 2008 at 1:43 AM, Dennis Li <dennis.li.sh@xxxxxxxxx> wrote:

Hi, Charis

I don't think any relationship between the secure boot (TPM) and XSS and phishing.

The secure boot is to prevent unauthrozied person to access your pc and privacy data on harddisk by encrpting your harddisk.

XSS and phishing attack work on web site. In some cases, the hack could access your data through the backdoor opened by trojoan which is injected by the XSS attack indirectly. (Malicious java script will be runned by XSS attack, and it may cause buffer overrun, and privilege to access your pc can be get, then backdoor will be opened). Even in that case, the TPM may not work since you already log on to your OS, and the data is decrypted.

So maybe you need state more clear about your requirement.

Dennis

On Wed, May 14, 2008 at 10:22 AM, Charis <cycharis@xxxxxxxx> wrote:

Hi,
Can anyone help me on how the use of secure boot(using a TPM) on vista could
prevent XSS and phishing attacks?
Thanks in advance
Charis