My chinese bank account does this. I am not sure how effective it is, and it requires a two step login, so it is terrible from a usability standpoint.
My chinese bank account does this. I am not sure how effective it is, and it requires a two step login, so it is terrible from a usability standpoint.
When fake-friendface wants to phish you, they get your username, then they give that username to friendface and receive your cartoon elephant in exchange. They show you the cartoon elephant, and you decide that this must be friendface.
The way this works looking at banking websites is that the user enters a username. Then they get some secret image + description that they previously wrote and can enter their password.
The reason it might work in this case is because the assumption is that people will only verify the browser bar when they first arrive on the page, and not when they have been "tab nabbed" like this
Plus, the secret image assumes I actually remember which image I select for every page. Given that none have the same collection of images, I'm likely to have only a vague notion of which one I picked at account creation.
This is not the common implementation since most seemed to have missed the point.