---
title: "Fighting phishing with counter-passwords"
date: 2005-10-13T12:42:52-04:00
url: https://blog.lmorchard.com/2005/10/13/fighting-phishing-with-counter-passwords/
author: Les Orchard
tags: [asides]
---

# Fighting phishing with counter-passwords

I just had a nutty idea to use against phishing scams:

When I visit a financial site, it generally requires me to enter a username and a password or PIN number in order to recognize me.  

What if the sites I deal with included some personalized passphrase or shibboleth in every communication sent to me?  That way, I'd recognize that that message came from some source with which I'd shared that code or mark, and that it wasn't a spoofed mass-mailing from an outside phisher.  It'd be like them authenticating with my brain.

For example, say that my bank included the phrase "Oh, and say hello to Francis for me" in every email I received.  Or maybe they chose from a set of 10 literary quotes pre-selected by me.

Now, assuming that financial sites didn't regularly expose their counter-password database, this might just work.  Too complicated?  Also, I don't think counter-password is *quite* the right phrase.

<div id="comments" class="comments archived-comments">
            <h3>Archived Comments</h3>
            
        <ul class="comments">
            
        <li class="comment" id="comment-221086760">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://admin.support.journurl.com/"><img src="http://www.gravatar.com/avatar.php?gravatar_id=5f89d3df08b8dedac1a0fde900a586db&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://admin.support.journurl.com/">Roger Benningfield</a>
                </div>
                <a href="#comment-221086760" class="permalink"><time datetime="2005-10-13T17:23:20">2005-10-13T17:23:20</time></a>
            </div>
            <div class="content"><p>How about "lightweight credentials"?</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086761">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://cavlec.yarinareth.net/"><img src="http://www.gravatar.com/avatar.php?gravatar_id=fa15e41d4cf102273b0e8f209c52c288&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://cavlec.yarinareth.net/">Dorothea</a>
                </div>
                <a href="#comment-221086761" class="permalink"><time datetime="2005-10-13T17:53:41">2005-10-13T17:53:41</time></a>
            </div>
            <div class="content"><p>The credit union I used in Madison (uwcu.org) does this. I gave their system an incredibly silly but highly memorable phrase from a college roleplaying campaign, and they include it in the email they send me.</p>

<p>Which never fails to make me grin. Added bonus.</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086763">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://www.sencer.de"><img src="http://www.gravatar.com/avatar.php?gravatar_id=0e94b4d4662542b91df48f0ff3b36d26&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://www.sencer.de">Sencer</a>
                </div>
                <a href="#comment-221086763" class="permalink"><time datetime="2005-10-13T18:01:39">2005-10-13T18:01:39</time></a>
            </div>
            <div class="content"><p>Actually that's already being done by some banks in a slightly different way. Schneier was writing on hos blog about it a while back. Here is an example of it:</p>

<p>http://www.bankofamerica.com/privacy/passmark/</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086765">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://edey.org"><img src="http://www.gravatar.com/avatar.php?gravatar_id=6558a34bd2590143d0e945e7020b49bf&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://edey.org">mike</a>
                </div>
                <a href="#comment-221086765" class="permalink"><time datetime="2005-10-13T18:13:12">2005-10-13T18:13:12</time></a>
            </div>
            <div class="content"><p>Ummm why fool around with stenography when we've got such an abundance of public key schemes? And no I don't think 'lightweight' or 'too hard for aunt minnie' count as reasonable answers. If it's worth doing it's worth doing well.</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086766">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://www.8dot3.com"><img src="http://www.gravatar.com/avatar.php?gravatar_id=2d870e8df3af0d62fa636b336b17cd60&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://www.8dot3.com">Nick</a>
                </div>
                <a href="#comment-221086766" class="permalink"><time datetime="2005-10-13T18:43:59">2005-10-13T18:43:59</time></a>
            </div>
            <div class="content"><p><i><b>Psycho:</b> The name's Francis Sawyer, but everybody calls me Psycho. Any of you guys call me Francis, and I'll kill you.</i></p>

<p><i><b>Leon:</b> Ooooooh.</i></p>

<p><i><b>Psycho:</b> You just made the list, buddy. Also, I don't like no one touching my stuff. So just keep your meathooks off. If I catch any of you guys in my stuff, I'll kill you. And I don't like nobody touching me. Any of you homos touch me, and I'll kill you.</i></p>

<p><i><b>Sergeant Hulka:</b> Lighten up, Francis. </i>

I notice that the Bank of America website calls it a passmark.  I like that.</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086767">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://advogato.org/person/mbrubeck/"><img src="http://www.gravatar.com/avatar.php?gravatar_id=85232f8499fd6ee91623408fc23835d1&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://advogato.org/person/mbrubeck/">Matt Brubeck</a>
                </div>
                <a href="#comment-221086767" class="permalink"><time datetime="2005-10-13T18:53:20">2005-10-13T18:53:20</time></a>
            </div>
            <div class="content"><p>This has the <a href="http://usablesecurity.com/2005/07/23/simon-says/" rel="nofollow">Simon Says problem</a>:  It requires users to notice when something is <em>not</em> present.  For the same reason that users don't notice the absense of the SSL "lock" icon, they won't notice the absence of the counter-password or passmark or whatever -- at least not enough of the time.</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086768">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://webseitz.fluxent.com/wiki"><img src="http://www.gravatar.com/avatar.php?gravatar_id=8157a5907b244071cda98ba5aa7a9635&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://webseitz.fluxent.com/wiki">Bill Seitz</a>
                </div>
                <a href="#comment-221086768" class="permalink"><time datetime="2005-10-13T19:26:08">2005-10-13T19:26:08</time></a>
            </div>
            <div class="content"><p>Wouldn't it be simpler to generate a custom From address which you could add to your AddressBook/WhiteList? Of course, you have to worry about having multiple computers with unsynched WhiteLists...</p>

<p>Then of course there's the custom RSS feed to get you to subscribe to...</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086769">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://bhiv.com/"><img src="http://www.gravatar.com/avatar.php?gravatar_id=a13775e56482ca85af50d0da0b401873&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://bhiv.com/">bhiv</a>
                </div>
                <a href="#comment-221086769" class="permalink"><time datetime="2005-10-13T20:40:47">2005-10-13T20:40:47</time></a>
            </div>
            <div class="content"><p>How about entering a serious of gibberish into the phisher's database? This way, when they try out their database the institution (say paypal.com) can notice that there are many failed logins from them? Or even automate it (amavis flags phishing attempts)</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086771">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://go-blog-go.blogspot.com"><img src="http://www.gravatar.com/avatar.php?gravatar_id=a9c49b00e73397cbd99fcf159104dd90&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://go-blog-go.blogspot.com">Saltation</a>
                </div>
                <a href="#comment-221086771" class="permalink"><time datetime="2005-10-14T13:55:26">2005-10-14T13:55:26</time></a>
            </div>
            <div class="content"><p>gads, someone who knows what "shibboleth" means</p></div>
            
        </li>
    
        <li class="comment" id="comment-221086772">
            <div class="meta">
                <div class="author">
                    <a class="avatar image" rel="nofollow" 
                       href="http://dougal.gunters.org/"><img src="http://www.gravatar.com/avatar.php?gravatar_id=81717a172b6918071fbea1a52483294b&amp;size=32&amp;default=http://mediacdn.disqus.com/1320279820/images/noavatar32.png"/></a>
                    <a class="avatar name" rel="nofollow" 
                       href="http://dougal.gunters.org/">Dougal Campbell</a>
                </div>
                <a href="#comment-221086772" class="permalink"><time datetime="2005-10-14T21:31:50">2005-10-14T21:31:50</time></a>
            </div>
            <div class="content"><p>Several sites I deal with already do something along these lines. For example, many banks and credit card companies will start the messages with something like "This message is in regard to your account ending with 9876". And some other sites will include your full name and/or login name. Which may or may not be useful, depending on how public that information is on that particular site (or in general).</p></div>
            
        </li>
    
        </ul>
    
        </div>
