Proposal (Was: When are and aren't two URLs the same?)

Jonathan Daugherty cygnus at
Fri Apr 21 22:18:15 UTC 2006

# >Not necessarily.  A solution which makes phishing *impossible* without
# >breaking anything else is a more convincing solution than one which
# >merely makes it "less likely".
# Are we getting off subject here? ;-) I thought there was general
# agreement that making phishing impossible is also impossible.

Depending on the context, making phishing impossible is possible, but
yes; this is off-topic.  I was just explaining why I don't think "it
makes phishing slightly less likely" is a good argument to add a
transform which I think will violate a user's trust in a given URL.

  Jonathan Daugherty
  JanRain, Inc.

