We are creating a website where we will distribute code fragments to our users, which they can post on their sites. These snippets contain a link containing javascript. When you click on the link, an iframe opens, containing a dialog box for entering our site. Then the user authenticates inside the iframe, does his work, and when he leaves the iframe, his session is closed. Everything works for us, and it is very smooth.
Our main concern is phishing. The user has a completely new way of simplification, from which the login page really begins. Phising attacks, on the other hand, are also successful, even if the user can see the fake URL in the address bar.
Do you enter your (OpenId) credentials in an iframe? Does anyone know a pattern with which we could minimize the chance of a phishing attack?
source share