End Adversary-in-the-Middle attacks
instantly, directly in the SSO
Overview
Relock offers the first server-side solution that stops the Adversary-in-the-Middle attacks and requires no action from the users. There is no browser extension, no extra software, and no adoption needed.
Relock prevents login attempts when there is a malicious proxy between the user and the SSO / customer authentication. It uses a challenge-based mechanism that forces the AitM phishing kit to reveal itself, pushed directly to the browser. Any adversary intercepting the login is immediately terminated.
See the flow diagram below to take an attacker's perspective.
Attacker's response - fingerprint declaration
Attacker's response - challenge execution