Protecting a user against web spoofing in which the user confirms the
authenticity of a web page prior to submitting sensitive information such
as user credentials (e.g., a login name and password) via the web page.
The web page provides the user with an identifiable piece of information
representing a shared secret between the user and the server. The user
confirms the correctness of the shared secret to ensure the legitimacy of
the web page prior to disclosing any sensitive information via the web
page.