Disappointing trend for online banking sites



Given how easy it is for people to be fooled by phishing sites, you would think banks would try and keep as many “easy ways to identify a legitimate bank site” as possible wouldn’t you? I mean, user-friendliness is certainly a big selling point in things software and even web site related so you would think banks would make it easier for those that are visiting to identify if they can trust that the site they’re visiting REALLY is a bank site.



Unfortunately, that’s not the case according to the Security Fix. According to his post…

However, Web sites for Bank of America, Wachovia, American Express and Chase no longer cause a user’s browser to display the little padlock as they did in years past,

Apparently in an effort to make sure their pages load as quickly as possible banks are forgoing the typical https:// login page for a page which merely CALLS to the secure login. Technically your login information is still encrypted, but there are a lot of reasons why this isn’t as good.

First, yes https:// pages load more slowly than http:// pages. Tough. I can survive an extra five seconds without seeing the login. I’d gladly PAY that 5 seconds if it meant I could VERIFY that I really am looking at a page served from my banks website.

I’ve spent literally years telling people that one way they can be sure that information is encrypted between them and a website they’re banking with or ordering from is that https, or lock icon. Now in reality yes it’s possible to spoof that (and least in Internet Explorer) and it is worth checking the certificate, but for most of the people I deal with the attitude is either a) I’m never entering a credit card number onto a website or b) lock? I’ll have to look for that next time I order something. I mean, there’s not that much in my account anyone would be interested in anyway…

I’ve specifically refused to log in to an unsecured portal for a bank previously, instead finding the same login served up through an https:// connection.

The Microsoft blog chimes in with a good point that if the initial connection isn’t https, then you can’t be REALLY sure that it’s REALLY coming from the correct source anyway and hasn’t been hijacked or rewritten along the way. The little secure login box that’s supposed to securely (https) submit your login info could have been rewritten to take you to Joe’s phishing log….

All of this was prompted by a netcraft report on the trend.

Let’s hope the IT departments at the banks falling for this idea wake up and smell the toast burning. It might be worth writing letters to voice opinions. We need every tool we can get to fight spoofing and to work to help people learn to identify legitimate and fraud sites. Today most fraud sites are advertised by links in email, what if they were DNS hijacked though? SSL logins (and original page delivery by SSL) is the best way to be able to verify.

Update – 8/24 Sunbelt blog has a reference to the trend.

Related Posts

Blog Traffic Exchange Related Posts
  • Google trying to warn about dangerous pages SunbeltBlog is talking about a new sign that Google is stepping up to try to protect users against potentially malicious sites. They have a screenshot, which I was able to verify, that gives a warning before allowing a user to proceed to a page that "Warning - the site you......
  • More Fake security sites More sites that claim to be windows security center or the like are popping up... a list: securitycaution(dot)com dnserror404(dot)com todaywarnings(dot)com updatesystempage(dot)com yoursecuritysystem(dot)com From sunbeltblog. There's a post at sysinternals about the bogus security software that's out there. Spyaxe, among others, pose as "antispyware software" and bring along more problems than......
  • Google cache revealing critical personal infromation A while back I did an article on using Google search in some slightly more advanced ways, as well as a link to a site of specific Google searches. I've come across something in the Handlers diary at Incidents.org that is worth knowing about. The entry in question details that......
Blog Traffic Exchange Related Websites
  • Don't Blame The Banks! I must be feeling particularly brave this week.  Monday, I took a bit of a jab at the public uproar surrounding the BP oil spill.  Unfortunately, I only received a few hate mails for that one, which isn't nearly enough.  To that end, I'm going to write another sure-to-be-unpopular article......
  • Facebook Advertising - Why You Ought To Use Facebook facebook for business marketing kitA single web site like this is a social networking web page. Here, you will see that it will previously have the website traffic you will need and most will contain the resources you need to effectively promote your solutions or services. A single these site......
  • Joint Banking, Budgets, and Savings Joint budgeting has been a topic for the past few weeks on some personal finances sites. Several bloggers have been posting their financial maps. Personal Finance Hour had a great show on couples and finances with Jim and J.D sharing their differing opinions on how they handle their family's finances.......
www.pdf24.org    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site