Re: Bank Of America - sign on process - how is this secure?
From: Shaolin Tiger (r00t@ku.gro.tenkrad)
Date: 11/25/02
- Next message: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Previous message: Barry Margolin: "Re: Bank Of America - sign on process - how is this secure?"
- In reply to: Lloydi: "Bank Of America - sign on process - how is this secure?"
- Next in thread: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Reply: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Reply: Sam Simpson: "Re: Bank Of America - sign on process - how is this secure?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Shaolin Tiger" <r00t@ku.gro.tenkrad> Date: Mon, 25 Nov 2002 20:20:43 -0000
Lloydi <nuggiepost.20.lloydi@spamgourmet.com> randomly produced:
> On Bank of America's site they have a sign in box to their online
> banking on the home page.
>
> http://www.bankofamerica.com/index.cfm
>
> I want to know, how is this secure? This would surely mean that the
> informattion typed in to the Online ID and passcode fields are not
> encrypted by 128 bit SSL when they are sent to the https page.
> Normally, you have to click through to https hosted page and THEN
> sign on from there, safe in the knowledge that the details are
> encrypted properly.
>
> Is this secure?
>
> Can you explain how they have managed to get around this?
>
> I'm mystified. I've had a look at the source code of the page, and I
> can't really see any client-side masking of the details (and even if
> I did see that I'd question just how secure this is)
It's not secure, simple as that, you are correct.
Shaolin
-- .: http://www.security-forums.com :. Share your knowledge It's a way to achieve Immortality.
- Next message: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Previous message: Barry Margolin: "Re: Bank Of America - sign on process - how is this secure?"
- In reply to: Lloydi: "Bank Of America - sign on process - how is this secure?"
- Next in thread: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Reply: those who know me have no need of my name: "Re: Bank Of America - sign on process - how is this secure?"
- Reply: Sam Simpson: "Re: Bank Of America - sign on process - how is this secure?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|