Re: Bank Of America - sign on process - how is this secure?

From: Henrick Hellström (henrick.hellstrm@telia.com)
Date: 11/26/02


From: Henrick Hellström <henrick.hellstrm@telia.com>
Date: Tue, 26 Nov 2002 00:11:00 GMT

those who know me have no need of my name wrote:
> [fu-t set -- this is off-topic in most of the groups named]
>
> in comp.security.misc i read:
>
>>Lloydi <nuggiepost.20.lloydi@spamgourmet.com> randomly produced:
>
>
>>>On Bank of America's site they have a sign in box to their online
>>>banking on the home page.
>>>
>>>http://www.bankofamerica.com/index.cfm
>>
>
>>>Is this secure?
>>
>
>>It's not secure, simple as that, you are correct.
>
>
> the form submission (aka, login) is totally secure. it's the lock / safety
> indicator that is incorrect or misleading, at least it is in all the
> browsers which i've seen, including mozilla and msie. most web sites cater
> to the idiocy (by serving the entire login page via ssl), some don't.

I don't think it is idiotic to transmit the entire login page via ssl.

Sure, the login form doesn't have to be kept *confidential* like the
login password has to, but there is some point in keeping the login page
*authenticated* so that the user doesn't have to look at the html source
to make sure where the password will be sent.

> bofa used to make you link through several pages to reach the login page,
> which you can still do if you like, start at
> <http://www.bankofamerica.com/state.cgi?section=signin>.
>



Relevant Pages

  • Re: SSL php code
    ... > Sean I am planning on exclusievely using secure pages (ssl) after the user requests to login. ... This will securely redirect to a login ...
    (comp.lang.php)
  • Re: How to use SSL for login page only
    ... If you just secure the login page, ... an SSL connection. ... Joe Kaplan-MS MVP Directory Services Programming ... I would then like to have a link to a login page so I can authenticate ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: Strange behavior using SSL and "FORMS" authentication.
    ... otherwise you would not even get the login page ... (as I assume you have SSL for the whole site, ... Help Secure Forms Authentication by Using Secure ... >-The security certificate is valid. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: From http:// to https://
    ... > I have a login page that is secured with SSL and other non secure pages ... As Server.Transefer or response.redirect takes http by default. ... > standard method to transefer pages from normal to SSL page and vice versa. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Is .NET Passport credential traffic secure?
    ... my point is that you must FIRST establish a secure connection to ... user instead of making the login page itself secured with SSL so the ... The "Sign In" page at eBay submits the form data ... HTTPS site: Allowing the site to generate the HTML content in the page ...
    (microsoft.public.security)