Re: Bank Of America - sign on process - how is this secure?

From: James Preston (jgp@operamail.com)
Date: 11/26/02


From: James Preston <jgp@operamail.com>
Date: 26 Nov 2002 13:05:14 +1100


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 25 Nov 2002, those who know me have no need of my name:
> the form submission (aka, login) is totally secure. it's the lock / safety
> indicator that is incorrect or misleading, at least it is in all the
> browsers which i've seen, including mozilla and msie. most web sites cater
> to the idiocy (by serving the entire login page via ssl), some don't.

Idiocy is not the brower's, IMHO - the browser is correctly indicating
that the form itself has not been protected. It is standard in
security terms to serve the form via HTTPS.

If someone can tamper with the login form itself in transit there is no
guarentee (without inspecting the source) that the login details will
be sent to right server - via HTTPS or otherwise.

- --
James Preston
-----BEGIN PGP SIGNATURE-----

iD8DBQE94tZqgXK32hUOOt0RAnJzAJ4tVQjwmwwTikxxaOh9ZNPv6/G+egCgwPRh
Iand/yB+6ud3tIQ6OhzGQ9o=
=fiEZ
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Using Javascript to submit a form at another URL
    ... How can you login if you cannot access the site first? ... However loading the login-page into an ifame will not help you. ... Only on a faked page, not on the page of the site, as modern browsers do ... not allow access to an iframe if cross domain. ...
    (comp.lang.javascript)
  • Re: whats up with Windows Live Hot Mail?
    ... Browsers these days are so complex that the best ... I'm not sure where I'd go to post with a Hotmail problem. ... I'd just go to Hotmail support. ... I set both addresses to save the login to this computer. ...
    (microsoft.public.windows.vista.administration_accounts_passwords)
  • Authentication Problem
    ... I need various devices to access iis5 running on win2k ... via https. ... IE pops up a login box which works quite well. ... devices and browsers seem unable to display this and ...
    (microsoft.public.inetserver.iis.security)
  • Re: Authentication Problem
    ... > IE pops up a login box which works quite well. ... > devices and browsers seem unable to display this and ... Maybe you have IIS set for Windows Integrated authentication, ... Tom Kaminski IIS MVP ...
    (microsoft.public.inetserver.iis.security)
  • Re: Automatic login from one website to another - how
    ... you can put the login and password in the url - e.g. ... The given examples (hotmail and yahoo!mail) don't. ... And not all browsers ... support the URL scheme for usernames and passwords (due to its abuse by ...
    (alt.html)