Re: Bank Of America - sign on process - how is this secure?

From: those who know me have no need of my name (not-a-real-address@usa.net)
Date: 11/26/02


From: those who know me have no need of my name <not-a-real-address@usa.net>
Date: 26 Nov 2002 05:59:47 GMT


[fu-t set -- still nothing here that is on-topic of pgp or o/s security]

in alt.security.pgp i read:

>However if you do not check the http source each time you attempt to
>login, then since the page requesting your login is sent to you
>unencrypted, it could possibly be modified.

that is true enough, and it is of some value. it would be better if it
weren't for the overall meaning that has come to be attached to the
padlock. like it or not the basic assumption that a lot of people operate
under is that if the padlock is locked they can turn their brains off, when
that is far from true. i.e., there remain other possibilities for which
the padlock, as it stands, cannot help at all, e.g., if the content could
be altered en-route (if not via https) don't you think you could be
transacting with the wrong host just as easily?

-- 
bringing you boring signatures for 17 years


Relevant Pages

  • Re: Creating secure login page
    ... SSL protect the login page as well. ... Instead you visit the homepage and there is no padlock. ... > then it redirects to a secure area. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Logging into my dot mac account
    ... >> When I go to the .mac login page there is a little padlock ... >> the upper right-hand corner of the login frame. ... But is it really secure? ...
    (comp.sys.mac.apps)
  • Re: Bank Of America - sign on process - how is this secure?
    ... > All corrections and elaborations appreciated! ... > I would think that this is only somewhat secure. ... > that the login is sent via https, ... > check the http source each time you attempt to login, ...
    (comp.security.misc)
  • Creating secure login page
    ... password box and a login button. ... Instead you visit the homepage and there is no padlock. ... then it redirects to a secure area. ... Prev by Date: ...
    (microsoft.public.dotnet.framework.aspnet)