<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Chase Bank responds to  Website Security Design Flaws in Security</title>
<link>http://www.dslreports.com/forum/r20972147</link>
<description></description>
<language>en</language>
<pubDate>Tue, 01 Dec 2009 13:32:35 EDT</pubDate>
<lastBuildDate>Tue, 01 Dec 2009 13:32:35 EDT</lastBuildDate>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20981114</link>
<description><![CDATA[<A HREF="/useremail/u/874811"><b>sivran</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Anyhow, in other forums, I have been known to use this tagline:<br><br>BANK OF AMERICA.COM ONLINE BANKING SUCKS IN THE HUGEST WAY IMAGINABLE<br><br>And it is so.  They took what was once a very useful, meaningful web site & turned it into a morass of what might come out of a horses posterior.  I have to assume they do this to totally piss of their customers - at least this one (or perhaps in the name of "security").<br></div>How so? The basic layout and information provided on bofa online has not changed in years. They've added a few bells and whistles, true, but it's still the same number of clicks, the same layout, the same information to pay your bills or look over your accounts as it's been for years.<br><br>Heck, they even encrypted their main page finally. <br><br>Personally I find it much better than WaMu's online banking. Though admittedly, WaMu's is cleaner.<br><small>--<br>The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no warrants shall issue, but upon pro<b>fit</b>able cause...</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20981114</guid>
<pubDate>Wed, 20 Aug 2008 17:38:41 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20977401</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  therube <A HREF="/useremail/u/1107429"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Chase was allowing unsecured logins, or they were allowing secured logins from a page which itself was unsecured?  And by virtue of that leaves them more vulnerable to various types of attacks that may have resulted in giving up your username/password.<br></div>The login data was transmitted via SSL regardless of whether the page it was entered into was encrypted or not.<br>A short sighted view would be that when entering your data in a legit Chase login page, it doesn't matter that the page isn't SSL, because the data won't be transmitted until it's encrypted & that's true.<br>The problem with this is one of education & appearances of a website asking for sensitive data.<br>It should be a common practice that if a page isn't encrypted, don't trust it with your stuff.<br>Maybe now that Chase is coming onboard more will follow.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977401</guid>
<pubDate>Wed, 20 Aug 2008 00:09:03 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20977392</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : Chase was allowing a secured login from an insecure page.  The dslreports link you gave does the same, but at least it isn't a bank.<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977392</guid>
<pubDate>Wed, 20 Aug 2008 00:07:36 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20977331</link>
<description><![CDATA[<A HREF="/useremail/u/1107429"><b>therube</b></A> : Well looky here, an insecure page that purports to have a secure login.  A little gold lock & all:<br><br><A HREF="http://www.dslreports.com/login/L3ByaXZhY3k=?secure=1">http://www.dslreports.com/login/L3ByaXZhY3k=?secure=1</a><br><br>So I'm confused - kind of.<br><br>Chase was allowing unsecured logins, or they were allowing secured logins from a page which itself was unsecured?  And by virtue of that leaves them more vulnerable to various types of attacks that may have resulted in giving up your username/password.<br><br>There is a difference.  And the wording used to describe it can skew ones judgments on the matter.<br><br>Anyhow, in other forums, I have been known to use this tagline:<br><br>BANK OF AMERICA.COM ONLINE BANKING SUCKS IN THE HUGEST WAY IMAGINABLE<br><br>And it is so.  They took what was once a very useful, meaningful web site & turned it into a morass of what might come out of a horses posterior.  I have to assume they do this to totally piss of their customers - at least this one (or perhaps in the name of "security").<br><br>When this DNS issue came up, I was glad that BoA had that "sitekey" authentication tool, as I <i>believe</i> that by virtue of seeing your key, it lessened fears that you were ending up at a spoofed page.<br><br>EDIT:<br><br>Revised dslreports link, <A HREF="http://www.dslreports.com/login?secure=1">http://www.dslreports.com/login?secure=1</a>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20977331</guid>
<pubDate>Tue, 19 Aug 2008 23:51:18 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20972569</link>
<description><![CDATA[<A HREF="/useremail/u/795407"><b>SnowyOne</b></A> : <div class="bquote"><small>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>While Chase now uses a secure login on their main webpage Chase still presents security and contact information on INSECURE pages which can lead to phishing attacks.  Plus, Chase still has work to do on login as it is still possible to login on an insecure Chase page but not easy like it was for several years.<br> </div>The amount of "http" pages where a login is possible are considerable. One area where they may have missed the boat is on their security pages. It would make sense to encrypt those pages if for the only reason to illustrate what an "https" page looks like.<br>&raquo;<A HREF="http://www.chase.com/ccp/index.jsp?pg_name=ccpmapp/privacy_security/protection/page/security_home" >www.chase.com/ccp/index.jsp?pg_n&middot;&middot;&middot;ity_home</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20972569</guid>
<pubDate>Tue, 19 Aug 2008 03:10:44 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20972441</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Obviously, you didn't read the authors' paper nor did you watch the videos or you would not claim that the login was still secure. <br><br>As for a fake lock, obviously you don't use Fx3.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20972441</guid>
<pubDate>Tue, 19 Aug 2008 02:07:29 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20972170</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : The login itself was still secure. Plus for phishing purposes putting a little lock on the bottom would not be that hard. At least good enough to fool most people. Just copy the website. Put a little fake lock and phish away. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20972170</guid>
<pubDate>Tue, 19 Aug 2008 00:19:54 EDT</pubDate>
</item>

<item>
<title>Re: Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20972147</link>
<description><![CDATA[<A HREF="/useremail/u/1070900"><b>nwrickert</b></A> : <div class="bquote"><small>said by  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</small><br><br>Finally, Chase Manhattan Bank is again using SSL for its main webpage and login from that page.</div>I'm guessing that the recent problems with DNS cache poisoning might have been one of the motivations.<br><br><div class="bquote">The link below has links to the videos and to the pdf version of the research paper.<br><br><A HREF="http://www.eecs.umich.edu/%7Eaprakash/?prxsniff%3Ahtml&prx-ref%3Ahttp%3A//www.eecs.umich.edu/">aprakash page at eecs.umich.edu</a> </div>Repeated the above link, since it was not clickable in  Mele20 <A HREF="/useremail/u/403861"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s post (site software was confused by the embedded ":").<br><small>--<br>AT&T dsl; Westell 327w modem/router; openSuSE 11.0; firefox 3.0.1</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20972147</guid>
<pubDate>Tue, 19 Aug 2008 00:13:37 EDT</pubDate>
</item>

<item>
<title>Chase Bank responds to  Website Security Design Flaws</title>
<link>http://www.dslreports.com/forum/remark,20971933</link>
<description><![CDATA[<A HREF="/useremail/u/403861"><b>Mele20</b></A> : Finally, Chase Manhattan Bank is again using SSL for its main webpage and login from that page.  Evidently,  this results from a very interesting study on banking website security design flaws presented at SOUPS'08 July 23-25, 2008. Chase was one of 214 financial institutions whose websites were studied for security design flaws.  While Chase now uses a secure login on their main webpage Chase still presents security and contact information on INSECURE pages which can lead to phishing attacks.  Plus, Chase still has work to do on login as it is still possible to login on an insecure Chase page but not easy like it was for several years.  I protested to Chase, and in several threads on this forum, when Chase switched to insecure login on its main webpage back in 2006 and got nowhere with Chase. When they switched to insecure login, the chaseonline site login page was hidden and it took me 30 minutes to find it. When I called Chase online, the tech said they had been looking for the secure login page and asked me how I found it. Later, Chase made the chaseonline page easier to find but continued with an insecure login on the main page until this study, and the various Quicktime videos, I guess embarrassed them enough that they finally changed it.  Not only does Chase still provide contact information on insecure pages, but as far as I know they still do not require difficult passwords and difficult user ID. <br><br>As this study points out Chase and other banks need to do exactly what my home bank, Bank of Hawaii (boh.com) has done for some time now: encrypt the entire site. With Chase I was going back and forth from secure to insecure pages a few minutes ago after trying the new secure login on Chase's main page (instead of going directly to chaseonline login page and avoiding login on chase.com) which redirects to chaseonline. I ended up not being able to logout properly because, by going back and forth between secure and insecure pages, I lost the tab where I was logged into my credit card account. It appears that losing the tab automatically closed the connection as I had to login again but still that is a little disturbing. As the paper's authors state, if the entire banking site was encrypted then no problems regarding insecure pages for FAQ, contact information, etc would happen. <br><br>I actually installed Quicktime (old version on a not much used virtual machine) so I could watch the videos on Chase problems.  The link below has links to the videos and to the pdf version of the research paper.<br><br>&raquo;<A HREF="http://www.eecs.umich.edu/%7Eaprakash/?prx-sniff:html&prx-ref:&raquo;<A HREF="http://www.eecs.umich.edu/"" >www.eecs.umich.edu/"</A> >www.eecs.umich.edu/%7Eaprakash/?&middot;&middot;&middot;ich.edu/</A><br><small>--<br>"The same ferocity that our founders devoted to protect the freedom and independence of the press is now appropriate for our defense of the freedom of the internet. The stakes are the same: the survival of our Republic". Al Gore, The Assault on Reason</small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/20971933?c=1340535&ret=L2ZvcnVtL3IyMDk3MjE0Ny54bWw%3D"><IMG class="apic" BORDER=0 TITLE="71367 bytes" WIDTH=600 HEIGHT=278 SRC="/r0/download/1340535.thumb600~51b871cd7f3d0e34d9027d01fcd69ee2/Monday, August 18, 2008 16;36;37001.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20971933</guid>
<pubDate>Mon, 18 Aug 2008 23:07:34 EDT</pubDate>
</item>

</channel>
</rss>
