 SnowyOne Premium join:2003-04-05 Kailua, HI
·RoadRunner Cable
·Clearwire Wireless
| Re: Chase Bank responds to Website Security Design Flaws said by therube :Chase was allowing unsecured logins, or they were allowing secured logins from a page which itself was unsecured? And by virtue of that leaves them more vulnerable to various types of attacks that may have resulted in giving up your username/password. The login data was transmitted via SSL regardless of whether the page it was entered into was encrypted or not. A short sighted view would be that when entering your data in a legit Chase login page, it doesn't matter that the page isn't SSL, because the data won't be transmitted until it's encrypted & that's true. The problem with this is one of education & appearances of a website asking for sensitive data. It should be a common practice that if a page isn't encrypted, don't trust it with your stuff. Maybe now that Chase is coming onboard more will follow. |