Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Vast Majority of US Bank Websites Pose Security Risk to Users Says Study  (Read 4359 times)

0 Members and 1 Guest are viewing this topic.

Broni

    Topic Starter

    Mastermind
  • Kraków my love :)
  • Thanked: 614
    • Computer Help Forum
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 8
http://tinyurl.com/59nuwn



A recently released study conducted at the University of Michigan has found that as many as 75% of all bank websites have security flaws which pose a security risk to customers who visit the website.

Now, this is different from phishing, etc., for which banks are known targets.

This is you going to your own bank’s website, and just by visiting the site, having your computer or your personal data - or both - compromised.

According to Atul Prakash, the University of Michigan professor who oversaw the study, “To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country,” although no names were named.

Perhaps even worse is that these are, as Prakash points out, design flaws. Not bugs. Not holes that have been hacked in by hackers. It’s how the websites were designed!

The three biggest problems were
# The use of insecure pages (http: instead of https:) where users might input their password
# Allowing weak user IDs and passwords that are easily guessable
# Emailing sensitive information via the site

What does this mean for you, the user? Well first, to be hypervigilant when using your bank’s website - make sure you are on a secure page, or don’t send sensitive information. And make sure that you have a strong password, that includes upper- and lowercase letters, and numbers.

ChrisXPPro



    Adviser

  • Forever Learning
  • Thanked: 4
    • ACB Systems
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows XP
I can only judge by my own on line banking but - some while ago they set up a two level sign-in - all under a secure socket umbrella so - hopefully reasonable secure.

I'd not want to be using one without this I must say.  Not good if some banks do not follow good SSL and encription practice.
Ain't technology great - until it goes wrong!

Computer Hope Admin

  • Administrator


  • Prodigy

    Thanked: 248
    • Yes
    • Yes
    • Yes
    • Computer Hope
  • Certifications: List
  • Computer: Specs
  • Experience: Guru
  • OS: Windows 10
Any bank that doesn't use a secure page for the log in has to be insane, however I'd **assume** that most of the banks with flaws are city/state town banks and not large world-wide/country-wide banks.
Everybody is a genius. But, if you judge a fish by its ability to climb a tree, it will spend its whole life believing that it is stupid.
-Albert Einstein

soybean



    Genius
  • The first soybean ever to learn the computer.
  • Thanked: 469
  • Computer: Specs
  • Experience: Experienced
  • OS: Windows 10
Re: Vast Majority of US Bank Websites Pose Security Risk to Users Says Study
« Reply #3 on: October 21, 2009, 08:28:22 AM »
http://tinyurl.com/59nuwn
That URL isn't working.

# The use of insecure pages (http: instead of https:) where users might input their password
Does anyone know of a bank that uses insecure logon pages?  If there are any, it would surely be a small local bank somewhere, and I find even that very difficult to believe.

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Vast Majority of US Bank Websites Pose Security Risk to Users Says Study
« Reply #4 on: October 21, 2009, 08:42:43 AM »
Personally i've never seen one...

They'd have to be lazy or incompetent...or both.
" Anyone who goes to a psychiatrist should have his head examined. "