[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87brk85o8n.fsf@snark.piermont.com>
From: perry at piermont.com (Perry E. Metzger)
Subject: http://www.chase.com/ vulnerability
"Brandon" <b_buckley@...cast.net> writes:
> Wells Fargo and Bank of America have similar home pages, although they do
> offer a secure login page, I'm sure most users don't bother using it.
So does Chase (if you bother learning how to get to it, which they
don't make obvious.)
American Express appears to have a brilliant setup where if you try to
go to https://www.americanexpress.com/, it redirects you back to an
http: based login page. If reload the login page with an https:
request, you get a popup about it using an Akamai certificate.
It is clear that some people are not paying attention here and they're
heavily endangering their customer.
--
Perry E. Metzger perry@...rmont.com
Powered by blists - more mailing lists