HTTPS on Your Landing Page Is Important
81–90 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#82I'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still ma…
But Nationwide is pretty good for banking.
Re: HTTPS on Your Landing Page Is Important
#83Earlier quoted context omitted.
Why is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling…
Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...
Re: HTTPS on Your Landing Page Is Important
#84>you could go register nuuolb.com right now Not anymore! https://www.whois.com/whois/nuuolb.com It seems NatWest has quickly gone to secure this major attack point in their otherwise chink-free armour. Does someone want to inform them about nwalb.com as well?
Gives me an idea! Why not go buy up a bunch of these types of names then tell them that they look similar to their login url. THEN when they come to try to buy it they find you own it and then charge them an arm and a leg for the domain?!
So I would advise you not to do it.
Re: HTTPS on Your Landing Page Is Important
#85The future is here folks. And it sucks.
Re: HTTPS on Your Landing Page Is Important
#86Earlier quoted context omitted.
> valid certificate trusted by a fake CA I don't think that's possible. A fake CA can't issue out valid certificates because you wouldn't trust their certs to begin with -- it's all about trust and if you know they are a fake CA, then you would never trust them or anything they issue. It's like if a known counterfeiter claims to be selling legit products, you probably wouldn't trust them.
A compromised, but legitimate CA is a vector of attack in this case. Any CA can be compromised by nation-states through legal coercion, and all of them probably have some vulnerabilities that have yet to be found. There are also new CAs that are not yet trusted, and sometimes old ones that are on their way to being delisted. So you need an up-to-date list of trusted CAs (which most of us are relying on google for, in…
For a NatWest customer accessing their internetbank, the expected, quite frequently observed risk comes from organized phishing teams pulling off mass semi-automated scams. For an attacker that, getting a certificate signed by a fake CA is unrealistic, and the concerns that you list aren't going to change anything since they're not going to do that anyway. On the other hand, getting a misleading certificate signed by a real CA and passing it off as the real thing is entirely feasible by this type of attacker, so fixing that is important.
Nation-state hacking, censorship and advanced persistent threats aren't what's causing the most damage/problems to most people on the internet right now, the multitude of random criminals is the largest issue. If you have to worry about a CA "compromised by nation-states through legal coercion", then this by itself means that you have a very different risk profile than pretty much everyone else; and the risk-reducing activities that make sense for you shouldn't be expected to be relevant for others and vice versa.
Re: HTTPS on Your Landing Page Is Important
#87Re: HTTPS on Your Landing Page Is Important
#88Earlier quoted context omitted.
Gives me an idea! Why not go buy up a bunch of these types of names then tell them that they look similar to their login url. THEN when they come to try to buy it they find you own it and then charge them an arm and a leg for the domain?!
That's typosquatting and it's not very ethical. It's also in a grey legal zone, you might get sued for this. So I would advise you not to do it.
Re: HTTPS on Your Landing Page Is Important
#89Earlier quoted context omitted.
Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...
How about all it really means? "Encrypted"
Re: HTTPS on Your Landing Page Is Important
#90Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
I was looking up details of the new Microsoft Surface recently, so hit the top link in a google search which was (supposedly) on Microsoft.com It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.
This is also exploited by malicious actors to occasionally buy out fake ads for amazon.com or bestbuy.com (or even, hilariously, youtube.com) which actually direct you to support scam websites claiming your computer is infected.
Google seems to have no desire to correct this by making their advertisements show you the actual URL are you going to be directed to.
Verify that any link you click on is not an ad. Always look for the first native result. The policies permitted around ads make them simply a security risk to click on.