Earlier quoted context omitted.
My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.
But did you call the support phone number shown on the dodgy domain?
HTTPS on Your Landing Page Is Important
191–200 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#192Re: HTTPS on Your Landing Page Is Important
#193Earlier quoted context omitted.
When I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.
To be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.
Re: HTTPS on Your Landing Page Is Important
#194Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…
Re: HTTPS on Your Landing Page Is Important
#195Apparently 35% of all UK banks have insecure landing pages. [5][6]
[2] https://www.starlingbank.com
[3] https://www.atombank.co.uk
[5] http://blog.softwareverify.com/list-of-uk-banks-that-are-sec...
[6] https://twitter.com/softwareverify/status/940961044633149440
Re: HTTPS on Your Landing Page Is Important
#196Re: HTTPS on Your Landing Page Is Important
#197Earlier quoted context omitted.
Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…
Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.
Very frustrating - fortunately I don't use Skype regularly but it's always an exercise when somebody asks for my username.
Re: HTTPS on Your Landing Page Is Important
#198Earlier quoted context omitted.
To be fair though, at least they offer the guarantee that if your online banking is hacked they will reimburse 100%. Though not sure how truthful it is having never needed it. https://i.imgur.com/O2eOwLw.jpg Edit: "You may be liable for all losses from unauthorized use of your Account if you: contributed to its unauthorized use; used a PIN combination selected from your name, telephone number, date of birth, address,…
Ok this sounds like a terrible question but how do they stop people from "hacking" themselves...
Re: HTTPS on Your Landing Page Is Important
#199Earlier quoted context omitted.
To be fair though, at least they offer the guarantee that if your online banking is hacked they will reimburse 100%. Though not sure how truthful it is having never needed it. https://i.imgur.com/O2eOwLw.jpg Edit: "You may be liable for all losses from unauthorized use of your Account if you: contributed to its unauthorized use; used a PIN combination selected from your name, telephone number, date of birth, address,…
Ok this sounds like a terrible question but how do they stop people from "hacking" themselves...
It's entirely possible to claim your card was skimmed and have your bank refund the money. However, if they then find out that the ATM used to withdraw your entire balance is the same ATM you've used for years, and your face is on the ATMs security camera at the time of withdraw, then you're in for a world of hurt.
Re: HTTPS on Your Landing Page Is Important
#200Well, the bank seems to be stuck in the past... 10 years ago it was best practice for ecommerce shops to serve non sensitive pages (pages without forms or user data) without HTTPS to reduce the server load (HTTPS connections are a little more expensive than HTTP). Nowadays, even the economical driven ecommerce shops got it that is better to just serve everything via HTTPS. It is very sad to see a bank (which should r…
In the UK there are major ecommerce sites still on HTTP.