Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

191–200 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#191
post #138

Earlier quoted context omitted.

My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.

But did you call the support phone number shown on the dodgy domain?

[deleted]

Re: HTTPS on Your Landing Page Is Important

#192
I wonder how GDPR would change this attitude? If Natwest were to lose some data after May 18 and it was possible to show that they were warned about the problem by a reputable professional, then they are more likely to get fined, one would presume. Maybe this legal liability is what $bigcorp needs

Re: HTTPS on Your Landing Page Is Important

#193
post #68

Earlier quoted context omitted.

When I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.

To be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.

Except for the unnecessary 5 second wait when accessing chase.com for the login prompt to appear.

Re: HTTPS on Your Landing Page Is Important

#194
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.

Re: HTTPS on Your Landing Page Is Important

#195
Monzo [1], Starling [2], Atom [3] and Tandem [4] all manage to have HTTPS landing pages. If they can, there isn't any excuse for the more established banks not to as well. Hopefully their mobile apps use HTTPS for everything too?

Apparently 35% of all UK banks have insecure landing pages. [5][6]

[1] https://monzo.com

[2] https://www.starlingbank.com

[3] https://www.atombank.co.uk

[4] https://www.tandem.co.uk

[5] http://blog.softwareverify.com/list-of-uk-banks-that-are-sec...

[6] https://twitter.com/softwareverify/status/940961044633149440

Re: HTTPS on Your Landing Page Is Important

#197

Earlier quoted context omitted.

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

Speaking of Microsoft's signin, I can no longer access my decade-old-held Skype since their SSO integration. I've tried over and over and over and tried every route possible. It is some edge case where the email was previously a microsoft account and the password cannot be reset. I'm not the only one with the issue. Shocking something like this doesnt get resolved for years on.

I have a similar Skype issue. I have ancient Skype accounts with usernames, and my email address linked, but now use a Microsoft account for Skype with that same email address. Nobody can find and add my current account - whenever they search for my email address, all of my old usernames appear. I always have to add other users instead.

Very frustrating - fortunately I don't use Skype regularly but it's always an exercise when somebody asks for my username.

Re: HTTPS on Your Landing Page Is Important

#198

Earlier quoted context omitted.

To be fair though, at least they offer the guarantee that if your online banking is hacked they will reimburse 100%. Though not sure how truthful it is having never needed it. https://i.imgur.com/O2eOwLw.jpg Edit: "You may be liable for all losses from unauthorized use of your Account if you: contributed to its unauthorized use; used a PIN combination selected from your name, telephone number, date of birth, address,…

Ok this sounds like a terrible question but how do they stop people from "hacking" themselves...

You basically need to file a police report about the theft, and the bank will probably know where the money was sent/spent, and the police ideally would investigate and subpoena the records of wherever the money went and presumably discover if it goes back to you somehow. The first liability thing says you cannot have "contributed to its unauthorized use". I mean realistically someone could possibly do it and get away with it, but I mean people could realistically do many types of fraud. Most could realistically probably get away with it. It's more a guarantee to people that if they get hacked somehow other then giving naughty little Johnny/vindictive ex Jane the bank card and pin, they can get their money back.

Re: HTTPS on Your Landing Page Is Important

#199

Earlier quoted context omitted.

To be fair though, at least they offer the guarantee that if your online banking is hacked they will reimburse 100%. Though not sure how truthful it is having never needed it. https://i.imgur.com/O2eOwLw.jpg Edit: "You may be liable for all losses from unauthorized use of your Account if you: contributed to its unauthorized use; used a PIN combination selected from your name, telephone number, date of birth, address,…

Ok this sounds like a terrible question but how do they stop people from "hacking" themselves...

How do insurance companies stop people from emptying their house and then burning it down? How do brick and mortars prevent people from paying with photocopied money? It is fraud, and it is generally illegal. Huge amounts of money is spent on detecting and deferring fraud attempts.

It's entirely possible to claim your card was skimmed and have your bank refund the money. However, if they then find out that the ATM used to withdraw your entire balance is the same ATM you've used for years, and your face is on the ATMs security camera at the time of withdraw, then you're in for a world of hurt.

Re: HTTPS on Your Landing Page Is Important

#200
post #175
post #64

Well, the bank seems to be stuck in the past... 10 years ago it was best practice for ecommerce shops to serve non sensitive pages (pages without forms or user data) without HTTPS to reduce the server load (HTTPS connections are a little more expensive than HTTP). Nowadays, even the economical driven ecommerce shops got it that is better to just serve everything via HTTPS. It is very sad to see a bank (which should r…

In the UK there are major ecommerce sites still on HTTP.

Major sites, really?
Post reply on HN