What was up was that on their new site, I had to use Google Chrome and only Google Chrome. Not Firefox, not even Chromium. I wonder if Edge even works.
I'm seriously considering switching providers over it.
71–80 of 122 posts
What was up was that on their new site, I had to use Google Chrome and only Google Chrome. Not Firefox, not even Chromium. I wonder if Edge even works.
I'm seriously considering switching providers over it.
Banks do stuff like this all the time - they are always the long tail of security - could be a topic in itself. I contemplated this for a very long time and decided that JP Morgan would rather take the hit for bad security then pay wages and benefits to support people to deal with password resets, lost yubikeys, etc. No other answer makes sense. My advise to OP is to dump Chase, Citibank, Bank Of America, ASAP. Move…
Banks do stuff like this all the time - they are always the long tail of security - could be a topic in itself. I contemplated this for a very long time and decided that JP Morgan would rather take the hit for bad security then pay wages and benefits to support people to deal with password resets, lost yubikeys, etc. No other answer makes sense. My advise to OP is to dump Chase, Citibank, Bank Of America, ASAP. Move…
I ran into a similar problem with the website of my general practitioner. It worked fine in all cases, except when using Firefox on Linux, which I use. After lots of testing and trying to contact whoever built the website I found that it blocked only user-agents which contained this literal string: X11; Ubuntu; Linux Only when that string was in there verbatim would it fail all requests with a 403 Forbidden. After I…
It would be a stretch to call this an outright violation (as they could satisfy the requirement by printing the information you want and mailing it to you...), but it's a trendy topic in healthcare right now, so it might be enough of a motivator.
Try Japanese business banking - where you have to pick an OS and stick with it when registering (with a paper form), and must use either the ESR release of Firefox or Internet Explorer. If you don't have a user agent of either of those it won't even let you sign in.
Try Spanish online digital administration. The digital certificates only worked in IE. And mid-process they require installing a Java-based program that required a different type of digital certificate. That of course make you restart the browser and lose all the data entered. Just wow. I couldn't even come up with such a bad process if I wanted.
> Worse, Chase even openly admits to being hostile to Linux and BSD to someone on Reddit. It’s something even Microsoft, Windows PC/hardware OEMs, or Apple won’t do. If you click through to the link, you will see that this claim is totally made up.
Banks do stuff like this all the time - they are always the long tail of security - could be a topic in itself. I contemplated this for a very long time and decided that JP Morgan would rather take the hit for bad security then pay wages and benefits to support people to deal with password resets, lost yubikeys, etc. No other answer makes sense. My advise to OP is to dump Chase, Citibank, Bank Of America, ASAP. Move…
Unfortunately can’t change loan providers, as my auto loan when was financed through the dealer ended up at Jp Morgan & Chase.
Banks do stuff like this all the time - they are always the long tail of security - could be a topic in itself. I contemplated this for a very long time and decided that JP Morgan would rather take the hit for bad security then pay wages and benefits to support people to deal with password resets, lost yubikeys, etc. No other answer makes sense. My advise to OP is to dump Chase, Citibank, Bank Of America, ASAP. Move…
(Wikipedia isn’t up to date BTW. Even before the Etrade they had over $1T in AUM)
I ran into a similar problem with the website of my general practitioner. It worked fine in all cases, except when using Firefox on Linux, which I use. After lots of testing and trying to contact whoever built the website I found that it blocked only user-agents which contained this literal string: X11; Ubuntu; Linux Only when that string was in there verbatim would it fail all requests with a 403 Forbidden. After I…
For anyone who works at the company who does that: why you do it? Is it to reduce amount of testing, and only have a few "blessed" browsers with guaranteed happy experience? Any other reasons?