Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

161–170 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#161
post #138
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

My citibank credit card redirects me to "cardservicesdirect.com.au" -- which reads like a phishing site if I've ever seen one. I confirmed over the phone with their support that was indeed the correct site before typing anything into it.

But did you call the support phone number shown on the dodgy domain?

Re: HTTPS on Your Landing Page Is Important

#163

Earlier quoted context omitted.

Microsoft's sign in is a real mess, I think in part due to having to make your hotmail login that you made 15 years ago still work, along with the dozens of other services that MS has acquired or integrated. I've had a real shitter of a time trying to login before, with redirect loops, or getting automatically signed out as soon as I sign in. Or accounts being a "games for Windows" account, but not an MS account, or…

I hear you. I was pulling my hair out the other day trying to find my Microsoft credentials in LastPass. I was searching for "microsoft", "office", "outlook" etc. until I finally found them under "live.com".

I also have an @live.com email. I think "live" was one of Microsoft's many failed services rebrands. Remember windows live messenger, windows live photo gallery? Lol

Re: HTTPS on Your Landing Page Is Important

#164

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

I know of at least one bank that requires your password to have exactly one digit. Not one or more, exactly one.

Re: HTTPS on Your Landing Page Is Important

#165

Earlier quoted context omitted.

I hear you. I was pulling my hair out the other day trying to find my Microsoft credentials in LastPass. I was searching for "microsoft", "office", "outlook" etc. until I finally found them under "live.com".

I also have an @live.com email. I think "live" was one of Microsoft's many failed services rebrands. Remember windows live messenger, windows live photo gallery? Lol

And before that, the grandiose ".Net passport"

Re: HTTPS on Your Landing Page Is Important

#166

It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.

I know of at least one bank that requires your password to have exactly one digit. Not one or more, exactly one.

http://password-shaming.tumblr.com/

Re: HTTPS on Your Landing Page Is Important

#167
post #165

Earlier quoted context omitted.

I also have an @live.com email. I think "live" was one of Microsoft's many failed services rebrands. Remember windows live messenger, windows live photo gallery? Lol

And before that, the grandiose ".Net passport"

Microsoft's account system has had at least five different names; it's just "Microsoft account" right now, but it'll likely be called something different in a year or two the next time Microsoft does one of their gigantic "rebrand all the things" purges.

Re: HTTPS on Your Landing Page Is Important

#168

A great example for why we (the Google Web Developer Relations team) advocate for HTTPS everywhere. https://developers.google.com/web/fundamentals/security/encr...

Google likes https for their own selfish reasons. Yes, it's still a good thing. But what Google really likes is that it keeps ISPs, hotspot operators, and others from enjoying the same ubiquitous traffic snooping they get via AdSense, Google Analytics, Android, Chrome, their CDN, etc.

It's nice that their goals align with something actually helpful. But don't mistake the motive. This extends their dominance in global snooping.

Re: HTTPS on Your Landing Page Is Important

#169
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

Microsoft's login experience has been generally broken for years. Multiple redirects through different domains. Heck it uses Javascript redirects. In 2017. So your back button won't work. And it has a habit of just not working. I went to visit a public page on docs.microsoft.com and wound up dead on a white page on login.live.com because it decided I needed to be redirected to login. Just to view a docs page.

Re: HTTPS on Your Landing Page Is Important

#170

Earlier quoted context omitted.

I assume one team is responsible for the home page, and another team is responsible for the banking portal, and they can't be bothered to coordinate with each other.

True true true. I know of some banks where invest.examplebank.com and bank.examplebank.com are controlled by mutually distrustful organizations. They really should put their stuff into the public suffix list at https://publicsuffix.org/ , because, session cookies. But that would assume they knew something about what they were doing.

Are you talking about Schwab? I don’t see why you need to hide this bank’s identity.
Post reply on HN