Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Patching without Details Difficult to Justify | Main | DNS Cache Poisoning Code Now Publicly Available »

Design Flaws Hamper Online Banking Security

Researchers at the University of Michigan are reporting that 75% of 214 online banking sites had significant design flaws. At first this did not sound surprising, assuming the design flaws were minor tradeoffs between security and usability but that wasn't the case.

"To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country," [lead researchers] Prakash said. "Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking."

The design flaws included: placing secure login boxes on insecure pages, placing contact information and security advice on insecure pages, breach in the chain of trust when the bank redirects customers to a site outside the bank's domain, inadequate user IDs and passwords, and e-mailing security-sensitive information insecurely.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/794

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net