Network World
Sunday, October 12, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

Bank Web sites full of security holes, University of Michigan survey finds

Three out of four bank Web sites examined by the University of Michigan had at least one security vulnerability that could leave customers' at the mercy of cybercrooks (10 of the Worst Moments in Network Security). 

Like with a lot of research, the results take a while to emerge. In this case, the researchers took a look at web sites from 214 financial institutions back in 2006. Their findings will be presented at this week's  Symposium on Usable Privacy and Security (SOUPS) meeting at Carnegie Mellon University and are outlined in a paper titled "Analyzing Web sites for user-visible security design flaws."

The security shortcomings cited fall into the category of flow and layout issues, not software bugs fixable with patches. For example, about half the sites put log-in boxes on insecure pages and a third of sites surveyed created unsafe situations in redirecting customers to other sites. Use of sensitive data such as Social Security numbers as IDs was also seen as a problem, as was putting security advice and contact info on unsecured pages that could be changed by cyber thieves to direct customers unknowingly to bogus customer service reps, etc. Overall, a lack of SSL usage was cited as a reason many pages were less secure than they should be.

"To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country," said Atul Prakash, a professor in the Department of Electrical Engineering and Computer Science, in a statement. "Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking."

Prakash launched the project after noticing security issues with the web site for a bank he uses.

MUST-READS FROM BOB BROWN:

* 25 Radical network research projects you should know about


 
 
 
 
 
 
 
 

 

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Latest software headlines from Network World:

Kernel developers, Wall Street to come together

Favorite Firefox extensions

Zoho launches e-mail app with offline, mobile access

Red Hat looks to mainstream markets for growth

Goldman Sachs leads $12 million investment in Nimsoft

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: