<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Secure? Don't bank on it.</title>
	<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it/</link>
	<description>Comments on Ask MetaFilter post Secure? Don't bank on it.</description>
	<pubDate>Mon, 02 Apr 2007 17:35:15 -0800</pubDate>
	<lastBuildDate>Mon, 02 Apr 2007 17:35:15 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Secure? Don&apos;t bank on it.</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it</link>	
		<description>Calling webbish folks: I&apos;d like to make sure &lt;a href=&quot;http://wachovia.com/personal/forms/privacy_optout&quot;&gt;this form&lt;/a&gt; is as unsecured as it appears before I complain. More inside! &lt;br /&gt;&lt;br /&gt; So as far as I can tell &lt;a href=&quot;http://wachovia.com/personal/forms/privacy_optout&quot;&gt;this form&lt;/a&gt; is completely unsecured (which is kind of bad, as it encourages you to use your Social Security number). The page isn&apos;t encrypted, the lock icon doesn&apos;t appear even briefly when it&apos;s submitted (try arbitrary gibberish that won&apos;t validate server-side), and the form post action is not to a https:// address. It seems painfully ironic that a privacy choices form would itself be a security problem.&lt;br&gt;
&lt;br&gt;
Before I complain to Wachovia, though, I&apos;d like to make sure I&apos;m not overlooking a way this form could be secure that I don&apos;t know about.</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2007:site.59808</guid>
		<pubDate>Mon, 02 Apr 2007 17:29:44 -0800</pubDate>
		<dc:creator>musicinmybrain</dc:creator>
		
			<category>banking</category>
		
			<category>security</category>
		
			<category>privacy</category>
		
			<category>Wachovia</category>
		
			<category>webforms</category>
		
			<category>ssl</category>
		
	</item> <item>
		<title>By: aubilenon</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899588</link>	
		<description>You&apos;re right, it&apos;s crap.  Complain.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899588</guid>
		<pubDate>Mon, 02 Apr 2007 17:35:15 -0800</pubDate>
		<dc:creator>aubilenon</dc:creator>
	</item><item>
		<title>By: majick</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899592</link>	
		<description>No, the form is not submitted over an SSL link.  SSL alone wouldn&apos;t make it &quot;secure,&quot; but it would certainly help.&lt;br&gt;
&lt;br&gt;
If you wish to make use of the form with encryption, however, you can just &lt;a href=&quot;https://www.wachovia.com/personal/forms/privacy_optout&quot;&gt;tack it on to the URL yourself&lt;/a&gt; and it appears to work just fine.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899592</guid>
		<pubDate>Mon, 02 Apr 2007 17:38:03 -0800</pubDate>
		<dc:creator>majick</dc:creator>
	</item><item>
		<title>By: odinsdream</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899605</link>	
		<description>&lt;a href=&quot;https://wachovia.com/personal/forms/privacy_optout&quot;&gt;Use this one instead.&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
The link you followed must have not included the https part.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899605</guid>
		<pubDate>Mon, 02 Apr 2007 18:03:59 -0800</pubDate>
		<dc:creator>odinsdream</dc:creator>
	</item><item>
		<title>By: smackfu</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899631</link>	
		<description>OTOH, they do have a picture of a lock, with a tooltip of &quot;secure form&quot;, so that makes it OK.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899631</guid>
		<pubDate>Mon, 02 Apr 2007 18:34:22 -0800</pubDate>
		<dc:creator>smackfu</dc:creator>
	</item><item>
		<title>By: event</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899653</link>	
		<description>This is bad and well worth complaining about.  Their little picture of a lock is a real kicker.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899653</guid>
		<pubDate>Mon, 02 Apr 2007 18:53:17 -0800</pubDate>
		<dc:creator>event</dc:creator>
	</item><item>
		<title>By: Sweetie Darling</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899655</link>	
		<description>Is it a phishing address? I got a cookie warning from ehg-wachovia.hitbox.com, which I never get when we access my husband&apos;s legit Wachovia account.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899655</guid>
		<pubDate>Mon, 02 Apr 2007 18:55:22 -0800</pubDate>
		<dc:creator>Sweetie Darling</dc:creator>
	</item><item>
		<title>By: Sweetie Darling</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899659</link>	
		<description>Oops, never mind. I got to the same page from online banking login. Sorry &apos;bout that.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899659</guid>
		<pubDate>Mon, 02 Apr 2007 18:57:26 -0800</pubDate>
		<dc:creator>Sweetie Darling</dc:creator>
	</item><item>
		<title>By: malphigian</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899662</link>	
		<description>FYI, the https:// version works fine:&lt;br&gt;
&lt;a href=&quot;https://wachovia.com/personal/forms/privacy_optout&quot;&gt;https://wachovia.com/personal/forms/privacy_optout&lt;/a&gt; -- maybe you just clicked a bad link?&lt;br&gt;
&lt;br&gt;
A lot of web servers have http and https pointing to the same directory.  This isn&apos;t really a security issue unless someone links to the wrong one.&lt;br&gt;
&lt;br&gt;
I don&apos;t think it&apos;s a phishing address.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899662</guid>
		<pubDate>Mon, 02 Apr 2007 18:58:45 -0800</pubDate>
		<dc:creator>malphigian</dc:creator>
	</item><item>
		<title>By: smackfu</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899665</link>	
		<description>Yeah, it&apos;s linked (insecurely) from the Privacy link at the bottom of every page.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899665</guid>
		<pubDate>Mon, 02 Apr 2007 18:59:19 -0800</pubDate>
		<dc:creator>smackfu</dc:creator>
	</item><item>
		<title>By: musicinmybrain</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899666</link>	
		<description>Thanks for the alternative links, majick and odinsdream. I had tried the swap to https:// myself, in fact... but I posted the regular http:// version because that&apos;s how it&apos;s linked from the &lt;a href=&quot;http://wachovia.com/privacy&quot;&gt;main Wachovia privacy page&lt;/a&gt; (d&apos;oh!).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899666</guid>
		<pubDate>Mon, 02 Apr 2007 19:00:21 -0800</pubDate>
		<dc:creator>musicinmybrain</dc:creator>
	</item><item>
		<title>By: Gerard Sorme</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899700</link>	
		<description>Look at this!&lt;br&gt;
&lt;a href=&quot;http://www.chase.com/&quot;&gt;http://www.chase.com/&lt;/a&gt;&lt;br&gt;
and the controversy it caused:&lt;br&gt;
&lt;a href=&quot;http://blogs.zdnet.com/Ou/?p=226&quot;&gt;http://blogs.zdnet.com/Ou/?p=226&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Even though the log-in is redirected to an SSL secured page, it is actually not secure for an instant. Does Chase care? Read all the comments under the ZDNet article. Bottom line: No. They use the same trick with the graphic of a lock. People have been told, &quot;Look for the lock,&quot; so...Chase gave them a lock!&lt;br&gt;
&lt;br&gt;
-</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899700</guid>
		<pubDate>Mon, 02 Apr 2007 19:36:11 -0800</pubDate>
		<dc:creator>Gerard Sorme</dc:creator>
	</item><item>
		<title>By: knave</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899736</link>	
		<description>Gerard, correct me if I&apos;m wrong, but the &quot;action&quot; attribute for the logon form is a POST to a https:// url.  In other words, the data should be encrypted.  I&apos;m a Chase customer, and I use that form, so this is not a hypothetical question at all for me.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899736</guid>
		<pubDate>Mon, 02 Apr 2007 20:14:41 -0800</pubDate>
		<dc:creator>knave</dc:creator>
	</item><item>
		<title>By: rbs</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899737</link>	
		<description>I&apos;m so glad you posted this. I&apos;ve noticed this on my credit card sites and it drives me crazy!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899737</guid>
		<pubDate>Mon, 02 Apr 2007 20:17:05 -0800</pubDate>
		<dc:creator>rbs</dc:creator>
	</item><item>
		<title>By: Civil_Disobedient</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899804</link>	
		<description>If the form action uses POST to send the parameters, the originating script &lt;b&gt;need not&lt;/b&gt; be from a secure site.  If, on the other hand, the form action uses GET, the form variables will be sent in the URL, which is insecure regardless of whether the transport layer is SSL or not.&lt;br&gt;
&lt;br&gt;
While the Wachovia form &lt;i&gt;does&lt;/i&gt; submit the form using POST, it&apos;s not specifically to a secure site. It looks like they just used a relative path, which is &lt;b&gt;LAZY&lt;/b&gt; programming on their part.  Had they simply hard-coded a SSL-enabled URL in the post action, they could have avoided all this hassle.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899804</guid>
		<pubDate>Mon, 02 Apr 2007 22:08:23 -0800</pubDate>
		<dc:creator>Civil_Disobedient</dc:creator>
	</item><item>
		<title>By: allterrainbrain</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899817</link>	
		<description>The grapevine being what it is, I expect somebody at Wachovia mgmt has seen this thread by now and will make sure to get these (simple) changes made -- both the relative-URL submission Civil Disobedent points out and the fact that all the internal links point to the http rather than htpps page.  But just in case, yeah, it might be worth notifying them.  &lt;br&gt;
&lt;br&gt;
And thanks for caring enough to ask about it here.  Pretty amazing to see a major bank asking for SSNs on an &quot;http&quot; page in 2007.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899817</guid>
		<pubDate>Mon, 02 Apr 2007 22:54:07 -0800</pubDate>
		<dc:creator>allterrainbrain</dc:creator>
	</item><item>
		<title>By: allterrainbrain</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899823</link>	
		<description>(Yes I meant https.)&lt;br&gt;
(And it might be worth pointing out explicitly that even as we discuss this, the changes may be underway -- but as of this post the privacy links in the global footer are still pointing to the http page.)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899823</guid>
		<pubDate>Mon, 02 Apr 2007 23:01:03 -0800</pubDate>
		<dc:creator>allterrainbrain</dc:creator>
	</item><item>
		<title>By: footnote</title>
		<link>http://ask.metafilter.com/59808/Secure-Dont-bank-on-it#899939</link>	
		<description>I was glad to see that the awesome Commerce Bank seems to have &lt;a href=&quot;https://www.commerceonlinebanking.com/&quot;&gt;proper &lt;/a&gt;security.  Just another reason to love my bank.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.59808-899939</guid>
		<pubDate>Tue, 03 Apr 2007 05:54:07 -0800</pubDate>
		<dc:creator>footnote</dc:creator>
	</item>
	</channel>
</rss>
