eWoss Home
  
Make eWoss Your Homepage
eWoss News
Breaking News Headlines
Top News Stories
U.S. National News
World News
Sports News
Business News
Entertainment News
Tech Industry News
Political News
Science News
Health News
Weird News

High Tech News

Study: Online banking possibly dicier than assumed

Wednesday, July 23, 2008 2:05:06 PM
By JORDAN ROBERTSON

SAN FRANCISCO (AP) - Many banks are unwittingly training their online customers to take risks with their passwords and other sensitive account information, leaving them more vulnerable to fraud, new research shows.

The result is that even the most security-conscious Web surfers could find themselves the victims of identity theft because they've been conditioned to ignore potential clues about whether the banking site they're visiting is real — or a bogus site served up by hackers.

That's the conclusion by University of Michigan researchers who found design flaws in 76 percent of the 214 U.S. financial institution Web sites they studied.

The study, to be presented Friday at a security conference, examined the sites of top banks and smaller institutions alike. The researchers aren't detailing which banks had problems, however.

"We want banks to make the right decisions so people who are trying to be careful can do online banking securely," said the paper's lead researcher, Atul Prakash, a professor of computer science and engineering.

The researchers found that many banks silently redirect users to third-party sites, plop "secure login" boxes on insecure Web pages, and improperly use Social Security numbers or e-mail addresses — which an outsider can figure out — as default user names.

All of those banking tactics put users at risk.

"Conventional wisdom is that the clients — or PCs — are inherently insecure devices," said Avivah Litan, a banking security analyst with Gartner Inc. "What this study shows is that the servers — or the bank and other consumer-facing Web sites — are also inherently insecure."

The research didn't uncover vulnerabilities in the Web sites themselves, or problems with the sites' coding that could allow criminals to break in. Instead, it found design flaws that teach people bad surfing habits.

One of the biggest problems: Even if the login boxes on banks' pages are properly secured — meaning they send and receive encrypted data through a technology known as Secure Sockets Layer — if the full page itself isn't protected with the same technology, it's more difficult to tell whether the site is real or fake.

SSL-equipped sites show a padlock icon in the address bar and signal not only the encryption technology but also that the site's owner is legitimate.

Also: If users aren't notified that they're being taken to another site — say a bank uses a partner site for online bill-paying — then it's hard to determine if the new site is trustworthy, because the online registration certificate carries a different company's name.

So even if they were inclined to dig that deep, consumers could still fall victim to "phishing" scams because they're accustomed to entering personal information into a site that isn't their bank's — and hasn't been clearly vouched for by the bank.

Hackers could take advantage by sending them bogus pages dressed up like the bank's Web site. That site would then redirect to another site under the criminal's control, and users might not question the redirection.

To fight that, the best protection remains: Don't click on links sent in e-mails.


Other High Tech News

Top court stays out of DVR patent fight 11:40AM CT
SAP says business turmoil hitting its bottom line 11:36AM CT
EBay to cut 1,600 jobs, 10 percent of work force 11:27AM CT
Ford feature will let parents set limits for teens 8:36AM CT
Ask.com hopes to make search faster, more relevant 8:15AM CT
EBay buys Bill Me Later for $945 million 8:14AM CT
Fraud plagues prepaid calling card market Oct 5 2008 2:54PM CT
CNN hands over info on author of Steve Jobs rumor Oct 3 2008 7:20PM CT
Google agrees to brief delay of Yahoo ad deal Oct 3 2008 6:11PM CT
Ex-McAfee executive clear of illegal option dating Oct 3 2008 5:22PM CT

  

© 2004-2007 eWoss.com. All trademarks are the property of their respective owners. All Rights Reserved.
Copyright 2008 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.