4 ms·
Much as I'm in favour of people understanding the structure of URLs, the article is wrong suggest this is the best way to prevent bank phishing. The correct adv
by by 17y ago
Much as I'm in favour of people understanding the structure of URLs, the article is wrong suggest this is the best way to prevent bank phishing. The correct advice is to bookmark your bank login URL, if your bank is competent this should be an https address, and always reach your login page using this bookmark. Never click a link in an email to login to your bank, it requires a great deal of effort and skill to check an emailed URL is valid.
- patio11 17y agoAnd your bank makes it hard for you! Chase Bank sent me a (legitimate!) email this week saying "We've just intercepted a suspicious transaction and tried reaching you by phone but we couldn't. Please click here if you authorized it or click here if you didn't." And then the link threw up a security certificate error! If they hadn't had my name, four digits of my account number, and a number exactly matching the number Google had just emailed me to say "We tried charging you $523.25 for your AdWords account but it got denied by your bank" 2 hours earlier, I would have sworn it was the world's best phishing attempt.
- by 17y agoYes, they're terrible at URLs too. Here's another case of something similar to your problem back in 2006. http://www.lightbluetouchpaper.org/2006/03/10/banks-dont-help-fight-phishing/ http://www.lightbluetouchpaper.org/2006/03/10/banks-dont-hel...
- byrneseyeview 17y agoIt gets worse: http://www.pixelmonkey.org/2009/08/21/chase-insecure http://www.pixelmonkey.org/2009/08/21/chase-insecure Chase sent me this, too. If you visit the site in Chrome, it tells you it's a suspected phishing site.
- jerf 17y agoYou should submit that as a top-level HN story.