3 ms·
Financial services should employ a second JS-based PKI layer. BofA has no excuse. "... log into the BofA website using the AccountID of "barry123457". While th
by MHammond 12y ago
Financial services should employ a second JS-based PKI layer. BofA has no excuse.
"... log into the BofA website using the AccountID of "barry123457". While this transaction went over SSL, you can see clearly that sslsplit was able to intercept it. AS you can see, in the middle of the post information is the string "barry123457".
- t0mas88 12y agoYou realize that anything the real BofA site adds to increase security can be removed by the proxy? Once your CA trust-store is compromised there really is no way to do anything secure without asking the user to use another channel to verify things.
- mschuster91 12y ago> You realize that anything the real BofA site adds to increase security can be removed by the proxy? This is true for targeted attacks only. A second JS layer doing crypto can at least prevent firesheep-class untargeted mass snooping of auth data.