Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Oh, common.

  Username: ____
  Password: ____

  Please note that as of June 7th 2012 the system prompt
  image identification system has been deprecated and
  being replaced with new security measures.

  If you have any questions or require assistance, contact
  technical support at support@bank.com
How many tech savvy persons would not be even a bit surprised by their bank legitimately doing something as retarded as this?


I wouldn't be surprised.

Some fairly large banks here in Norway have at times ran with a not-completely-valid SSL certificate - making the bank login indistinguishable from a man-in-the-middle.

Answer from their phone support? "Oh yeah whenever you see that warning, just click 'allow' or 'ignore'."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: