• Sign Up
  • |
  • Sign In Sign Out
  • |
  • Make us your home
  • |
  • RSS
1 2
1 15
1 4
1 9
1 13
1 14
IPO
1 25
1 5018
SME
1 5018
  • MAY JOIN RACE FOR SHELL'S EUROPEAN REFINERIES: SOURCES
  • SENSEX, NIFTY UP 1% EACH FOR THE WEEK
  • CNX MIDCAP INDEX UP 1%, BSE SMALLCAP INDEX UP 1.6%
  • METAL INDEX UP 3.7%, AUTO INDEX UP 2.3%, FMCG UP 1.5%
  • INDEX GAINERS: SUZLON UP 9.3%, TATA STEEL UP 6.3%, SAIL UP 5.3%
  • RIL SPOKESPERSON TO NDTV: 'REVIEWS CANNOT ASSURE TRANSACTIONS'
  • RIL SPOKESPERSON: 'WE ARE REVIEWING A NUMBER OF GLOBAL OPPORTUNITIES'
  • ESSAR-SHELL IN EXCLUSIVE NEGOTIATIONS TILL NOV 30 TO BUY 3 SHELL REFINERIES
  • APPROACHED SHELL FOR BUYOUTS BEFORE ESSAR'S EXCLUSIVE TALKS BEGUN
  • JSW ENERGY ALSO IN RACE FOR ANDREW YULE'S DPSC STAKE: NW
  • CESC, SREI INFRA IN RACE FOR ANDREW YULE'S DPSC STAKE: NW
  • GAMMON INFRA BAGS NHAI PROJECT WORTH RS.850 CRORES
  • NET PROFIT AT RS.48.2 CR VS RS.12 CR; SALES UP 55% AT RS.849 CR (YOY)
  • PROFIT UP 55% AT RS.143.50 CR; NET SALES UP 22.5% AT RS.2234.20 (YOY)
  • IMPORTING SUGAR BEING REVIEWED; NEED FOR ECONOMIC PRICING OF SUGAR
  • IN DISCUSSIONS WITH FARMERS TO COME AT PRICE COMFORTABLE FOR BOTH SIDES
  • TOO EARLY TO TALK OF DENA BANK MERGER WITH ANOTHER PSU BANK: NW
  • KEEPS OVERNIGHT LENDING RATE UNCHANGED AT 0.1%
  • STILL SEE DOWNSIDE RISK FOR THE ECONOMY
  • AIM TO CONVERT NON USERS TO USERS WITH THE HELP OF ROAMING TARIFF CUTS
  • PREFER TO REMAIN AGGRESSIVE WITHOUT GETTING INTO A PRICE WAR
  • MURTAZA KHORAKIWALA TO NDTV: CANNOT COMMENT ON SUB JUDICE MATTER
  • WOCKHARDT TO PAY BACK ALL SECURED, UNSECURED LOANS IN 5 YRS AS PER CDR
  • DBS TOP BRASS MET HABIL KHORAKIWALA TO DISCUSS WAYS OF SETTLEMENT: SRCS
  • EYEING TO SETTLE PAYMENT DEFAULT CASE OUT OF COURT: SOURCES
  • ALERT: ROAMING CONTRIBUTES 15% OF BHARTI REVENUES
  • ROAMING CALLS ON OTHER NETWORKS AT 80 PAISE/MINUTE
  • ROAMING CALLS ON OWN NETWORK AT 60 PAISE/MIN
  • SWAP TO REDUCE OVERALL FINANCE CHARGES FOR THE COMPANY: CFO
  • COMPLETES SWAP OF $875MN FOREX CONVERTIBLE BONDS
Updated: 24/07/2008 | 12:42 PM IST
Design flaws make online banking vulnerable: study
Press Trust of India
Thursday, July 24, 2008 (New York)
Comments:
Read (0)

A majority of websites floated by banks have design-related flaws that could make customers vulnerable to cyber-theft, endangering their money or even their identities, a study has found.

Led by an Indian American professor at University of Michigan, a study that surveyed web sites of 214 financial institutions in 2006 found that more than 75 per cent of them had at least one design flaw that made customers vulnerable to cyber thieves.

These design flaws were not bugs that could be fixed with a patch, the authors said, but they stemmed from the flow and layout of Web sites.

The flaws include placing log-in boxes and contact information on insecure web pages as well as failing to keep users on the site they initially visited.

Atul Prakash, Professor at the Department of Electrical Engineering and Computer Science, who led the research along with doctoral students Laura Falk and Kevin Borders, said some banks may have taken steps to resolve the problems since data was gathered, but there is still much room for improvement.

The findings will be presented for the first time at a Symposium on Usable Privacy and Security meeting at Carnegie Mellon University tomorrow.

"To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country," Prakash said.

"Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking."

The flaws leave cracks in security that hackers could exploit to gain access to private information and accounts.

The Federal Deposit Insurance Corporation (FDIC) says computer intrusion, while relatively rare compared to financial crimes like mortgage fraud and check fraud, is a growing problem for banks and their customers.

A recent FDIC Technology Incident Report, compiled from suspicious activity reports filed by banks, listed 536 cases of computer intrusion, with an average loss per incident of $30,000. That added up to nearly $16-million loss in the second quarter of 2007.

Computer intrusions increased by 150 per cent between the first quarter of 2007 and the second. In 80 per cent of the cases, the source of the intrusion was unknown but it occurred during online banking, the report stated.

The design flaws Prakash and his team looked for include placing secure login boxes on insecure pages, which allow hackers to reroute data entered in boxes or create a spoof copy of the page to harvest information. A full 47 per cent of banks were guilty of this.

Another flaw was putting contact information and security advice on insecure pages, which an attacker could manipulate by changing an address or phone number and setting up his own call center to gather private data from customers who need help, Prakash said.

Besides, breach in the chain of trust occurs when a bank redirects customers to a site outside the bank's domain for certain transactions without warning, Prakash added. He found this problem in 30 per cent of the banks surveyed.

Allowing inadequate user IDs and passwords, which are easy to guess or find out also amounts to a security flaw, the study found.

Comments:
Read (0)
Comments
 
Market Watch
         
Graphs
Stocks

                                Moremore
Stock Dashboard
Trading Calls
Rupal Saraogi
Rupal Saraogi
2.09% status
Current: Rs 1755.5
Simi Bhaumik
Simi Bhaumik
2.43% status
Current: Rs 2335.75
Stock Recos
The investors should remain invested in the stock
The investors can book partial profit and hold the remaining stock with a stoploss of closing below Rs 105
Buy or Sell
Today's Analyst: Neera Jain
Query : Sukhendu, an investor from Mumbai, has 500 Wockhardt at Rs 184/share.