Is internet banking secure?
->
Utusan Malaysia today covers front page story on the reliability of Malaysian internet banking facilities. It mention specifically the phishing threat all around the internet banking users where an exact replication of those banking facilities websites can be made in hours. Some good webmasters can do it less than 30 minutes. Download the real websites template to local computer in 2-3 minutes, write a logging script (ASP,PHP or any scripting) in another 5-7 minutes, upload them all to your own web space. Get few more minutes to spam targetted email addresses asking them to change password. If one really serious in doing it, I don’t think it’s hard to get 1 people to fall into the trap in a day. Out of 1000 people reading the emails, 1 people will click the link and give what you need (usernames,passwords). That’s the standard conversion rate, it might be in better figure in Malaysia considering the low safety awareness of the internet users.
Btw, the article report that one victim manage to get some help from NISER. That’s nice to know, at least there are people who will help us with cyber crimes. I wrote one suggestion about this in my previous article.



October 21st, 2006 at 2:45 am
Maybe banks can u the sign-in seal like that been used by Yahoo mail. No need for smartcards.