More than 75 percent of the bank Web sites surveyed in a University of Michigan, Ann Arbor, study had at least one design flaw that could make customers vulnerable to cyberthieves after their money or even their identity. The study — Analyzing Web sites For User-Visible security Design Flaws — conducted by the University of Michigan’s Department of Electrical Engineering and Computer Science, examined the Web sites of 214 financial institutions in 2006.
The study concluded that the design flaws researchers discovered weren’t bugs that can be fixed with a patch, but rather they stemmed from the flow and the layout of the Web sites.
The flaws include placing log-in boxes and contact information on insecure Web pages as well as failing to keep users on the site they initially visited, according to Atul Prakash, co-author of the study.
“To our surprise, design flaws that could compromise security were widespread and included some of the largest banks in the country,” Prakash said. “Our focus was on users who try to be careful, but unfortunately some bank sites make it hard for customers to make the right security decisions when doing online banking.”
The flaws leave cracks in security that hackers could exploit to gain access to private information and accounts, Prakash said. While some banks may have taken steps to resolve these problems since the study data were gathered, overall, Prakash said, he still sees much need for improvement.
According to the study, 47 percent of banks placed secure login boxes on insecure pages. A hacker could reroute data entered in the boxes or create a spoof copy of the page to harvest information. In a wireless situation, it’s possible to conduct this “man-in-the-middle” attack without changing the bank URL for the user, so even a vigilant customer could fall victim, Prakash explained.
To solve this…