Extra caution is recommended when installing recently uploaded/updated scripts (read more)
Be sure you trust any scripts you install
natwest-login
fill in silly "enter first, twelth and fourth" boxes
I absolutely HATE banks because they don't employ me to write their web applications. Bank webapps are the worst I've ever
used. They're so shoddy. And there's no excuse for it. Banks earn so
much money from me and everyone else that they're customer service
experience (especially the web one) ought to be tip top. But they
seem to employ people completly ignorant of web architecture.
The way banks SHOULD do authentication is with client certificates
because they would be practically unspoofable - you could maybe
spoof the DNS and present a different banking front end to the user
but to what end?. Without passwords it's not going to do you much
good.
Instead they choose to do authentication like this. With multiple
tokens and other rubbish they have dreamt up themselves. Do they
actually employ someone who considers themselves an expert to come
up with this crap?
Fortunately, hackers can fight back with Greasemonkey.
This asks for your PIN and password and then puts the characters
that the page is asking for in the correct boxes.
Amusingly I was told by the Natwest people that the whole reason for
this page was to stop programs from watching keypresses. It worked,
they explained, because computers can't understand the words
"first", "second" or "fifth".
Well, this program won't work then.
As I say, idiots.
This program is only a first step. I hope that I'll be able to make
an infrastructure that can apply client certificates to bank
authentication thus solving the problem premanently.
|
|
Hi, I just installed your script, it works really well, nice work. But, I also just figured out why it is definitely less secure for people to use this script. The reason is, it opens up vulnerability to keyloggers which are frequently installed with malware, spyware and other such nasties lurking out there on the web. If you have a keylogger that has crept onto your system, and you have installed this script, somebody will be able to remotely record your entire password and PIN code. If you only type in, for example, the 3rd and 5th characters, then your bank account, and all your precious golden coins, remains safe whatever happens. |
|
|
It doesn't seem to set focus to the input box, which is a little annoying. Otherwise, great script, thanks :D |
|
|
Hahahahaha idiots. :) Nice work. |
|
|
No. It's no more insecure than using the page's password and pin entry. |
|
|
would this not be kinda insecure??? |
You could comment on this script if you were logged in.
