Archived Comments (locked)
|
|
The following is an archive of comments made before threaded discussions was implemented (November 16th, 2008) |
|
|
I've uploaded a new version that works with the latest ING site updates. |
|
|
Matthew, Could you write a script that would allow me to sort the "View my Account" table by Account Nickname, Balance, or Available Balance? |
|
|
I've updated it to work on the new ING login page, and added a function. When ING enrolls me in the "new security feature", I'm planning to post a proof of concept exploit for that too. It seems fundamentally flawed. They have to show you the picture and phrase before authenticating you, so an unauthenticated adversary has that data available to phish with. I don't know what the details are, but this problem seems unavoidable. |
|
|
Thank you. It was meant as a proof of concept as much as anything else, though I do use it (but only on my own computer). |
|
|
The virtual keyboard does mitigate the key logger threat.
Nice script though. |