<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2009://3.3727-</id>
  <updated>2009-11-18T17:49:31Z</updated>
  <title>Comments for Can I prevent phishing attacks by using a bookmark?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34833</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34833" />
    <title>Comment from howiem on 2009-06-03</title>
    <author>
      <name>howiem</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>I should have mentioned in my initial question that when one finishes a banking session, one should always log out and then close the browser window/tab.  But this is not always possible (if the browser crashes, for example, in which case I restart the browser, log in and log out again.  I also use Sandboxie and have separate sandboxes dedicated to each bank I use, plus No-Script and various web analysis tools to alert me to bad web sites. </p>

<p>One of the reasons for using an https bookmark is that as I understand it, a request to  visit a web site goes through a Domain Name Server (DNS).  Some are secure and some are not.  By using the https bookmark, the request to visit a web site goes to a secure DNS and is redirected to the log-in page.  Typing in an IP number will go to a non-secure DNS, and if it has been compromised (called DNS poisoning) it will make no difference if you use the normal URL or the IP number.  But when using a bookmarked https address, the site visit request will go through a secure DNS, and I have not heard of any of those being compromised to date.  Leo, correct me if I am wrong on this.  </p>

<p>Using bookmarks do not have any effect of the banking session length, and because using https bookmarks is more secure, why in the world would a bank want to prevent bookmarking them?  </p>

<p>I am curious as to how typing the correct IP number  makes any difference in security.  The request still has to go to an unsecure DNS.  If you type the name of the site correctly, the DNS translates it to an IP number anyway, so while there might be a tiny increase in speed, it is no more secure than typing in the CORREC name.  And one can make a typo on an IP number just as one can mistype a word.  Using a password manager is always a good idea, though, as long as you are sure you are on the genuine web site.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-06-03T20:21:42Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34832</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34832" />
    <title>Comment from J. Y. on 2009-05-17</title>
    <author>
      <name>J. Y.</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Back to the phishing problem... Another circumventing possibility?  You can right-click on any link within an email, copy the shortcut and paste it to your browser address bar, see whether it is, indeed, the correct address before actually going to the site.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-17T17:02:35Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34831</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34831" />
    <title>Comment from Linda on 2009-05-12</title>
    <author>
      <name>Linda</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I'm with all of you. Any bank that keeps you logged in to a secure site is NOT a bank I want to deal with. My bank has a 10 minute interval until you must sign in again. I like it.<br />
<div class="leocomment">For the record, this has nothing to do with bookmarking. It's very reasonable to have a bookmark deep in the bank's site, and have it boucne you to a login page if that's required. (The best will then return you to the page you bookmarked, <strong>after</strong> you've logged in).<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">13-May-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-13T03:12:59Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34830</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34830" />
    <title>Comment from George on 2009-05-12</title>
    <author>
      <name>George</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I agree with the previous comments, you should not be able to bookmark a secure banking site, it should go to the main login page only. In addition I use the ip number for the bank instead of a normal url. This still only takes you to the main login page. I type in the IP# such as 143.0.XXX.XXX. You can also save that in a program such as KeePass or Roboform and it will take you there immediately with auto login if you set it up correctly. Almost the same as using a url, but less chance of being redirected to some phony page.<br />
(¯`·._.·ns¢ävË·._.·´¯)<br />
    www.nscave.com</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-12T19:15:27Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34829</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34829" />
    <title>Comment from Brad on 2009-05-12</title>
    <author>
      <name>Brad</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I don't understand the basis of the queestion for this tip.  Any bank that allows you to bookmark ANYthing other than their 'front page' or login screen is NO bank I'd want to do business with.  What gigi said is true. TRY to bookmark anything 'inside' the bank site.  If you CAN bookmark that page...change your bank. <br />
<div class="leocomment">Yikes, that seems kinda harsh. For the record, I disagree. Being able to bookmark a page is benign. One way or another, it's going to happen. Rather than disallowing it, banks should simply be handling the security implications of people using them. Depending on the implementation that could mean, as another commentor has stated, bouncing to a secure login page. But disallowing bookmarks completely is not only overkill, but ineffective.<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">13-May-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-12T18:15:07Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3727-comment:34828</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3727" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html#c34828" />
    <title>Comment from Gigi on 2009-05-12</title>
    <author>
      <name>Gigi</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>The described procedure has a major weak point: for security reasom most banks log you out from your account when you leave their site; so, when you connect again to a page in which you previously entered after login, you would (at best) get bumped to a generic (non secure) page or - usually - you get an error.<br />
The safest way is to type the site's URL yourself, ideally in a Live-CD OS - no chance of infection so no chance of hyjacking. Otherwise bookmark the site before login.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/can_i_prevent_phishing_attacks_by_using_a_bookmark.html">Can I prevent phishing attacks by using a bookmark?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-05-12T15:51:34Z</published>
  </entry>

</feed>
