The following  exchange was initiated by me to my bank in an attempt to get my bank to fix a WEB security problem. Note the dates as posted:
9/13
I am stressed out by your web site security. On my USBank account I am forced to type in both my user name and password. With your (Tech CU) site, I only have to click on my user (field) and up pops my user id and then when progressing to the password page, the password pops in automatically. If my laptop were stolen, it wouldn't take any effort at all to get access to my (bank) account and xfer my money out. My email accounts are more secure then my bank account. Isn't that just wrong?


9/17
Hello James:

Thank you for using TechCU Secure Email.

This is in regard to your user name and password inquiry.

A setting in your Firefox browser is causing your user name and password to be remembered.

To stop your browser from remembering your username and password, please click “Options” and then uncheck the box to remember your passwords.

For further questions or comments, please contact us.

Thank you,

Tom Dunn
AVP - Member Contact Center
Technology Credit Union

Tom, perhaps you misunderstood, same browser, same settings, U.S. Bank requires me to type the security (sign in) information in, tech CU doesn't. Your web interface needs adjusting, not my browser settings. You need to learn what it takes to do this, not me.

9/18
Hello James:

Thank you for using TechCU Secure Email.

This is in regard to your username and password inquiry.

TechCU’s Online Banking system is not set to have usernames and passwords memorized.

TechCU is not able to make changes to your browser settings. To stop your browser from remembering your username and password, please click “Options” and then uncheck the box to remember your passwords. TechCU is unable to do this for you.

More than likely, your browser asked if you wanted your username and password memorized when you access your TechCU account, and “yes” was selected. And, “no” was probably selected for your US Bank account, which is why the accounts operate differently.

For further questions or comments, please contact us.

Thank you,

Tom Dunn
AVP - Member Contact Center
Technology Credit Union

9/18
Boy, I am pointing out a serious flaw in your web site HTML code and you keep referring the problem to me and my browser. Do I need to escalate and take this to upper management?

I thought it was enough to point out that US Bank has web security HTML code to prevent my browser from auto filling these user and password fields. Do you not understand this? and the importance of not letting my browser auto fill these two fields?

Really, this is a serious problem and it is your problem, not mine.


9/24
Hello James:

Thank you for using TechCU Secure Email.

This is in regard to your username and password request.

Your original Secure Email was forwarded to upper management, and it was the VP of Enterprise Applications who confirmed it was a browser setting that was remembering your password.

If you disable this feature on your browser, your username and password will no longer be remembered.

For further questions or comments, please contact us.

Thank you,

Tom Dunn
AVP - Member Contact Center
Technology Credit Union


and now it works as expected and you say you did nothing?

9/24
Hello James:

Thank you for using TechCU Secure Email.

You inquired about accessing Online Banking.

Your Secure Emails were forwarded to the Enterprise Applications group, who were able to configure the sign on page so that browsers are unable to remember user names and passwords.

For further questions or comments, please contact us.

Thank you,

Tom Dunn
AVP - Member Contact Center
Technology Credit Union



From 9/13 to 9/24 before being resolved.  Like touring a sausage factory............

, ,

© copyright mark  All of the images and text on this post are copyright protected and have been digitally watermarked.  The images and text displayed here, in no way implies consent for any form of distribution or reuse.  Email me if you desire permission to do so. 


web metrics