Time to regulate banks' Internet activities?
Comments
I work for one of those vendors (VeriSign) and we would indeed like to see federally mandated encryption, but there's enough competition between security providers to suggest that the intention here is sound. In all honesty, if you're looking to cut down on phishing there are few solutions as expedient as extended validation ssl -- the green url bar can't be spoofed by hackers looking to purloin personal info. And the more banks that implement EV SSL the more users that will be educated on the significance of the green url bar, which will additionally cut down on the success rate of MITM attacks and a host of other perils. Across the board encryption can only help.
Yes, that's exactly what we need, the government telling us how to write software. After all, they so good at security, just ask the terrorists in Afghanistan...



