Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.




623 posts

Ultimate Geek


# 223175 17-Sep-2017 09:38
Send private message

 

 

 

 

"Westpac NZ will never email you a link to Westpac Online Banking, or ask you for your security details or passwords by email."

 

 

 

 

 

The above line appears on the top of the Westpac email I received this morning advising that my online credit card statement is available.

 

The thing I find interesting is that there are nine links in the email to Westpac websites???

 

"You can view, download and print your statements anytime by going to westpac.co.nz and logging into Westpac One."


Create new topic
Mr Snotty
8909 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  # 1867455 17-Sep-2017 09:51
Send private message

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.

 

Many banks do this.





2132 posts

Uber Geek


  # 1867457 17-Sep-2017 10:01
7 people support this post
Send private message

michaelmurfy:

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.


Many banks do this.


Doesn't that contradict the basic rules though? Surely routinely putting links into emails leading to banks websites is just teaching people it's ok to use email links to the banks websites.

Seems pretty foolish to me.
People are pretty stupid, and habits are created easily.




Location: Dunedin

 


 
 
 
 


6765 posts

Uber Geek

Trusted
Lifetime subscriber

  # 1867459 17-Sep-2017 10:04
4 people support this post
Send private message

michaelmurfy:

 

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.

 

Many banks do this.

 

 

I don't see how linking to the home page is any better.

 

The reason for not directly linking to the login page is presumably to stop people from being "conditioned" to click on links without checking them (to avoid phishing). But by linking to the home page, it doesn't actually solve the problem - the phishers will then just need to make an additional fake page that looks like Westpac's home page, complete with its own "Log In" link that goes to the actual phishing page.

 

It's a little more work for the phishers, but doesn't seem to be any more secure. Or am I missing something?

 

Edit: What Andrew said :)




623 posts

Ultimate Geek


  # 1867461 17-Sep-2017 10:09
Send private message

Clicking on the link in the bottom line of my post takes you to the page with the login button.

 

Isn't this how phising works?

 

You receive an email that looks to be official from your bank, PayPal, etc which has a link. You click on the link and a page opens asking you to log in.........

 

 

 

Must learn to type faster!


Mr Snotty
8909 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  # 1867467 17-Sep-2017 10:21
Send private message

andrewNZ:
Doesn't that contradict the basic rules though? Surely routinely putting links into emails leading to banks websites is just teaching people it's ok to use email links to the banks websites.

Seems pretty foolish to me.
People are pretty stupid, and habits are created easily.

 

Not really. It is directing you to an easy to verify url (eg: https://westpac.co.nz) instead of your internet banking page and also telling you to navigate to it and login. All phishing emails I have come across do not clone the complete homepage and instead attempt to take you to a phishing page which is simply the internet banking login.

 

Other links may include help pages etc - they're stating in the email they'll never directly link you to the internet banking login. While I partly agree with what you're saying if you got an email for lets say a special term deposit rate like this:

 

"As you're a special customer we have a special term deposit rate for you - head over to our website and click on investments then term deposits to find out more" it is easier for everyone to go "Go over to https://westpac.co.nz/termdeposits for more information".

 

Like you said - some people are pretty stupid...





5595 posts

Uber Geek


  # 1867473 17-Sep-2017 10:41
4 people support this post
Send private message

Having links in those emails is just setting the customer up for a fail later. It doesn't matter what the link is - you subconsciously trust it because it wasn't a problem last time you clicked on a link in a bank email.

 

For people to avoid phishing scams, they have to recognise (while distracted on other tasks) that the action being asked in the phishing email is not normal - if they are used to clicking links in banks emails, there is a higher probability of them clicking the link when a phishing email comes through.


1014 posts

Uber Geek
Inactive user


  # 1867501 17-Sep-2017 12:52
Send private message

RunningMan:

 

Having links in those emails is just setting the customer up for a fail later. It doesn't matter what the link is - you subconsciously trust it because it wasn't a problem last time you clicked on a link in a bank email.

 

 

Absolutely 100% correct. They're training their customers to click on links inside emails purporting to be from their bank. It's just crazy.


 
 
 
 


2132 posts

Uber Geek


  # 1867559 17-Sep-2017 16:30
3 people support this post
Send private message

michaelmurfy: Not really. It is directing you to an easy to verify url (eg: https://westpac.co.nz)

Wow, that's a lot of faith in the average person... I've got no IT training, but I've helped my fair share of ordinary people with computer and internet trouble. Assuming people will verify a url is very optimistic.
I'd argue that a significant portion of users don't know what the url is (no matter what you call it), or where to look for it.

I believe that the majority of IT people seriously overestimate the average user, which then leads to unrealistic expectations of the user.

Links in advertising emails are one thing (I still think it's asking for trouble), but in this case the bank is specifically asking someone to login to internet banking and providing a link to achieve that. I think that's flat out irresponsible.




Location: Dunedin

 


2132 posts

Uber Geek


  # 1867565 17-Sep-2017 16:39
2 people support this post
Send private message

michaelmurfy: https://westpac.co.nz/termdeposits

This link is a prime example of why people don't/can't verify url's. It redirects to https://westpac.co.nz/investment-kiwisaver/term-investments/term-deposit/. That's a significant alteration.

Generally speaking, people don't understand url's and most don't want to. Most people would be happy if the bank name appears somewhere in the address.




Location: Dunedin

 


3885 posts

Uber Geek

Subscriber

  # 1867723 18-Sep-2017 00:57
One person supports this post

And how many people would know that you can hover over a link to check that say www.internetbankingsite.co.nz actually goes to that site. Instead of going to pilshingwebsite.com And if you are using a mobile or a tablet, then it is much harder to check where links point to before clicking on them.






Create new topic



Twitter and LinkedIn »



Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:





News »

Microsoft launches first Experience Center worldwide for Asia Pacific in Singapore
Posted 13-Nov-2019 13:08


Disney+ comes to LG Smart TVs
Posted 13-Nov-2019 12:55


Spark launches new wireless broadband "Unplan Metro"
Posted 11-Nov-2019 08:19


Malwarebytes overhauls flagship product with new UI, faster engine and lighter footprint
Posted 6-Nov-2019 11:48


CarbonClick launches into Digital Marketplaces
Posted 6-Nov-2019 11:42


Kordia offers Microsoft Azure Peering Service
Posted 6-Nov-2019 11:41


Spark 5G live on Auckland Harbour for Emirates Team New Zealand
Posted 4-Nov-2019 17:30


BNZ and Vodafone partner to boost NZ Tech for SME
Posted 31-Oct-2019 17:14


Nokia 7.2 available in New Zealand
Posted 31-Oct-2019 16:24


2talk launches Microsoft Teams Direct Routing product
Posted 29-Oct-2019 10:35


New Breast Cancer Foundation app puts power in Kiwi women's hands
Posted 25-Oct-2019 16:13


OPPO Reno2 Series lands, alongside hybrid noise-cancelling Wireless Headphones
Posted 24-Oct-2019 15:32


Waikato Data Scientists awarded $13 million from the Government
Posted 24-Oct-2019 15:27


D-Link launches Wave 2 Unified Access Points
Posted 24-Oct-2019 15:07


LG Electronics begins distributing the G8X THINQ
Posted 24-Oct-2019 10:58



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.