Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


k1w1k1d

741 posts

Ultimate Geek


#223175 17-Sep-2017 09:38
Send private message

 

 

 

 

"Westpac NZ will never email you a link to Westpac Online Banking, or ask you for your security details or passwords by email."

 

 

 

 

 

The above line appears on the top of the Westpac email I received this morning advising that my online credit card statement is available.

 

The thing I find interesting is that there are nine links in the email to Westpac websites???

 

"You can view, download and print your statements anytime by going to westpac.co.nz and logging into Westpac One."


Create new topic
michaelmurfy
/dev/null
9635 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #1867455 17-Sep-2017 09:51
Send private message

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.

 

Many banks do this.





andrewNZ
2326 posts

Uber Geek


  #1867457 17-Sep-2017 10:01
Send private message

michaelmurfy:

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.


Many banks do this.


Doesn't that contradict the basic rules though? Surely routinely putting links into emails leading to banks websites is just teaching people it's ok to use email links to the banks websites.

Seems pretty foolish to me.
People are pretty stupid, and habits are created easily.




Electrician.

 

Location: Dunedin

 

 


 
 
 
 


Behodar
7171 posts

Uber Geek

Trusted
Lifetime subscriber

  #1867459 17-Sep-2017 10:04
Send private message

michaelmurfy:

 

That is not directly linking to the internet banking login page - it is directing you to their website for you to click the internet banking link to login.

 

Many banks do this.

 

 

I don't see how linking to the home page is any better.

 

The reason for not directly linking to the login page is presumably to stop people from being "conditioned" to click on links without checking them (to avoid phishing). But by linking to the home page, it doesn't actually solve the problem - the phishers will then just need to make an additional fake page that looks like Westpac's home page, complete with its own "Log In" link that goes to the actual phishing page.

 

It's a little more work for the phishers, but doesn't seem to be any more secure. Or am I missing something?

 

Edit: What Andrew said :)


k1w1k1d

741 posts

Ultimate Geek


  #1867461 17-Sep-2017 10:09
Send private message

Clicking on the link in the bottom line of my post takes you to the page with the login button.

 

Isn't this how phising works?

 

You receive an email that looks to be official from your bank, PayPal, etc which has a link. You click on the link and a page opens asking you to log in.........

 

 

 

Must learn to type faster!


michaelmurfy
/dev/null
9635 posts

Uber Geek

Moderator
Trusted
Lifetime subscriber

  #1867467 17-Sep-2017 10:21
Send private message

andrewNZ:
Doesn't that contradict the basic rules though? Surely routinely putting links into emails leading to banks websites is just teaching people it's ok to use email links to the banks websites.

Seems pretty foolish to me.
People are pretty stupid, and habits are created easily.

 

Not really. It is directing you to an easy to verify url (eg: https://westpac.co.nz) instead of your internet banking page and also telling you to navigate to it and login. All phishing emails I have come across do not clone the complete homepage and instead attempt to take you to a phishing page which is simply the internet banking login.

 

Other links may include help pages etc - they're stating in the email they'll never directly link you to the internet banking login. While I partly agree with what you're saying if you got an email for lets say a special term deposit rate like this:

 

"As you're a special customer we have a special term deposit rate for you - head over to our website and click on investments then term deposits to find out more" it is easier for everyone to go "Go over to https://westpac.co.nz/termdeposits for more information".

 

Like you said - some people are pretty stupid...





RunningMan
6141 posts

Uber Geek


  #1867473 17-Sep-2017 10:41
Send private message

Having links in those emails is just setting the customer up for a fail later. It doesn't matter what the link is - you subconsciously trust it because it wasn't a problem last time you clicked on a link in a bank email.

 

For people to avoid phishing scams, they have to recognise (while distracted on other tasks) that the action being asked in the phishing email is not normal - if they are used to clicking links in banks emails, there is a higher probability of them clicking the link when a phishing email comes through.


cadman
1014 posts

Uber Geek
Inactive user


  #1867501 17-Sep-2017 12:52
Send private message

RunningMan:

 

Having links in those emails is just setting the customer up for a fail later. It doesn't matter what the link is - you subconsciously trust it because it wasn't a problem last time you clicked on a link in a bank email.

 

 

Absolutely 100% correct. They're training their customers to click on links inside emails purporting to be from their bank. It's just crazy.


 
 
 
 


andrewNZ
2326 posts

Uber Geek


  #1867559 17-Sep-2017 16:30
Send private message

michaelmurfy: Not really. It is directing you to an easy to verify url (eg: https://westpac.co.nz)

Wow, that's a lot of faith in the average person... I've got no IT training, but I've helped my fair share of ordinary people with computer and internet trouble. Assuming people will verify a url is very optimistic.
I'd argue that a significant portion of users don't know what the url is (no matter what you call it), or where to look for it.

I believe that the majority of IT people seriously overestimate the average user, which then leads to unrealistic expectations of the user.

Links in advertising emails are one thing (I still think it's asking for trouble), but in this case the bank is specifically asking someone to login to internet banking and providing a link to achieve that. I think that's flat out irresponsible.




Electrician.

 

Location: Dunedin

 

 


andrewNZ
2326 posts

Uber Geek


  #1867565 17-Sep-2017 16:39
Send private message

michaelmurfy: https://westpac.co.nz/termdeposits

This link is a prime example of why people don't/can't verify url's. It redirects to https://westpac.co.nz/investment-kiwisaver/term-investments/term-deposit/. That's a significant alteration.

Generally speaking, people don't understand url's and most don't want to. Most people would be happy if the bank name appears somewhere in the address.




Electrician.

 

Location: Dunedin

 

 


Aredwood
3885 posts

Uber Geek


  #1867723 18-Sep-2017 00:57

And how many people would know that you can hover over a link to check that say www.internetbankingsite.co.nz actually goes to that site. Instead of going to pilshingwebsite.com And if you are using a mobile or a tablet, then it is much harder to check where links point to before clicking on them.






Create new topic





News »

Huawei launches IdeaHub Pro in New Zealand
Posted 27-Oct-2020 16:41


Southland-based IT specialist providing virtual services worldwide
Posted 27-Oct-2020 15:55


NASA discovers water on sunlit surface of Moon
Posted 27-Oct-2020 08:30


Huawei introduces new features to Petal Search, Maps and Docs
Posted 26-Oct-2020 18:05


Nokia selected by NASA to build first ever cellular network on the Moon
Posted 21-Oct-2020 08:34


Nanoleaf enhances lighting line with launch of Triangles and Mini Triangles
Posted 17-Oct-2020 20:18


Synology unveils DS16211+
Posted 17-Oct-2020 20:12


Ingram Micro introduces FootfallCam to New Zealand channel
Posted 17-Oct-2020 20:06


Dropbox adopts Virtual First working policy
Posted 17-Oct-2020 19:47


OPPO announces Reno4 Series 5G line-up in NZ
Posted 16-Oct-2020 08:52


Microsoft Highway to a Hundred expands to Asia Pacific
Posted 14-Oct-2020 09:34


Spark turns on 5G in Auckland
Posted 14-Oct-2020 09:29


AMD Launches AMD Ryzen 5000 Series Desktop Processors
Posted 9-Oct-2020 10:13


Teletrac Navman launches integrated multi-camera solution for transport and logistics industry
Posted 8-Oct-2020 10:57


Farmside hits 10,000 RBI customers
Posted 7-Oct-2020 15:32









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.


Support Geekzone »

Our community of supporters help make Geekzone possible. Click the button below to join them.

Support Geezone on PressPatron



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.