HTTPS != Security

SSL/HTTPS does not necessarily mean security!

Ax Sharma
3 min readOct 14, 2018
onlineaccessplus.com website screenshot

Look at the screenshot above. Is it a legitimate banking website? A phishing website?

More likely than not it looks like a phishing webpage. Notice the interface — no indication of the banking institution whatsoever. But… the URL — it’s https!

For the record, this is in fact a legitimate website used by TD Bank and its international subsidiaries.

I mean just look at their choice of domain names! Who came up with these?!

If I was to design a Natural Language Processing (NLP) phishing algorithm, probably all of these would be flagged as phishing.

--

--

Ax Sharma
Ax Sharma

Written by Ax Sharma

Security Researcher | Tech Columnist | https://hey.ax

No responses yet