There are several banks that use non-SSL login pages. This does not mean they are sending your credentials in the clear, but the user has no way to tell if the login form is legit or spoofed. Alun Jones moves from the findings of Johannes Ullrich, chief research officer for the SANS Institute, to raise an alarm on this overlooked problem: how secure is the web form you are filling in?

Delicious
Digg
Reddit
Facebook
Yahoo
Netscape
StumbleUpon