<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Silly Security Archives - Brandon Checketts</title>
	<atom:link href="https://www.brandonchecketts.com/archives/category/silly-security/feed" rel="self" type="application/rss+xml" />
	<link>https://www.brandonchecketts.com/archives/category/silly-security</link>
	<description>Web Programming, Linux System Administation, and Entrepreneurship in Athens Georgia</description>
	<lastBuildDate>Tue, 26 Apr 2022 19:25:07 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>
	<item>
		<title>Silly Security: TreasuryDirect.gov is the worst website ever</title>
		<link>https://www.brandonchecketts.com/archives/silly-security-treasurydirect-gov-is-the-worst-website-ever</link>
					<comments>https://www.brandonchecketts.com/archives/silly-security-treasurydirect-gov-is-the-worst-website-ever#comments</comments>
		
		<dc:creator><![CDATA[Brandon]]></dc:creator>
		<pubDate>Tue, 26 Apr 2022 19:25:07 +0000</pubDate>
				<category><![CDATA[Silly Security]]></category>
		<guid isPermaLink="false">https://www.brandonchecketts.com/?p=979</guid>

					<description><![CDATA[<p>I saw some content today about savings bonds having a great interest rate. So I tried to sign up. I didn&#8217;t know I was going to waste an hour to simply create an account. This has to be the worst website I&#8217;ve ever seen. Somewhere in the middle of the process, after entering a fantastic [&#8230;]</p>
<p>The post <a href="https://www.brandonchecketts.com/archives/silly-security-treasurydirect-gov-is-the-worst-website-ever">Silly Security: TreasuryDirect.gov is the worst website ever</a> appeared first on <a href="https://www.brandonchecketts.com">Brandon Checketts</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>I saw some content today about savings bonds having a great interest rate. So I tried to sign up. I didn&#8217;t know I was going to waste an hour to simply create an account. This has to be the worst website I&#8217;ve ever seen.</p>
<p>Somewhere in the middle of the process, after entering a fantastic password generated by my password manager, to log back into the site, I was presented with this virtual keyboard. You are forced to enter your password using the virtual keyboard by clicking on the keys.  Entering 40 random characters by clicking on the image is SUPER TEDIOUS.</p>
<p><img fetchpriority="high" decoding="async" src="https://www.brandonchecketts.com/wp-content/uploads/2022/04/treasurydirect-virtual-keyboard-required.png" alt="" width="605" height="351" class="alignnone size-full wp-image-980" srcset="https://www.brandonchecketts.com/wp-content/uploads/2022/04/treasurydirect-virtual-keyboard-required.png 605w, https://www.brandonchecketts.com/wp-content/uploads/2022/04/treasurydirect-virtual-keyboard-required-300x174.png 300w" sizes="(max-width: 605px) 100vw, 605px" /></p>
<p>Not to mention, it took me about 10 attempts to enter the password correctly. I didn&#8217;t notice it until getting extremely frustrated, but clicking a button on the virtual keyboard will sometimes double-click the character.</p>
<p>After getting into the site, any attempt to navigate using the browsers forward/back buttons will immediately log you out.  As will an accidental double-click on any of the navigation.</p>
<p>It&#8217;s a good thing they have a monopoly on savings bonds, because nobody would try to use this and stay sane!</p>
<p>The post <a href="https://www.brandonchecketts.com/archives/silly-security-treasurydirect-gov-is-the-worst-website-ever">Silly Security: TreasuryDirect.gov is the worst website ever</a> appeared first on <a href="https://www.brandonchecketts.com">Brandon Checketts</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.brandonchecketts.com/archives/silly-security-treasurydirect-gov-is-the-worst-website-ever/feed</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title>Silly Security: Don&#8217;t Show Me The Secret, Then Confirm I Have It!</title>
		<link>https://www.brandonchecketts.com/archives/silly-security-dont-show-me-the-secret-then-confirm-i-have-it</link>
					<comments>https://www.brandonchecketts.com/archives/silly-security-dont-show-me-the-secret-then-confirm-i-have-it#respond</comments>
		
		<dc:creator><![CDATA[Brandon]]></dc:creator>
		<pubDate>Wed, 13 Apr 2022 13:50:04 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Silly Security]]></category>
		<guid isPermaLink="false">https://www.brandonchecketts.com/?p=967</guid>

					<description><![CDATA[<p>I just received a replacement credit card from Health Equity because my previous card is expiring. Their validation screens made me laugh. The first screen shows the card you are replacing, and includes the last four digits of the card. &#160; Then the following screen asks for the last four digits of the card number [&#8230;]</p>
<p>The post <a href="https://www.brandonchecketts.com/archives/silly-security-dont-show-me-the-secret-then-confirm-i-have-it">Silly Security: Don&#8217;t Show Me The Secret, Then Confirm I Have It!</a> appeared first on <a href="https://www.brandonchecketts.com">Brandon Checketts</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>I just received a replacement credit card from <a href="https://www.healthequity.com/">Health Equity</a> because my previous card is expiring. Their validation screens made me laugh.</p>
<p>The first screen shows the card you are replacing, and includes the last four digits of the card.</p>
<p><img decoding="async" class="alignnone size-full wp-image-970" src="https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-1.png" alt="" width="910" height="386" srcset="https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-1.png 910w, https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-1-300x127.png 300w, https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-1-768x326.png 768w" sizes="(max-width: 910px) 100vw, 910px" /></p>
<p>&nbsp;<br />
Then the following screen asks for the last four digits of the card number &#8220;In order to verify possession&#8221;.</p>
<p><img decoding="async" class="alignnone size-full wp-image-973" src="https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-2.png" alt="" width="948" height="305" srcset="https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-2.png 948w, https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-2-300x97.png 300w, https://www.brandonchecketts.com/wp-content/uploads/2022/04/health-equity-replace-card-2-768x247.png 768w" sizes="(max-width: 948px) 100vw, 948px" /></p>
<p>You probably shouldn&#8217;t tell me the last four digits before asking me to confirm that I have the card.</p>
<p>The post <a href="https://www.brandonchecketts.com/archives/silly-security-dont-show-me-the-secret-then-confirm-i-have-it">Silly Security: Don&#8217;t Show Me The Secret, Then Confirm I Have It!</a> appeared first on <a href="https://www.brandonchecketts.com">Brandon Checketts</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.brandonchecketts.com/archives/silly-security-dont-show-me-the-secret-then-confirm-i-have-it/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
