Bank's own developers a much bigger problem than browsers Banks will imminently be under pressure to eliminate opportunities for cross site scripting from their sites, following a demonstration that several very widely used banking web sites could act as conduits for fraudsters to solicit and steal their customers' account information. Amongst the vulnerable sites are MasterCard and Barclays, which ironically each recently announced initiatives to combat phishing, apparently without ensuring that their own houses were in order. [via Netcraft]


