6:42 am
September 30, 2017
9:33 am
January 12, 2019
.
The new 'Oaken Digital' has been up & running for a little over a week now. Most (including myself) were sent an email notification.
It didn't take long to discover a Security Flaw with their new platform. During the login process, Google Chrome's Auto-Fill is allowed to automatically provide your User Name. Needless to say ... I'm Not impressed ❗
The same thing happened when Hubert changed over to their new website last year. It took them over Three Months to fix it.
I can't believe stuff like this gets past their beta testing.
- Dean
" Live Long, Healthy ... And Prosper! "
9:46 am
December 20, 2016
Dean said
.......I can't believe stuff like this gets past their beta testing.Dean
I believe what we are seeing is financial institutions allowing their "new, improved, stylized" interfaces to be released without traditional beta testing and letting their clients act as unpaid beta testers.
The trail of these recent mis-steps so far include Canadian Tire Bank, Hubert, Oaken, Concentra (Wyth) and even Tandia.
Hope it doesn't take a security breach to shock these FI's into reality.
Stephen
11:16 am
October 27, 2013
12:17 pm
January 12, 2019
AltaRed said
What is wrong with auto population of User Name? I default to that where possible. It is password which is the critical element that has to be robust.
As part of the login process, asking for your User Name provides another layer of security. When Auto-fill (auto population) is allowed to provide your User Name, that eliminates a layer of security.
Auto-fill should 'Never' be allowed to provide answers to security questions. Except for the new Oaken Digital website, all of the FI websites I'm aware of, block Auto-fill during the login process.
- Dean
" Live Long, Healthy ... And Prosper! "
10:08 am
January 12, 2019
Dean said
.
The new 'Oaken Digital' has been up & running for a little over a week now. Most (including myself) were sent an email notification.It didn't take long to discover a Security Flaw with their new platform. During the login process, Google Chrome's Auto-Fill is allowed to automatically provide your User Name. Needless to say ... I'm Not impressed ❗
The same thing happened when Hubert changed over to their new website last year. It took them over Three Months to fix it.
I can't believe stuff like this gets past their beta testing.
Dean
Ten minutes after entering that ⬆ post I sent Oaken an email, expressing our concern with the sign-in security flaw on their new website.
To date (three days later) they Still haven't responded ❗
Go Figure
- Dean
" Live Long, Healthy ... And Prosper! "
10:23 am
October 27, 2013
Dean said
As part of the login process, asking for your User Name provides another layer of security. When Auto-fill (auto population) is allowed to provide your User Name, that eliminates a layer of security.
Auto-fill should 'Never' be allowed to provide answers to security questions. Except for the new Oaken Digital website, all of the FI websites I'm aware of, block Auto-fill during the login process.
Dean
Well, certainly not auto-fill. That wasn't my point. I often tick off the 'Remember Me' box so that User Name box remains filled via cookie contents. User Name is often one's email address with no alternative choice anyway. The key is having a bulletproof password.
10:39 am
April 6, 2013
Their web developers should be smart enough to mark the password fields with the appropriate autocomplete attribute, like "current-password", to indicate it is a password.
That way, the autocomplete feature in web browser knows and can treat the password field contents appropriately.
2:30 pm
January 12, 2019
Norman1 said
Their web developers should be smart enough to mark the password fields with the appropriate autocomplete attribute, like "current-password", to indicate it is a password.
That way, the autocomplete feature in web browser knows and can treat the password field contents appropriately.
Thanks for that ⬆ link, Norman. If I don't hear back from Oaken by Monday, I'll send a follow-up email to them, and I'll include that link.
And I agree ... their web developers should be smart enough to mark/protect security fields appropriately, but in this case they goofed and didn't.
This is just like last year when Hubert's new website was unveiled. It had this exact same security flaw ... and it took them over 3 months to fix it ❗
- Dean
" Live Long, Healthy ... And Prosper! "
10:56 am
January 12, 2019
Dean said
Thanks for that ⬆ link, Norman. If I don't hear back from Oaken by Monday, I'll send a follow-up email to them, and I'll include that link.
. . .
It's been Six days now since I sent that email to Oaken ... but Still no response ❗
I just finished sending a follow-up email to them, and I included the link Norman provided above in Post #8.
Here's hoping they have the courtesy to finally reply.
- Dean
" Live Long, Healthy ... And Prosper! "
1:36 pm
September 30, 2017
Come to think of it … I sent three emails to Oaken. The first one got an automatic reply right away, then followed by a staff reply the next day. The other two didn't even get the automatic reply! … Could be broken as well.
… or maybe Oaken, is there a spam folder? Can you check for mine there? Without online access, you totally shut me out
5:12 am
December 20, 2019
I am liking their rate comparison page, lots of great info
7:59 am
December 20, 2016
KamWest said
I am liking their rate comparison page, lots of great info.....
Illustrations of the lowest hanging fruit, designed to be largely self serving.
Wealth One information is inaccurate / outdated for example.
If one is serious about monitoring deposit rates, this Forum is a much better, current and reliable source combined with one's own links to the main FI players' websites.
Would you rely on the Chev dealer to tell you why you should not buy a Ford??
Stephen
8:15 am
November 7, 2014
11:41 am
November 18, 2017
11:59 am
October 21, 2013
6:45 pm
November 15, 2018
10:12 am
November 18, 2017
I spoke to Patrick at Wealth One's national phone line, and he was okay. I don't use E-mail or internet banking, so my service issues are mail and phone, which they are not very good at.
The gentleman who signed me up at the Vancouver/Richmond office was very helpful last year, but the national line did not back up what he promised. He seems to be MIA this year, though Richmond says he's still with them. It's very hard to get anyone now - leave a message and hope. And lots of oopsie hang-ups, too, both locally and nationally. If Oaken's rates and terms suit me, I will move.
RetirEd
RetirEd
6:57 am
September 30, 2017
9:59 am
November 18, 2017
I visited Oaken in their downtown Vancouver offices. Appointment required, but they at least exist and weren't dinky. Location is right on a SkyTrain line but parking nearby is around $9 an hour! There's free motorcycle parking not far but only a few stalls, so it's a crapshoot even on a rainy day. (Wealth One's Richmond BC office is far from where I live but parking's free. I never mind an opportunity to go for a ride!)
Contrary to what I was told on the phone, they do NOT provide free printed statements. On the other hand, they will provide them for $2 as opposed to Wealth One's $5! I wasn't going to pay Tangerine $2 monthly either, FWIW.
They were not very happy about non-on-line work but did provide printed forms and documents. Their terms & conditions were reasonable compared to the insanely invasive and probably illegal ones at W1, and their phone centre is staffed and the waits not long.
Without statements, I won't be using their savings account - it's not worth it for .05% over Peoples and a host of others (this may change) but their GIC rates are excellent. I wouldn't want to be moving money around on a regular basis without hard-copy records.
They say it will take about two weeks to set up my account, which is fine if there's another round of rate increases coming following the Bank of Canada announcement that they plan to move rates up early next year. That will allow me to buy a GIC.
So adieu Wealth One; if all goes through at Oaken, I'll be back under CDIC limits everywhere.
RetirEd
RetirEd
Please write your comments in the forum.