Financial services should employ a second JS-based PKI layer. BofA has no excuse.
"... log into the BofA website using the AccountID of "barry123457". While this transaction went over SSL, you can see clearly that sslsplit was able to intercept it. AS you can see, in the middle of the post information is the string "barry123457".