false security based on dim presumption
If ING really sat down in a quiet corner for thirteen milliseconds they should surely understand just how poor their implementation must be: "because it was requested by the browser, it was invoked by the user"
A security philosophy that seems to be based on the notion that all client software is flawless!


