Do they? My banks did that years ago, and they also stopped doing it years ago.
Do they? My banks did that years ago, and they also stopped doing it years ago.
>Of the 63 participants whose responses to prior tasks had been verified, we were able to corroborate 60 participants’ responses to the removal of their site-authentication images. 58 of the 60 participants (97%) entered their passwords, de-spite the removal of the site-authentication image
See https://security.stackexchange.com/a/19801 which summarises https://sites.google.com/site/ianfischercv/emperor.pdf
In either case, the "correct profile picture" would not load.
Okta still includes this "feature" by default, and is among the reasons I will never trust Okta or any client of theirs.
We already know how to actually solve this problem. WebAuthn.
Why is that a concern? You try to log in on a phishing site. The phishing site tries to log in as you at your bank's actual website. Your bank sends the phishing site your picture. The phishing site displays your picture to you.