Financial services should employ a second JS-based PKI layer. BofA has no excuse.
"... log into the BofA website using the AccountID of "barry123457". While this transaction went over SSL, you can see clearly that sslsplit was able to intercept it. AS you can see, in the middle of the post information is the string "barry123457".
You realize that anything the real BofA site adds to increase security can be removed by the proxy? Once your CA trust-store is compromised there really is no way to do anything secure without asking the user to use another channel to verify things.