Why is the banking server trusting the client? Thats criminally incompetent security. If your website gets hacked because a client had "root" whose fault is it?
Because the unknowing user has entered their auth credentials?
Because the unknowing user has entered their auth credentials?