Live data from Hacker News

HTTPS on Your Landing Page Is Important

troyhunt.com

91–100 of 307 posts

Re: HTTPS on Your Landing Page Is Important

#91
post #65

About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question. I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to us…

Reminiscent of Amex's password policy (at least what it was a few years ago): can't use punctuation in your password, because those keys are less frequently used, and using them frequently in passwords will cause visible wear on the keys, indicating to an attacker with physical access to your keyboard which punctuation characters are in your password. Trying so hard, but failing so badly.

Re: HTTPS on Your Landing Page Is Important

#92

Earlier quoted context omitted.

What is the business reasoning behind this kind of domain name silliness?

I assume one team is responsible for the home page, and another team is responsible for the banking portal, and they can't be bothered to coordinate with each other.

I agree. There is no technical reason behind this sort of bollocks.

One day S&M will catch up and have a fit at the fragmented "front face" - quite right too. To be honest the board should also give a shit about their org's outward appearance.

Bit of a fail all 'round, really.

Re: HTTPS on Your Landing Page Is Important

#93

Earlier quoted context omitted.

Why is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling…

Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...

Perhaps the reverse would be better. If a site doesn't use HTTPS, call it unsecured.

Re: HTTPS on Your Landing Page Is Important

#94

Maybe someday browsers won't accept http connections by default (except for a few domaines defined for test purpose, or for some specific tld like .local) Only then we can have 100% of the web encrypted.

At that point, will we start seeing attackers targeting DNS instead?

You need to get to global DNS to get a valid cert. When certificate transparency logs become mandatory, that case will be detectable though not preventable.

Re: HTTPS on Your Landing Page Is Important

#95
post #70
post #55

Earlier quoted context omitted.

The people doing random things with fake .dev domains were going to get bit in the ass one way or another. You can't just make up your own domain and hope no one ever does anything conflicting with it.

> You can't just make up your own domain and hope no one ever does anything conflicting with it. Actually you can! You just need to use one reserved for that purpose: > In 1999, the Internet Engineering Task Force reserved the DNS labels example, invalid, localhost, and test so that they may not be installed into the root zone of the Domain Name System. https://en.wikipedia.org/wiki/.test

Sure, but you should NEVER use a domain that isn’t delegated to you or explicitly reserved by the IANA for local purposes. Plenty of people used .int as well which is now a gTLD, you can’t complain about a name you don’t own breaking down the line.

Re: HTTPS on Your Landing Page Is Important

#96
SSL certs are based primarily on domainname registrations.

Why not check the domainname registration first? See below.

But the author is not highlighting HTTPS "validation".

He is highlighting HTTPS encryption. Protection against tampering with traffic.

   Domain Name: nwolb.com
   Registry Domain ID: 9074606_DOMAIN_COM-VRSN
   Registrar WHOIS Server: whois.corporatedomains.com
   Registrar URL: www.cscprotectsbrands.com
   Updated Date: 2017-09-15T14:16:24Z
   Creation Date: 1999-08-13T15:18:25Z
   Registrar Registration Expiration Date: 2019-08-13T15:18:12Z
   Registrar: CSC CORPORATE DOMAINS, INC.
   Registrar IANA ID: 299
   Registrar Abuse Contact Email: domainabuse@cscglobal.com
   Registrar Abuse Contact Phone: +1.8887802723
   Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
   Registry Registrant ID: 
   Registrant Name: Domain Manager
   Registrant Organization: National Westminster Bank plc
   Registrant Street: 135 Bishopsgate
   Registrant City: London
   Registrant State/Province: ENG
   Registrant Postal Code: EC2M 3UR
   Registrant Country: GB
   Registrant Phone: +44.1316260002
   Registrant Phone Ext: 
   Registrant Fax: +44.1315239568
   Registrant Fax Ext: 
   Registrant Email: domains@rbs.co.uk
   Registry Admin ID: 
   Admin Name: Domain Name Manager
   Admin Organization: The Royal Bank of Scotland Group Plc
   Admin Street: Global Network Services
   Admin City: Edinburgh
   Admin State/Province: SCT
   Admin Postal Code: EH12 1HQ
   Admin Country: GB
   Admin Phone: +44.1316260002
   Admin Phone Ext: 
   Admin Fax: +44.1315239568
   Admin Fax Ext: 
   Admin Email: domains@rbs.co.uk
   Registry Tech ID: 
   Tech Name: DNS Administrator
   Tech Organization: CSC Corporate Domains, Inc.
   Tech Street: 251 Little Falls Drive
   Tech City: Wilmington
   Tech State/Province: DE
   Tech Postal Code: 19808
   Tech Country: US
   Tech Phone: +1.3026365400
   Tech Phone Ext: 
   Tech Fax: +1.302636545
   Tech Fax Ext: 
   Tech Email: dns-admin@cscglobal.com
   Name Server: dns1.cscdns.net
   Name Server: dns2.cscdns.net
   DNSSEC: unsigned

Re: HTTPS on Your Landing Page Is Important

#97
"If someone is messing with traffic then they can modify non-secure requests. Yeah?"

Yeah, but what does "messing with traffic" mean exactly?

Does it mean sniffing?

If it does not mean sniffing then please stop reading here.

            -------------------
Assuming the user is using DNS over UDP, as most are, what if "someone" who is sniffing the network modifies one of DNS packets destined for the user?

Assume HTTPS and DNSSEC, just for fun.

Will the user be able to reach the website and log in?

[ ] Yes [ ] No

What do you think?

Re: HTTPS on Your Landing Page Is Important

#98
post #78
post #42

Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…

I was looking up details of the new Microsoft Surface recently, so hit the top link in a google search which was (supposedly) on Microsoft.com It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.

You didn't click on a search result, you clicked on an advertisement.

Re: HTTPS on Your Landing Page Is Important

#99

That edit, about NatWest buying up the example domain to "fix" the problem, gave me real good laugh. It's interesting how simple mindedness can be so unexpectedly expected.

Actually that is a smart thing to do in it's own right, as long as they quickly move to https.

Not even predicated on HTTPS; owning more domains helps combat some obvious forms of fraud. Though, really, I agree that HTTPS is more important.

Re: HTTPS on Your Landing Page Is Important

#100
post #39
post #24

Earlier quoted context omitted.

The important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.

The problem is that for all of the stereotypes to the contrary, tech is really full of people who worry, "Am I wrong? Am I the idiot?" Banks clearly don't attract the same kind of person, with the same intellectual gifts and challenges. Your advice is great, but it's probably already being taken to a fault by people like Troy Hunt, and people like the goober on the other end of the line think Dunning-Kruger is a bran…

"think Dunning-Kruger is a brand of champagne."

Oh bollocks, that's me undone. Err without Googling and being British and given where I am and a few other things, I'm going to go for ... ... firearm?

Simplistic analysis by me: Well it can't likely be a Champagne (French). Dunning (English), Kruger (German with options).

OK Goo ... https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect - hmmm 8)

Post reply on HN