About 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question. I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to us…
HTTPS on Your Landing Page Is Important
91–100 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#92Earlier quoted context omitted.
What is the business reasoning behind this kind of domain name silliness?
I assume one team is responsible for the home page, and another team is responsible for the banking portal, and they can't be bothered to coordinate with each other.
One day S&M will catch up and have a fit at the fragmented "front face" - quite right too. To be honest the board should also give a shit about their org's outward appearance.
Bit of a fail all 'round, really.
Re: HTTPS on Your Landing Page Is Important
#93Earlier quoted context omitted.
Why is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling…
Words are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/secur...
Re: HTTPS on Your Landing Page Is Important
#94Maybe someday browsers won't accept http connections by default (except for a few domaines defined for test purpose, or for some specific tld like .local) Only then we can have 100% of the web encrypted.
At that point, will we start seeing attackers targeting DNS instead?
Re: HTTPS on Your Landing Page Is Important
#95Earlier quoted context omitted.
The people doing random things with fake .dev domains were going to get bit in the ass one way or another. You can't just make up your own domain and hope no one ever does anything conflicting with it.
> You can't just make up your own domain and hope no one ever does anything conflicting with it. Actually you can! You just need to use one reserved for that purpose: > In 1999, the Internet Engineering Task Force reserved the DNS labels example, invalid, localhost, and test so that they may not be installed into the root zone of the Domain Name System. https://en.wikipedia.org/wiki/.test
Re: HTTPS on Your Landing Page Is Important
#96Why not check the domainname registration first? See below.
But the author is not highlighting HTTPS "validation".
He is highlighting HTTPS encryption. Protection against tampering with traffic.
Domain Name: nwolb.com
Registry Domain ID: 9074606_DOMAIN_COM-VRSN
Registrar WHOIS Server: whois.corporatedomains.com
Registrar URL: www.cscprotectsbrands.com
Updated Date: 2017-09-15T14:16:24Z
Creation Date: 1999-08-13T15:18:25Z
Registrar Registration Expiration Date: 2019-08-13T15:18:12Z
Registrar: CSC CORPORATE DOMAINS, INC.
Registrar IANA ID: 299
Registrar Abuse Contact Email: domainabuse@cscglobal.com
Registrar Abuse Contact Phone: +1.8887802723
Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: Domain Manager
Registrant Organization: National Westminster Bank plc
Registrant Street: 135 Bishopsgate
Registrant City: London
Registrant State/Province: ENG
Registrant Postal Code: EC2M 3UR
Registrant Country: GB
Registrant Phone: +44.1316260002
Registrant Phone Ext:
Registrant Fax: +44.1315239568
Registrant Fax Ext:
Registrant Email: domains@rbs.co.uk
Registry Admin ID:
Admin Name: Domain Name Manager
Admin Organization: The Royal Bank of Scotland Group Plc
Admin Street: Global Network Services
Admin City: Edinburgh
Admin State/Province: SCT
Admin Postal Code: EH12 1HQ
Admin Country: GB
Admin Phone: +44.1316260002
Admin Phone Ext:
Admin Fax: +44.1315239568
Admin Fax Ext:
Admin Email: domains@rbs.co.uk
Registry Tech ID:
Tech Name: DNS Administrator
Tech Organization: CSC Corporate Domains, Inc.
Tech Street: 251 Little Falls Drive
Tech City: Wilmington
Tech State/Province: DE
Tech Postal Code: 19808
Tech Country: US
Tech Phone: +1.3026365400
Tech Phone Ext:
Tech Fax: +1.302636545
Tech Fax Ext:
Tech Email: dns-admin@cscglobal.com
Name Server: dns1.cscdns.net
Name Server: dns2.cscdns.net
DNSSEC: unsignedRe: HTTPS on Your Landing Page Is Important
#97Yeah, but what does "messing with traffic" mean exactly?
Does it mean sniffing?
If it does not mean sniffing then please stop reading here.
-------------------
Assuming the user is using DNS over UDP, as most are, what if "someone" who is sniffing the network modifies one of DNS packets destined for the user?Assume HTTPS and DNSSEC, just for fun.
Will the user be able to reach the website and log in?
[ ] Yes [ ] No
What do you think?
Re: HTTPS on Your Landing Page Is Important
#98Another lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft…
I was looking up details of the new Microsoft Surface recently, so hit the top link in a google search which was (supposedly) on Microsoft.com It wouldn’t load because Facebook.com was blocked and apparently they were doing a full redirect via fb. Crazy.
Re: HTTPS on Your Landing Page Is Important
#99That edit, about NatWest buying up the example domain to "fix" the problem, gave me real good laugh. It's interesting how simple mindedness can be so unexpectedly expected.
Actually that is a smart thing to do in it's own right, as long as they quickly move to https.
Re: HTTPS on Your Landing Page Is Important
#100Earlier quoted context omitted.
The important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.
The problem is that for all of the stereotypes to the contrary, tech is really full of people who worry, "Am I wrong? Am I the idiot?" Banks clearly don't attract the same kind of person, with the same intellectual gifts and challenges. Your advice is great, but it's probably already being taken to a fault by people like Troy Hunt, and people like the goober on the other end of the line think Dunning-Kruger is a bran…
Oh bollocks, that's me undone. Err without Googling and being British and given where I am and a few other things, I'm going to go for ... ... firearm?
Simplistic analysis by me: Well it can't likely be a Champagne (French). Dunning (English), Kruger (German with options).
OK Goo ... https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect - hmmm 8)