Bank harrasses user because he tweeted screenshot of their SSL certificate
1–10 of 74 posts
Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#2Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#3Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#4Marketing opportunity for other banks to jump on the bandwagon and share there public keys on social media.
Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#5Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#6Site seems to be down.
http://webcache.googleusercontent.com/search?q=cache:BJedQ1n...
Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#7[deleted]
Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#8https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr
their twitter account is: https://twitter.com/ibanknbg
EDIT: The most effective outreach will be friendly and respectful, if anyone chooses to do this. Also, all the other major greek banks score poorly:
Piraeus Bank Score: F! https://www.ssllabs.com/ssltest/analyze.html?d=www.piraeusba... twitter:https://twitter.com/skepsouprasina
Alpha Bank: B https://www.ssllabs.com/ssltest/analyze.html?d=www.alpha.gr&... twitter: https://twitter.com/alpha_bank
Eurobank: Score: F! https://www.ssllabs.com/ssltest/analyze.html?d=eurobank.gr twitter:https://twitter.com/Eurobank_Group
Re: Bank harrasses user because he tweeted screenshot of their SSL certificate
#9128 bits for symmetric key ciphers is actually fine. Especially with AES.
TLS1.0 and SHA1 certificates? I'd expect better.
> The second bank has also a cross site javascript script and that’s for sure not a best practice. Again that’s not a security hole. They just pull a javascript from their official web page (although a different url/domain from their web banking).
Yay, watering hole attack vectors.