Live data from Hacker News

Bank harrasses user because he tweeted screenshot of their SSL certificate

ebalaskas.gr

21–30 of 74 posts

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#21
post #13

Site seems to be down.

Tad ironic seeing as one of the last sentences in the blog post is: "Hope this blog post stays up for some time." I hope the site is not down because his domain/hosting got "convinced" by the legal department of the bank.

It's more than ironic. I'm actually concerned about this guy. It appears he might be in the cross-hairs of some individuals who are willing to leverage whatever they have at their disposal to shut him up and maybe make an example out of him.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#23
post #13

Site seems to be down.

Tad ironic seeing as one of the last sentences in the blog post is: "Hope this blog post stays up for some time." I hope the site is not down because his domain/hosting got "convinced" by the legal department of the bank.

This is an excellent example of why censorship resistant name resolution and hosting are so necessary. With projects like Namecoin and Freenet, this wouldn't be a problem.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#24

> Firefox suggests some security concerns in the firefox console on both sites. Especially about how weak is sha1 algorithm. Both sites have a 2048 public cert, the one use TLS1.2 but the other TLS1.0 and one of them have a 128bit private key size. You all understand that from a security point of view, these things arent best practices. Especially if you are a bank ! 128 bits for symmetric key ciphers is actually fin…

It's a "128 bits private key", what means it's assymetric. I fully expect it to be an RSA key, but even for ECC that's at least half the size of something that could be considered secure.

I do beleive the author misspoke here. They already said 2048 bit public key.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#25
post #16

I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue. Freedom of speech refers to government restrictions on limiting the right to voice your opinion. The government wasn't involved and he didn't legally have to remove the tweet (but I would have removed the tweet as well if it threatened my job). I totally support th…

> I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue.

I don't agree. In US terms, "Freedom of Speech" appears to be framed only in terms of the rights of someone relative to the government.

But in the UK, we don't have a first amendment, or even a written constitution. I would find it absolutely normal for someone to discuss freedom of speech issues about wider things than simply government overreach. In fact, the opposite is just as likely to be true: freedom of speech can be curtailed by things like private injunctions or the lack of space where it's safe to speak, which may be occuring due to lack of government action or regulation.

Freedom of Speech is a phrase that I've always thought has a wider application than it appears limited to in the US, where it seems mixed up with a lot of politics that don't appear anywhere else.

Anyway, just my opinion from the UK. I think this is very much something that can be discussed in terms of freedom of speech in the wider (non-US) sense, due to the power disparity of the actors being used (if true) to quash speech that would otherwise be freely available - and, given Greece is in Europe, I believe the author is right to frame it in those terms.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#26
post #16

I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue. Freedom of speech refers to government restrictions on limiting the right to voice your opinion. The government wasn't involved and he didn't legally have to remove the tweet (but I would have removed the tweet as well if it threatened my job). I totally support th…

It's worth noting, particularly given where the story occurred, that this is a US-centric take on what "Freedom of Speech" means, and really doesn't generalize well.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#27
post #15

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

https://twitter.com/ansimionescu/status/576425676036780032 I work in security/privacy/premium snake oil trade. Bank security (and software in general) is _usually_ a joke. The main reason for not fucking with a bank is the same why you wouldn't fuck with casinos, or the mob.

> you wouldn't fuck with casinos, or the mob.

Why wouldn't I, from the other side of the world, from the wifi connection of a coffee shop on the other side of town, bounced through a couple VPNs? It's one thing if I have to walk inside the casino, but the internet isn't like that.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#28

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

Eurobank: Score: F! https://www.ssllabs.com/ssltest/analyze.html?d=eurobank.gr twitter:https://twitter.com/Eurobank_Group

This one is interesting, as it shows IIS 5.0 (Win2000 SChannel) affected by POODLE TLS.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#29
A friend went through the Swedish banks and ranked them (post in Swedish https://friendlybit.com/security/hur-sakra-ar-svenska-banker... and Google translate https://translate.google.com/translate?sl=auto&tl=en&js=y&pr... )

The response he got was the banks starting fixed their problems. He had one group of banks that he classified as you should stay away from. All those banks fixed things so they are not longer in that category

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#30
post #15

Earlier quoted context omitted.

https://twitter.com/ansimionescu/status/576425676036780032 I work in security/privacy/premium snake oil trade. Bank security (and software in general) is _usually_ a joke. The main reason for not fucking with a bank is the same why you wouldn't fuck with casinos, or the mob.

> you wouldn't fuck with casinos, or the mob. Why wouldn't I, from the other side of the world, from the wifi connection of a coffee shop on the other side of town, bounced through a couple VPNs? It's one thing if I have to walk inside the casino, but the internet isn't like that.

No, that that bank on the other side of the world is likely insured by a company in the US. The global financial system is intricately linked, and the bankers and insurance companies effectively run the global economy. Given that, do you think it's really a huge stretch to think that three letter agencies from the US - the ones with documented capabilities to de-anonymize your VPNs if your OpSec is even a little sloppy - might get involved? Jurisdiction wouldn't be an issue if the bank asked them for help.

There are many ways to ensure security: one is technical, and another is investigative. The amount of resources a bank can bring to bear on you if you steal money from them is immense - IMO it's just best not to mess with that shit. It may have been true at one time that you could outsmart the banks and get away with it, but there are just too many smart people watching anymore.

Post reply on HN