Live data from Hacker News

Bank harrasses user because he tweeted screenshot of their SSL certificate

ebalaskas.gr

31–40 of 74 posts

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#31

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info.

Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-25... - web browsers have already started turning it off.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#32

> Firefox suggests some security concerns in the firefox console on both sites. Especially about how weak is sha1 algorithm. Both sites have a 2048 public cert, the one use TLS1.2 but the other TLS1.0 and one of them have a 128bit private key size. You all understand that from a security point of view, these things arent best practices. Especially if you are a bank ! 128 bits for symmetric key ciphers is actually fin…

Yea, more important is the RC4 at the top of the list with nbg.gr.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#33

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

Yea, I hope PCI DSS clarifies this matter soon.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#34

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

Yeah. Worse, if RC4 being enabled was the only problem, it would be bad, but somewhat reasonable, as RC4 only recently became known to be weak. But POODLE? FREAK? TSL1.0? All the other crap? Absolutely incredible.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#36
post #30

Earlier quoted context omitted.

> you wouldn't fuck with casinos, or the mob. Why wouldn't I, from the other side of the world, from the wifi connection of a coffee shop on the other side of town, bounced through a couple VPNs? It's one thing if I have to walk inside the casino, but the internet isn't like that.

No, that that bank on the other side of the world is likely insured by a company in the US. The global financial system is intricately linked, and the bankers and insurance companies effectively run the global economy. Given that, do you think it's really a huge stretch to think that three letter agencies from the US - the ones with documented capabilities to de-anonymize your VPNs if your OpSec is even a little slop…

My other personal analysis, from looking at banks in a third world county, is that you can't easily get away with enough to make it worthwhile. Sure, it'd probably be trivial to get money moved around inside the bank's own system. But getting it out from there seems to involve actual competent actors that aren't third world. Getting it out directly from the bank also seemed unlikely, because they manually check things for such low amounts.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#37
Along the same line, there are currently around 4,000 sites in Alexa's top 1 million that only support RC4. Nothing else.

Some of these sites have large user bases too, and it's making it hard to disable RC4 in Firefox. https://bugzilla.mozilla.org/show_bug.cgi?id=1138101

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#38
post #35

Earlier quoted context omitted.

National Bank of Greece ( https://www.nbg.gr/en , @ibanknbg)

That's incorrect: > The first bank contacted almost immediately with me and I respect National Bank of Greece for that.

What's incorrect?

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#39
post #18

Which bank was it?

National Bank of Greece ( https://www.nbg.gr/en , @ibanknbg)

Actually, to quote the article:

The first bank contacted almost immediately with me and I respect National Bank of Greece for that.

The second bank took another approach.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#40
post #35

Earlier quoted context omitted.

That's incorrect: > The first bank contacted almost immediately with me and I respect National Bank of Greece for that.

What's incorrect?

If you read the article, the National Bank of Greece is not the one that harassed the author/their employer, the unnamed "second bank" did.
Post reply on HN