Live data from Hacker News

Bank harrasses user because he tweeted screenshot of their SSL certificate

ebalaskas.gr

41–50 of 74 posts

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#41
post #13

Site seems to be down.

Tad ironic seeing as one of the last sentences in the blog post is: "Hope this blog post stays up for some time." I hope the site is not down because his domain/hosting got "convinced" by the legal department of the bank.

As a Greek, I find that rather unlikely, not only is this sort of censorship rare, but the government is too inefficient to get something done this quickly (or at all) even if they wanted to. I'm fairly sure this is just heavy load.

EDIT: Yeah, it's back up.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#42
post #40

Earlier quoted context omitted.

What's incorrect?

If you read the article, the National Bank of Greece is not the one that harassed the author/their employer, the unnamed "second bank" did.

Interesting - looks like you are correct. Could have sworn it was different when I first read it!

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#43
post #33

Earlier quoted context omitted.

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

Yea, I hope PCI DSS clarifies this matter soon.

For a long time I thought PCI DSS/NVD was the culprit for all RC4 on payment sites, but luckily this was solved, I see they updated the score on 03/12/2015: https://code.google.com/p/chromium/issues/detail?id=375342#c... https://code.google.com/p/chromium/issues/detail?id=375342#c...

I usually complain when some site uses RC4 and I can't access it, but unlike the OP I don't do that via twitter (one reason is that I don't even have an account there).

I've sent 2 emails regarding the use of ONLY RC4 on payment sites in my country, and although such emails aren't always acknowledged they did get fixed after I CC-ed their PCI auditors [1] :)

[1] which you can find publicly on Visa's site at 'PCI DSS validated Member Agent Weblisting' http://www.visaeurope.com/receiving-payments/security/downlo...

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#44
post #18

Which bank was it?

National Bank of Greece ( https://www.nbg.gr/en , @ibanknbg)

No, he writes that there were SSL related problems with two banks. The first one was the National Bank of Greece. They contacted him directly and were nice about it.

The second bank was the one that showed this appalling behaviour and isn't mentioned in his blog post, probably out of fear.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#45
post #16

I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue. Freedom of speech refers to government restrictions on limiting the right to voice your opinion. The government wasn't involved and he didn't legally have to remove the tweet (but I would have removed the tweet as well if it threatened my job). I totally support th…

> The government wasn't involved About that, when somebody threatens to sue a person and that is a credible threat, it's because the government is involved. The minimum guarantee of a democratic legal system is that for an innocent that phrase isn't a threat. If there is no guarantee, it's not a democratic system.

Necessary conditions to ensure an innocent person need not feel threatened by the prospect of litigation include a time, money and irritation-free trial process and omniscient judges.

Your "minimum guarantee of a democratic legal system" is an impossibility, unless tort law is altogether abolished, and good luck seeking democratic approval for that...

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#46
post #29

A friend went through the Swedish banks and ranked them (post in Swedish https://friendlybit.com/security/hur-sakra-ar-svenska-banker... and Google translate https://translate.google.com/translate?sl=auto&tl=en&js=y&pr... ) The response he got was the banks starting fixed their problems. He had one group of banks that he classified as you should stay away from. All those banks fixed things so they are not longer in t…

Interestingly, Nordea, which gets an A- in Sweden, still gives an F for their front page in Finland. So it looks that even if the same bank operates with the same brandname, the security level may be quite different.

Their internet banking front page domain name has a different environment which gets a B, but most people go to it via the front page that is still vulnerable to POODLE and what not.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#48
post #33

Earlier quoted context omitted.

Yea, I hope PCI DSS clarifies this matter soon.

For a long time I thought PCI DSS/NVD was the culprit for all RC4 on payment sites, but luckily this was solved, I see they updated the score on 03/12/2015: https://code.google.com/p/chromium/issues/detail?id=375342#c... https://code.google.com/p/chromium/issues/detail?id=375342#c... I usually complain when some site uses RC4 and I can't access it, but unlike the OP I don't do that via twitter (one reason is that I d…

Lets hope that the new RC4 attacks that will hit the news in a few weeks will help also.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#49

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

That being said, www.eurobank.gr is just a redirect to http. The actual banking uses https://www.ssllabs.com/ssltest/analyze.html?d=https://ebank...

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#50

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

As an aside, bank websites don't necessarily fall in-scope for PCI.

I worked for a small credit union, and we were beholden to our state auditors, FFIEC guidance, and the like -- but PCI simply wasn't a thing we worried about.

Post reply on HN