Live data from Hacker News

Bank harrasses user because he tweeted screenshot of their SSL certificate

ebalaskas.gr

51–60 of 74 posts

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#51
post #37

Along the same line, there are currently around 4,000 sites in Alexa's top 1 million that only support RC4. Nothing else. Some of these sites have large user bases too, and it's making it hard to disable RC4 in Firefox. https://bugzilla.mozilla.org/show_bug.cgi?id=1138101

That list includes Priceline, Orbitz and American Airlines. Hard to believe.

Is there a browser plugin that could report on SSL health in real-time, when visiting a site?

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#52
You're all talking about the bank's response - but I actually think his employer's reaction was worse.

Threatening to fire him for a tweet from a personal account? What Kafkaesque bullshit is this? Frankly, I'd be taking them to a tribunal - and I'm an employer. The idea of pulling that kind of shit on anyone fills me with disgust.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#53
post #15

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

https://twitter.com/ansimionescu/status/576425676036780032 I work in security/privacy/premium snake oil trade. Bank security (and software in general) is _usually_ a joke. The main reason for not fucking with a bank is the same why you wouldn't fuck with casinos, or the mob.

I used to write trading software - had test FIX accounts on live cbot, cme, xetra, Liffe, lme, etc.

Decided to see if I could still log in to any of them about a year ago. Still could on half of them. I left that gig a decade ago.

Oh, and a few of them have no trade limits or risk management.

Boggle.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#54
post #16

I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue. Freedom of speech refers to government restrictions on limiting the right to voice your opinion. The government wasn't involved and he didn't legally have to remove the tweet (but I would have removed the tweet as well if it threatened my job). I totally support th…

The idea that "freedom of speech" only applies to government actions is common, but nonsensical. Constitutional protection of that freedom only applies to the government, but that doesn't mean another entity taking the same actions isn't also abridging your freedom of speech, even in the US — it's just that the Bill of Rights was focused on limiting the government's power, not any other entity's, so it only prevents the government from abridging your freedom of speech.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#55
post #33

Earlier quoted context omitted.

Yea, I hope PCI DSS clarifies this matter soon.

For a long time I thought PCI DSS/NVD was the culprit for all RC4 on payment sites, but luckily this was solved, I see they updated the score on 03/12/2015: https://code.google.com/p/chromium/issues/detail?id=375342#c... https://code.google.com/p/chromium/issues/detail?id=375342#c... I usually complain when some site uses RC4 and I can't access it, but unlike the OP I don't do that via twitter (one reason is that I d…

It was, part of it. RC4 had a CVE score below 4 (which many interpreted as an issue they could argue around, i.e. "we need to support Windows XP!"), but BEAST had a score above 4 (auto-fail). And what was the (horrible!) recommendation people got when asking how to mitigate BEAST but still let Windows XP connect? That's right: RC4.

That excuse has gone, on two counts. RC4's now thoroughly toast, and Windows XP's unsupported - and now finds itself without any secure ciphers at all.

It's zmap time…

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#56

I really hope the bank gets a lot of bad publicity out of this. Marketing opportunity for other banks to jump on the bandwagon and share there public keys on social media.

Did the second (bad behaving) bank get named?

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#57
post #48

Earlier quoted context omitted.

For a long time I thought PCI DSS/NVD was the culprit for all RC4 on payment sites, but luckily this was solved, I see they updated the score on 03/12/2015: https://code.google.com/p/chromium/issues/detail?id=375342#c... https://code.google.com/p/chromium/issues/detail?id=375342#c... I usually complain when some site uses RC4 and I can't access it, but unlike the OP I don't do that via twitter (one reason is that I d…

Lets hope that the new RC4 attacks that will hit the news in a few weeks will help also.

Not long now. I think that will mostly depend on whether they give the issues a name and a logo! (Seriously though, that does seems to get people off their arses!)

You might want to get ready to change passwords for sites that have used RC4 in the past. Or, despite as much warning as anyone can give, are inexplicably still using it.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#58
post #32

> Firefox suggests some security concerns in the firefox console on both sites. Especially about how weak is sha1 algorithm. Both sites have a 2048 public cert, the one use TLS1.2 but the other TLS1.0 and one of them have a 128bit private key size. You all understand that from a security point of view, these things arent best practices. Especially if you are a bank ! 128 bits for symmetric key ciphers is actually fin…

Yea, more important is the RC4 at the top of the list with nbg.gr.

Ewww. I couldn't see the tweets or screenshots because of the HN DDoS.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#59

Earlier quoted context omitted.

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

As an aside, bank websites don't necessarily fall in-scope for PCI. I worked for a small credit union, and we were beholden to our state auditors, FFIEC guidance, and the like -- but PCI simply wasn't a thing we worried about.

Interesting. I know far, far less about the regulatory side than the practical side. I gather it's focused mainly on merchants, but the card providers themselves founded it?

I'm not sure what I can say except not every bank seems to share that view (although as said in other comments, quite a few banks do indeed have paleolithic systems in unexpected places, and that tends to extend to their security practices - I am not able to name any names, but I can wave in the vague general direction of things which involve VAXen, COBOL and DES-and-I-don't-mean-3DES, all of which thankfully predate me). But I'm not exactly familiar with US banking practices (thankfully): did the credit union just not issue any Visa/Mastercard/etc cards? Huh.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#60
post #29

A friend went through the Swedish banks and ranked them (post in Swedish https://friendlybit.com/security/hur-sakra-ar-svenska-banker... and Google translate https://translate.google.com/translate?sl=auto&tl=en&js=y&pr... ) The response he got was the banks starting fixed their problems. He had one group of banks that he classified as you should stay away from. All those banks fixed things so they are not longer in t…

Interestingly, Nordea, which gets an A- in Sweden, still gives an F for their front page in Finland. So it looks that even if the same bank operates with the same brandname, the security level may be quite different. Their internet banking front page domain name has a different environment which gets a B, but most people go to it via the front page that is still vulnerable to POODLE and what not.

Ditto for Denmark: https://www.ssllabs.com/ssltest/analyze.html?d=www.netbank.n...
Post reply on HN