Live data from Hacker News

Bank harrasses user because he tweeted screenshot of their SSL certificate

ebalaskas.gr

61–70 of 74 posts

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#61
post #15

Earlier quoted context omitted.

https://twitter.com/ansimionescu/status/576425676036780032 I work in security/privacy/premium snake oil trade. Bank security (and software in general) is _usually_ a joke. The main reason for not fucking with a bank is the same why you wouldn't fuck with casinos, or the mob.

> you wouldn't fuck with casinos, or the mob. Why wouldn't I, from the other side of the world, from the wifi connection of a coffee shop on the other side of town, bounced through a couple VPNs? It's one thing if I have to walk inside the casino, but the internet isn't like that.

The problem is cashing out. Any method of transferring the money to somewhere you can spend it (including Bitcoin) is going to require an identity. Not impossible, but certainly not as easy as Tor.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#62

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

The article states the the National Bank of Greece was the nice bank, NOT the one harassing him. It was the SECOND one that harassed him.

By listing the nice bank's twitter first, you're going to cause a backlash against the one that actually responded nicely.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#63

I really hope the bank gets a lot of bad publicity out of this. Marketing opportunity for other banks to jump on the bandwagon and share there public keys on social media.

> I really hope the bank gets a lot of bad publicity out of this.

It's a Greek bank. They couldn't care less about 'bad publicity' nowadays.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#64

You're all talking about the bank's response - but I actually think his employer's reaction was worse. Threatening to fire him for a tweet from a personal account? What Kafkaesque bullshit is this? Frankly, I'd be taking them to a tribunal - and I'm an employer. The idea of pulling that kind of shit on anyone fills me with disgust.

"Some guy who is wrong is threatening to beat me up unless I hit you or you change your tweet"

It's not like the employer said "you wrote an unfriendly tweet now you are fired!" The bank was threatening the employer with legal action unless action was taken.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#65

I really hope the bank gets a lot of bad publicity out of this. Marketing opportunity for other banks to jump on the bandwagon and share there public keys on social media.

I would sooner expect a bank to accidentally share their private key on social media. Banks aren't bad at security by accident. They don't have good, solid security people working for them being held back by management (as some industries do). Banks take the long view on most things and are ill-prepared for dealing with something like security, where the situation changes moment by moment. They are also extremely loathe (more than most industries I would say) to spend a penny on anything which they can not predict a tangible return on investment.

Hmm.. with the large number of security firms popping up every day, has anyone actually done some studies and statistical analysis so that it can be said "If you save $200,000 this year by not hiring a competent security professional, there is a 30% chance your bank will lose more than $10 million in either direct intrusion or public scandal"? That is the sort of thing a banker needs to hear before he can determine whether it is actually WORTH being safe. And even then... hiring competent security people is really hard. How is a normal HR person supposed to be able to judge whether an applicant is competent?

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#66
Someone created a site called https-watch, to list banks, government sites etc. that aren't using HTTPS properly but should be.

It has a built-in 'tweet to this entity' link, similar to what this guy did by himself.

Perhaps someone can open a Greek sub-section on the site, with links to these banks.

https://httpswatch.com/global

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#67

It's dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE: https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr their twitter account is: https://twitter.com/ibanknbg EDIT: The most effect…

The article states the the National Bank of Greece was the nice bank, NOT the one harassing him. It was the SECOND one that harassed him. By listing the nice bank's twitter first, you're going to cause a backlash against the one that actually responded nicely.

You're right, I noticed that in the article. I'll reorder them. They still desperately need to fix their security though.

edit: woops, looks like I cant edit it any more. bummer

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#68

Earlier quoted context omitted.

Let's be crystal-clear: All of these fail PCI compliance, because they have RC4 enabled. These sites have no business processing anything, let alone personal or financial info. Yes, having RC4 enabled is now an instant PCI compliance fail as it has a die-die-die RFC and as a result NIST changed it, on request, to a CVE grade above a 4.0 - https://tools.ietf.org/html/rfc7465 - https://web.nvd.nist.gov/view/vuln/detail…

As an aside, bank websites don't necessarily fall in-scope for PCI. I worked for a small credit union, and we were beholden to our state auditors, FFIEC guidance, and the like -- but PCI simply wasn't a thing we worried about.

True, but this is because a large number of credit unions don't issue Visa / Mastercard credit cards directly; typically they do it through their banking partners (who are registered as banks as opposed to credit unions who for almost all cases are not banks), if they do it at all.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#69

Earlier quoted context omitted.

> The government wasn't involved About that, when somebody threatens to sue a person and that is a credible threat, it's because the government is involved. The minimum guarantee of a democratic legal system is that for an innocent that phrase isn't a threat. If there is no guarantee, it's not a democratic system.

Necessary conditions to ensure an innocent person need not feel threatened by the prospect of litigation include a time, money and irritation-free trial process and omniscient judges. Your "minimum guarantee of a democratic legal system" is an impossibility, unless tort law is altogether abolished, and good luck seeking democratic approval for that...

There are several ways to make it happen in practice (where things are not boolean).

Imposing penalties to the suing party on stupid cases is one such way. One can also make the legal system cheaper, make it less irritating (as most of the irritation is accidental), level the playing field for people against giant corporations (and, while we are at that, also level for small corporations against big corporations)... There are probably hundreds of other actions that'll help, if none are taken, it's a huge sign that a legal system is already brought.

Re: Bank harrasses user because he tweeted screenshot of their SSL certificate

#70
post #20

Earlier quoted context omitted.

It's a "128 bits private key", what means it's assymetric. I fully expect it to be an RSA key, but even for ECC that's at least half the size of something that could be considered secure.

TLS uses several algorithms, almost always both asymmetric and symmetric algorithms, in every session. For example, my current connection to HN is TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256. And that does mean that our underlying session key is 128 bits, independent of the size of HN's public key (which turns out to be 2048 bits). There is a possible argument that a 128-bit AES key and a 2048-bit RSA key are mismatched, b…

Symmetric encryption does not have the concept of a "private key". A 128 bits private key in TLS can only vary from almost useless (if it's some ECC algorithm) to completely useless (in case it's RSA).

Too bad (but understandable) that the article does not give any detail. About a decade ago, 128 bits RSA keys were widely used (but not recommended anymore), I wouldn't be surprised to discover a bank didn't change their security procedures since then.

Post reply on HN