4 ms·
Well, Halifax (one of the bigger banks in the UK) has a similar config: https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Fwww.halifax-online.co.uk ht
by 9point6 11y ago
Well, Halifax (one of the bigger banks in the UK) has a similar config: https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Fwww.halifax-online.co.uk https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2...
I would have expected banks to have audits for things like these fairly regularly. Does anyone know why they are running such a broken configuration when a lot of these vulnerabilities have been around for months/years? Not to mention that even ignoring any vulnerabilities, their ciphersuite is dire.
- laumars 11y agoI'd be surprised / disappointed if banks weren't subject to PCI DSS audits and I know from my own personal experience with PCI compliance that the SSL 3 and TLS 1.0 would fail many 3rd party vulnerability scans. So I was very surprised to read your post and after checking the URL (www.halifax-online.co.uk) myself, sadly it seems you're right. Sadly this isn't the first time I've questioned Halifax over their security policy for online banking. When I first signed up with them approximately 5 years ago, their login process consisted predominantly of researchable questions (eg "what was your pet's name", "what primary school did you attend", etc). Thankfully now they have a standard 2 password process now with 2FA used for any additional payment processing.
- brohee 11y agoBanks aren't subject to company wide PCI DSS audits. Which makes sense as you don't usually input your credit card number anywhere...
- laumars 11y agoI'm not going to disagree with your generalisation there. However with Halifax, specifically, you input your debit card details as authentication when resetting your password / sending user name reminders. And since user names are non-memorable (the one assigned to me was a 9 digit integer!), you can find yourself using the user name reminder feature on Halifax more regularly than you'd normally expect.
- PuffinBlue 11y agoLloyds appears to have an identical config: https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Fonline.lloydsbank.co.uk%2Fpersonal%2Flogon%2Flogin.jsp https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2...