32 ms·
HTTPS on Your Landing Page Is Important
- paulddraper 9y agoTroy is way overstating the case. You want to know if the login page is NatWest? Click on the Login link and look at the browsers security bar. If it says "The Royal Bank of Scotland Group Plc [GB]" and that then entity with which you do business, great. It seems as if Troy would be just fine with HTTPS rather than HTTP, but DV validated certs aren't what you want anyway with a financial institution. It seems far more likely that you care about the entity you are working with (Royal Bank of Scotland), than the domain of the referring page (personal.natwest.com).
- lucaspiller 9y agoNatWest is a subsidiary of RBS.
- umanwizard 9y agoWhat fraction of users will do this, in your opinion?
- paulddraper 9y agoAbout the same number of people that have been MITM'ed for personal.natwest.com and divulged login information.
- tonyztan 9y agoThe issue is that users tend not to notice the absence of EV security indicators. If they see a padlock (which a phisher could get for a phishing domain), they assume it's secure and enter their credentials. Also, it may not be apparent to users whether "The Royal Bank of Scotland Group Plc [GB]" would be affiliated with NatWest. Companies often have different names they do business under.
- paulddraper 9y ago> Companies often have different names they do business under. If the name is unrecognizable for users, _that_ is the user security concern that you should be posting about. That handles the widest array of security vulnerabilities on http://personal.natwest.com/ http://personal.natwest.com/, whether MITM, compromised site, misspelled domain, etc.
- f2n 9y agoAnd if you aren't familiar with the details of how web browsers work (eg most people who use them), you would have no idea something was wrong. Not to mention potential problems such as http://stripe.ian.sh http://stripe.ian.sh
- steve_musk 9y agoUhh, yeah you could do that. Do most people do that after they click the login page on their bank's website? No. The issue is that most non-technical users would not even think about checking. They went to their "secure" bank website and clicked login, why should they have to worry?
- theptip 9y agoUnfortunately EV certs are not bulletproof: https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/ https://arstechnica.com/information-technology/2017/12/nope-... For ~$170 apparently you can get an EV cert for "Stripe, Inc" (by forming a company with that name). Even aside from that fact, users are very bad at knowing what a secure site looks like. I would wager that if most users clicked "login" and didn't see an EV cert, but instead saw "<padlock> Secure" (i.e. a non-EV HTTPS connection), they would not notice the difference. Troy is right to kick up a fuss about this; this is a significant attack vector (anyone on a wifi network can MITM your banking login URL), and it's more egregious because of how easy it is to set up HTTPS.
- paulddraper 9y agoDomain names don't solve that either. For one tenth that cost, you can register stripeinc.net and get an SSL cert. Yay! Domain registration is available instantly for anyone, anytime, and it can be phished at least as easily as anything else. https://www.xn--80ak6aa92e.com/ https://www.xn--80ak6aa92e.com/ looks pretty legit in Firefox.
- swvjeff 9y agoSure, but that's just more reason to use HTTPS across their entire domain and would help prevent users from being phished as easily. If I enter "apple.com" I expect all links on that page to point me to the correct location. A MITM attack from a non-HTTP page could easily alter the page and link me to https://www.xn--80ak6aa92e.com/login https://www.xn--80ak6aa92e.com/login instead.
- chickenfries 9y agoOr put another way, don't notice the absence of "The Royal Bank of Scotland Group Plc [GB]". Or don't notice if it's been changed to "RBSG [GB]" or "Royal Bank [GB]". Then there's this: https://stripe.ian.sh/ https://stripe.ian.sh/
- ithilglin909 9y agoI think Troy will be just fine -- it's the average user NatWest should be protecting.
- latortuga 9y agoWasn't there a post on HN just yesterday about EV certs not being a secure method of authenticating the website you're on? Something about Stripe being spoofed. The case is not overstated in any way, serving a major trust-building page like a bank homepage over HTTP is crazy. Redirecting to a spoofed webpage is obviously the simple hijack but there's no reason some attacker couldn't drop some custom-built HTML and JS to drop a faux-login form right on the page that's filled with copy about how trustworthy the bank is. Sidenote: several years ago my bank started POSTing their login form to a completely separate domain to login to my account. So I fill in the username field on the homepage and it sends me to "totallysecurebankloginsite.com" to enter my password. After a few calls to the bank they insist that this is the design they intended and that it's just fine.
- niftich 9y agoJust one day prior, I wrote that people's mental model of the benefits that EV certs confer is broken [1]: "an EV cert asserts that the domain name is controlled by a legal entity in some jurisdiction. This is a very distinct notion from the site that you've arrived at being the site that you were intending to visit, but people use it as a terrible, flawed proxy for such." This was on the topic of an EV cert being issued to a different 'Stripe, Inc'. But also, I observed that for top sites, "people trust their website by fiat, simply by mental associations about their domain names (...)". This is why HTTPS on a landing page is so important: to safeguard the trust chain that most users use to arrive at the login page -- first, the name of their bank, then the bank's URL from memory, then the bank's login page from the homepage's URL. [1] https://news.ycombinator.com/item?id=15909273 https://news.ycombinator.com/item?id=15909273
- dasil003 9y agoDude, you could walk into a coffee shop in the UK today, set up a honeypot wifi, and over the course of a day collect a handful of credentials with direct access to bank accounts. Unlike the US, once you're into an account you can send money directly and more or less instantaneously to any other UK account. Assuming every single person is verifying the cert/domain after they click the login link is batshit insane, I guarantee you no more than 10% of people would even have a chance of noticing.
- wepple 9y agoMost users check the URL when they first browse to a page. You want them to continuously keep verifying it’s the correct domain/cert just because this company is too lazy/cheap to buy a cert?
- cdancette 9y agoMaybe someday browsers won't accept http connections by default (except for a few domaines defined for test purpose, or for some specific tld like .local) Only then we can have 100% of the web encrypted.
- f2n 9y agoIt's moving that direction. As it stands, any website can opt-in to this behavior for future visitors with HSTS[0], or even for first time visitors with HSTS preload[1]. And Google has been doing HSTS preload on their .google TLD for several years, and recently rolled it out to their .foo and .dev [2] TLDs [0] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [1] https://hstspreload.org/ https://hstspreload.org/ [2] https://security.googleblog.com/2017/09/broadening-hsts-to-secure-more-of-web.html https://security.googleblog.com/2017/09/broadening-hsts-to-s...
- WorldMaker 9y agoThere were a lot of complaints about Google doing that with .dev given the number of other companies and developers that use .dev for random LAN things, but an HSTS Preload for random LAN things isn't a bad idea in that it can prevent some types of mistakes going to production like bad HTTPS->HTTP redirects in an application. Obviously, Google themselves thought it a good idea to test that in their development environments.
- f2n 9y agoThe people doing random things with fake .dev domains were going to get bit in the ass one way or another. You can't just make up your own domain and hope no one ever does anything conflicting with it.
- untog 9y ago> You can't just make up your own domain and hope no one ever does anything conflicting with it. Actually you can! You just need to use one reserved for that purpose: > In 1999, the Internet Engineering Task Force reserved the DNS labels example, invalid, localhost, and test so that they may not be installed into the root zone of the Domain Name System. https://en.wikipedia.org/wiki/.test https://en.wikipedia.org/wiki/.test
- konschubert 9y agoThat feeling when you're arguing with an idiot, and the idiot isn't listening because he thinks it's YOU who's missing the point.
- ethbro 9y agoThe important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.
- QAPereo 9y agoThe problem is that for all of the stereotypes to the contrary, tech is really full of people who worry, "Am I wrong? Am I the idiot?" Banks clearly don't attract the same kind of person, with the same intellectual gifts and challenges. Your advice is great, but it's probably already being taken to a fault by people like Troy Hunt, and people like the goober on the other end of the line think Dunning-Kruger is a brand of champagne.
- gerdesj 9y ago"think Dunning-Kruger is a brand of champagne." Oh bollocks, that's me undone. Err without Googling and being British and given where I am and a few other things, I'm going to go for ... ... firearm? Simplistic analysis by me: Well it can't likely be a Champagne (French). Dunning (English), Kruger (German with options). OK Goo ... https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect https://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect - hmmm 8)
- msla 9y agoThe most important scientific mindset is being willing and able to prove yourself wrong. It's an important legal mindset, too, because it's an important mindset for any honest debater: You prepare an argument by attacking it, and trying your damndest to be the best argument for the opposition you can possibly be. That's important in moral issues, where there arguably is no "right answer" to certain questions, but it's vital when things come down to factual questions where one position is right, any other position is wrong, and being able to recognize when you're holding a position which is wrong is vital to being honest, not only with others but with yourself.
- leesalminen 9y agoProbably not a good person to piss off. Several months ago I recall a website owner posted a bug to Firefox saying he didn’t need HTTPs and that Firefox shouldn’t tell users it’s insecure. Within hours his database was pwned.
- nkkollaw 9y agoAnd it's so easy for anyone nowadays to get SSL with Let's Encrypt... I remember a few years ago when there was no way you could do it for side projects because certs were 100/yr., now they're free.
- megy 9y agoIt is not easy if you are on a shared domain and it is not supported by your host. Please don't run around saying it is easy for everyone.
- peterkelly 9y agoIf you're on a host that doesn't support HTTPS, you should probably find a different one.
- giancarlostoro 9y ago
- bribroder 9y agoSo more specifically, HTTPS on pages where you log in is important, not necessarily on your landing / homepage? I am not disputing that may be a good idea, but it seems like the main complaint is that users are submitting credentials on an HTTP page?
- i80and 9y agoThis is exactly the opposite of what the article states. The HTTP landing page serves a link to the login page. This link could be modified by a hostile network to another site. The fact that the login page is served over HTTPS is immaterial for this attack.
- deleted 9y ago[deleted]
- pmelendez 9y agoHonest question... Under that attack, wouldn't be the same whether you are using https or not? If you are in a hostile network with a compromised DNS, Couldn't the domain be phished too? Meaning that a valid certificate trusted by a fake CA would be used by the browser?
- wayfarer2s 9y ago> valid certificate trusted by a fake CA I don't think that's possible. A fake CA can't issue out valid certificates because you wouldn't trust their certs to begin with -- it's all about trust and if you know they are a fake CA, then you would never trust them or anything they issue. It's like if a known counterfeiter claims to be selling legit products, you probably wouldn't trust them.
- ashelmire 9y agoA compromised, but legitimate CA is a vector of attack in this case. Any CA can be compromised by nation-states through legal coercion, and all of them probably have some vulnerabilities that have yet to be found. There are also new CAs that are not yet trusted, and sometimes old ones that are on their way to being delisted. So you need an up-to-date list of trusted CAs (which most of us are relying on google for, in this case), which means trusting google at the very least (a company that compiles and sells your data, and is also based in a nation that issues secret warrants and orders to tech companies). It would be pretty surprising if this wasn't already a vector of attack being actively used (the fact that a trusted list needs to be maintained suggests that it is).
- freeflight 9y agoThat edit, about NatWest buying up the example domain to "fix" the problem, gave me real good laugh. It's interesting how simple mindedness can be so unexpectedly expected.
- andrewflnr 9y agoYep. I laughed out loud in an empty room at that one.
- quickthrower2 9y agoActually that is a smart thing to do in it's own right, as long as they quickly move to https.
- yjftsjthsd-h 9y agoNot even predicated on HTTPS; owning more domains helps combat some obvious forms of fraud. Though, really, I agree that HTTPS is more important.
- quickthrower2 9y ago> Not even predicated on HTTPS Sorry that's what I meant. Both moves are smart. Doing both is smartest.
- marksomnian 9y ago> Alarmingly though, nw0lb.com is still available as is nuu0lb.com and it-doesnt-matter-because-that-isnt-the-point.com. My sides.
- JepZ 9y agoWell, they probably got a process for buying domains, but changing the websites architecture requires a project/task-force/whatever, which can't be set up so quickly (I'm just guessing).
- ivanbakel 9y ago>you could go register nuuolb.com right now Not anymore! https://www.whois.com/whois/nuuolb.com https://www.whois.com/whois/nuuolb.com It seems NatWest has quickly gone to secure this major attack point in their otherwise chink-free armour. Does someone want to inform them about nwalb.com as well?
- cdancette 9y agoThis is mentioned in the article. He also mentioned they didn't buy nw0lb.com and some other domains.
- zodPod 9y agoGives me an idea! Why not go buy up a bunch of these types of names then tell them that they look similar to their login url. THEN when they come to try to buy it they find you own it and then charge them an arm and a leg for the domain?!
- cdancette 9y agoThat's typosquatting and it's not very ethical. It's also in a grey legal zone, you might get sued for this. So I would advise you not to do it.
- npgatech 9y agoDo you have any examples of "You might get sued for this"?
- berbec 9y agoThere is the horrible example of the nice computer company that had called itself by a certain name. [1] They registered their domain in good faith and conducted business. Later, a multi-million dollar car company decided they wanted the domain for the name they choose after Datsun and lawyered up on the mom-and-pop computer company. 1: http://nissan.com/ http://nissan.com/
- tachion 9y agoI'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still major company) Three mobile provider that asks your for your password while calling in for support. You heard it right, support representative asks you for your password to verify you are the account holder. There is no other way and no amount of explaining that it's insane and won't happen till I'm conscious was able to convince them to stop.
- tolien 9y ago> Three mobile provider that asks your for your password while calling in for support When I got a new nano-SIM (in 2012, one hopes they've changed this since), they didn't check any ID and only needed a postcode and date of birth to move my account to a new SIM.
- IneffablePigeon 9y agoWhen I went in a couple of months ago to do the same thing (_slightly_ more complicated situation - I had two accounts but only one SIM card and had topped up the wrong account), the store manager told me he couldn't help me and handed me their store phone dialled to their call centre (!). The man on the other end of the phone was totally unable to solve my problem and in the end just gave me £10 of free credit on the account I'd meant to top up. He didn't ask for any ID or verification at any point, except for the serial number on the SIM card. It was a pretty bizarre customer service experience.
- sumitgt 9y agoI think it's not just the UK. In fact, in many countries you don't have enough protections for security researchers. So no one bothers reporting these things because it would get you in trouble.
- philipwhiuk 9y ago
- kaycebasques 9y agoA great example for why we (the Google Web Developer Relations team) advocate for HTTPS everywhere. https://developers.google.com/web/fundamentals/security/encrypt-in-transit/why-https https://developers.google.com/web/fundamentals/security/encr...
- blakesterz 9y agoWhy is it you (or someone there) chose "Secure" in the address bar rather than something like "Private"? It seems like the people who don't understand what httpS means at all see "Secure" and think "oh this site is safe/secure" no matter what this site is, like if it's a phishing site. I'm not one to be very pedantic, but "Secure" up there really doesn't mean "Secure" at all. I know what it means, but people falling for dangerous sites don't get that at all. I don't really know what the best word is, but "Secure" seems like not the best choice there. [Edit] Thank you to those people who had some honest replies, not sure why this got down voted, it was an honest question. When you go to the "Learn More" page on Chrome it doesn't even say "Secure" it says "Information you send or get through the site is private."
- kaycebasques 9y agoWords are hard. Anyone got an idea for a better word? Send your ideas to the security-dev mailing list (at least, I think that's the best forum...): https://groups.google.com/a/chromium.org/forum/#!forum/security-dev https://groups.google.com/a/chromium.org/forum/#!forum/secur...
- quickthrower2 9y agoA Bank! There is no excuse. The thing about domains is that so many companies register companyname-someotherwords.com for legitimate use that if you are suspicious about the domain name you'll get little done. Azure is a case in point. What if browsers record "tainted follows"? E.g. you visit http. Once you click a link, anything linked from there onwards is not trusted. No http post information is sent to the server without a hard to get around warning page.
- cm2187 9y agoAnother lesson is to always host the login section on a sub domain of the company which website you visit. A prime example not to follow is Citibank in Europe. My account is with citibank.co.uk, but when I login to my account I get redirected to online.citi.eu. How do I know that citi.eu belongs to Citibank? I have no relationship with citi.eu, that’s not the website I visited. How do I know I can trust it? Microsoft is another major offender. When logging in, I get redirected 20 times between various domains, none of which in microsoft.com
- iaw 9y agoCiti has some really bad security practices, when I talked with them about it they mentioned some future changes they were planning that were even worse.
- nerdponx 9y agoWhat is the business reasoning behind this kind of domain name silliness?
- johnsoft 9y agoI assume one team is responsible for the home page, and another team is responsible for the banking portal, and they can't be bothered to coordinate with each other.
- gerdesj 9y agoI agree. There is no technical reason behind this sort of bollocks. One day S&M will catch up and have a fit at the fragmented "front face" - quite right too. To be honest the board should also give a shit about their org's outward appearance. Bit of a fail all 'round, really.
- deleted 9y ago[deleted]
- 9y ago
- nanoscopic 9y agoWhat is the exact problem here? Who would be doing a MITM attack on someone and how? It doesn't seem to matter to me if my ISP is MITM, because someone inside the ISP would need to cause that. If my ISP is forced to MITM by government etc, I am in trouble anyway. I could see that it could be done by using a bad/spoofed wireless or a public network connection somewhere. That makes sense. I don't do that though; I only use my own secure home network in a wired fashion when accessing my bank account. If people are able to spoof my network connection, they could interfere with non-https software updates on my machine, which would let them replace the root certs of my browser potentially, in which case https wouldn't matter. Is the assumption here that all software updates on my machine are happening via https and only the bank website is a danger? My point here is that while I agree what the bank is doing is bad practice, I don't see how it would affect me in any way.
- moreira 9y agoThere are plenty of people accessing their banks on public / insecure networks; it’s folly to assume that MITM attacks just can’t happen. You yourself might not be at risk, but you’re not the only person out there. The assumption is that yes, all of your machine’s updates are served over HTTPS. If they weren’t, then of course you’re right - it’d be possible to hijack your machine by serving malicious binaries. That’d be one hell of a security hole.
- nanoscopic 9y agoI stated specifically that I agree it is bad in situations where you could be MITM. I also agree many people do that. My question here is only how it could effect me or people who follow the practice I follow.
- zAy0LfpBZLC8mAC 9y agoYour assumption that there is such a thing as a "secure network" is foolish. ISPs inject vulnerable javascript into pages, ISPs have vulnerable routers, ISPs have bad passwords on their devices, ISPs have criminals on staff, ISPs run traffic through unencrypted microwave links that anyone close to the beam can listen in to, ISPs have devices running in remote locations, ... and your traffic is going to run through who knows how many ISPs, possibly even through other countries, ... in short, it simply doesn't make sense to build anything on the assumption that the network is secure.
- logingone 9y agoNatwest is RBS - there is no point interacting with them - useless. Same with many UK household names, once they reach a certain size you are not a person and what's in your head is of no interest to anyone.
- dazc 9y agoThis can, sometimes, work in you favour though since it is possible to get a county court judgement against these organisations for trivial reasons because the original claim isn't responded to.
- deleted 9y ago[deleted]
- JepZ 9y agoWell, the bank seems to be stuck in the past... 10 years ago it was best practice for ecommerce shops to serve non sensitive pages (pages without forms or user data) without HTTPS to reduce the server load (HTTPS connections are a little more expensive than HTTP). Nowadays, even the economical driven ecommerce shops got it that is better to just serve everything via HTTPS. It is very sad to see a bank (which should really know better) arguing that way.
- dazc 9y agoIn the UK there are major ecommerce sites still on HTTP.
- mprev 9y agoMajor sites, really?
- dazc 9y agomarksandspencer.com very.co.uk asos.com next.co.uk and many more.
- Jaruzel 9y agoOther than shopping privacy, who cares? As long as the checkout and account management pages are https, then I don't see the big issue here. I'm just not one of these people who think there are armies of people at the NSA/GCHQ spying on me. I'm also against forcing every website in the world onto https. Doing so will significantly raise the bar of accessibility for tinkerers and makers. If I had a webcam that showed the world whether my coffee put needed refilling[1], are we all saying (on this thread, and troy hunt) that it needs serving over https because the privacy and security of coffee watchers is such a closely guarded secret that they need to be secure in their coffee pot watching habit? By all means, https up important pages and sites, but lets not make it mandatory to the extent that http is no longer supported by browsers. As an aside... a Barclays bank advert running in the UK at the moment is showing users that 'a padlock in your browser bar ensures that you are safe and that the site you are visiting is who you think it is' - which is utter bullshit, all a padlock tells you is that site owner has spent 5 minutes setting up LetsEncrypt - it in NO way confirms that they are who they say they are, and it's this lie that Joe Public are being sold right now. --- [1] Apparently this was a thing once ;)
- 4rt 9y agoAbout 8 years ago Natwest had a policy of having a "browser whitelist" which was rarely updated. Each time a security update for chrome or firefox came out it would be 2 weeks before online banking was accessible, and using any pre-release versions were out of the question. I complained and a member of the dev team phoned me up and after a long discussion about why this was madness he told me that it was better to use older browsers for important things such as online banking (like IE6 which was in their whitelist) because they're tried and tested.
- adenta 9y agoWhen I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.
- foobarbazetc 9y agoTo be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.
- DaiPlusPlus 9y agoExcept for the unnecessary 5 second wait when accessing chase.com for the login prompt to appear.
- foobarbazetc 9y agoI just go direct to chaseonline.chase.com . It’s not pretty but it’s quick. :)
- bubblethink 9y agoChase doesn't like chromium. It'll randomly load a mobile page if your user agent string is chromium. Not to mention, none of the US banks allow standard 2FA (TOTP). If they have 2FA at all, it'll be SMS.
- philipwhiuk 9y agoI'm so glad I bank with Nationwide who seem to do this right.
- exabrial 9y agoIt's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
- morinted 9y agoBMO in Canada forces 6 digits or alphanumerics as your account password. No more, no less. What's worse, because it can be entered on the phone, aAbBcC are all == 1. So it's really just 6 digits.
- toomanybeersies 9y agoSomewhere, in the background, there's a poor old unix mainframe running Cobol, unaware that the world around it has changed, and that it should put to pasture, where it can live out the rest of its days in peace.
- bigiain 9y agoWorse, it's probably an emulation of a Unix mainframe running the original Cobol code - with the emulator running in machine generated JavaScript in Nodejs on AWS... (Obligatory xkcd comic: https://xkcd.com/1926/ https://xkcd.com/1926/ )
- azernik 9y agoNo, more likely it's a newer IBM mainframe, as those are built to be backwards-compatible with software written back in the 60s.
- madaxe_again 9y agoA large bank in the uk runs their core software on AS400s emulating a 1401. Their ledger software is almost 60 years old.
- palencharizard 9y agoit-doesnt-matter-because-that-isnt-the-point.com
- yjftsjthsd-h 9y agoWhat is the point?
- SAI_Peregrinus 9y agoAn insecure page can be MITMed. The landing page is insecure. The links from the landing page to the login page can be redirected by an attacker to go to the attacker's login page. Links on HTTP pages cannot be trusted. NOTHING on HTTP pages can be trusted.
- syncsynchalt 9y agoBuying every domain name that could possibly be confused with yours would be unnecessary in this context if you fixed the issue of an attacker being able to redirect to another name. (Banks should also protect against easily phishable domain names but that's a also losing game, and in that case the technical solution is not as simple or complete).
- pwdisswordfish2 9y agoSSL certs are based primarily on domainname registrations. Why not check the domainname registration first? See below. But the author is not highlighting HTTPS "validation". He is highlighting HTTPS encryption. Protection against tampering with traffic. Domain Name: nwolb.com Registry Domain ID: 9074606_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.corporatedomains.com Registrar URL: www.cscprotectsbrands.com Updated Date: 2017-09-15T14:16:24Z Creation Date: 1999-08-13T15:18:25Z Registrar Registration Expiration Date: 2019-08-13T15:18:12Z Registrar: CSC CORPORATE DOMAINS, INC. Registrar IANA ID: 299 Registrar Abuse Contact Email: domainabuse@cscglobal.com Registrar Abuse Contact Phone: +1.8887802723 Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited Registry Registrant ID: Registrant Name: Domain Manager Registrant Organization: National Westminster Bank plc Registrant Street: 135 Bishopsgate Registrant City: London Registrant State/Province: ENG Registrant Postal Code: EC2M 3UR Registrant Country: GB Registrant Phone: +44.1316260002 Registrant Phone Ext: Registrant Fax: +44.1315239568 Registrant Fax Ext: Registrant Email: domains@rbs.co.uk Registry Admin ID: Admin Name: Domain Name Manager Admin Organization: The Royal Bank of Scotland Group Plc Admin Street: Global Network Services Admin City: Edinburgh Admin State/Province: SCT Admin Postal Code: EH12 1HQ Admin Country: GB Admin Phone: +44.1316260002 Admin Phone Ext: Admin Fax: +44.1315239568 Admin Fax Ext: Admin Email: domains@rbs.co.uk Registry Tech ID: Tech Name: DNS Administrator Tech Organization: CSC Corporate Domains, Inc. Tech Street: 251 Little Falls Drive Tech City: Wilmington Tech State/Province: DE Tech Postal Code: 19808 Tech Country: US Tech Phone: +1.3026365400 Tech Phone Ext: Tech Fax: +1.302636545 Tech Fax Ext: Tech Email: dns-admin@cscglobal.com Name Server: dns1.cscdns.net Name Server: dns2.cscdns.net DNSSEC: unsigned
- pwdisswordfish2 9y ago"If someone is messing with traffic then they can modify non-secure requests. Yeah?" Yeah, but what does "messing with traffic" mean exactly? Does it mean sniffing? If it does not mean sniffing then please stop reading here. ------------------- Assuming the user is using DNS over UDP, as most are, what if "someone" who is sniffing the network modifies one of DNS packets destined for the user? Assume HTTPS and DNSSEC, just for fun. Will the user be able to reach the website and log in? [ ] Yes [ ] No What do you think?
- toomanybeersies 9y agoA bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this when people try talking to me about computer science topics, when they don't realise that it's what I do for a living. I've probably done the same myself when talking to Doctors and other domain experts, I'm sure.
- wruza 9y agoAuthority is a bad thing here, since the person who spoke to him is in a shadow of his own tech team authority. Don’t get me wrong, but if there is an objective security/xyz problem, then it doesn’t matter who’s reporting it and what does he make for a living.
- madaxe_again 9y agoThis being NatWest the penny probably still hasn’t dropped, and they’re probably trying to get him arrested for “hacking our internet”. I doubt they’ll actually implement a change. The general approach in the UK has been to not blame banks at all for poor security, and to punish anyone who finds a security issue severely.
- ZoFreX 9y agoNatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things. There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.
- sp8 9y agoI was in branch the other week and they were doing exactly that... from Windows XP. Staff member told me they were upgrading to Windows 10 soon and they couldn’t wait.
- OliverJones 9y agoA tweet from Troy Hunt is like a telelphone call from Brian Krebs: a sign your day is not going to get better, if you're a company infosec person.
- syncsynchalt 9y agoCould be worse; could be @taviso.
- wyldfire 9y ago> Alarmingly though, nw0lb.com is still available as is nuu0lb.com and it-doesnt-matter-because-that-isnt-the-point.com. I can just imagine NatWest: "Oh, is that the problem? Ah, ok, well, let's just go get that domain then. Sorted!"
- sandov 9y agoIt would be acceptable for your local Chinese food restaurant to serve their landing page without https. But a bank? of all things? A FUCKING BANK?.
- jacinabox 9y agoI followed out this logic, and concluded that all pages on a site have to be encrypted, because someone may try to navigate to the login page from any page on the site. If the attacker can intercept one page they can lead the user to their own site (possibly even HTTPS, but with the wrong certificate). In a perfect worlds users would always check which certificate they're trusting (and have a plausible way to check who it belongs to) but that is not the real world.
- syncsynchalt 9y agoAgreed, every page should be encrypted. And the user shouldn't need to check the certs - if the CAs are trusted (yes there are problems there) then the domain name is enough.
- kuon 9y agoI think the main point is to explain this kind of issue to non tech people. A bit of programming, but most importantly, general concepts required to understand this kind of issue should be common knowledge. For me it falls in the same category as the people putting an IP camera to watch their son sleep and broadcasting it to the whole internet. This kind of issue should be understood by them. In this case, if the "banking manager" was aware of how security works, the issue would not have presented itself in the first place.
- erikb 9y agoI thought we are on "all pages should be HTTPS" since 2010 or something?
- syncsynchalt 9y agoIt looks like some markets have gotten the message more quickly than others.
- thorin1 9y agoScotiabank, one of the biggest banks in Canada, has the same issue: http://www.scotiabank.com/ca/en/0,,2,00.html http://www.scotiabank.com/ca/en/0,,2,00.html Didn't find any contact to report it. Is Twitter really the right place?
- antoineMoPa 9y agoThe fact that there is no HTTPs on a brand's landing page is no reason to annoy PR dudes on twitter though. I think the attitude here is kind of douche.
- jwilk 9y agoNote that https://personal.natwest.com/ https://personal.natwest.com/ has a valid certificate, but it redirects back to HTTP. :-(
- jimnotgym 9y agoI wonder how GDPR would change this attitude? If Natwest were to lose some data after May 18 and it was possible to show that they were warned about the problem by a reputable professional, then they are more likely to get fined, one would presume. Maybe this legal liability is what $bigcorp needs
- arthurfm 9y agoMonzo [1], Starling [2], Atom [3] and Tandem [4] all manage to have HTTPS landing pages. If they can, there isn't any excuse for the more established banks not to as well. Hopefully their mobile apps use HTTPS for everything too? Apparently 35% of all UK banks have insecure landing pages. [5][6] [1] https://monzo.com https://monzo.com [2] https://www.starlingbank.com https://www.starlingbank.com [3] https://www.atombank.co.uk https://www.atombank.co.uk [4] https://www.tandem.co.uk https://www.tandem.co.uk [5] http://blog.softwareverify.com/list-of-uk-banks-that-are-secure-by-default/ http://blog.softwareverify.com/list-of-uk-banks-that-are-sec... [6] https://twitter.com/softwareverify/status/940961044633149440 https://twitter.com/softwareverify/status/940961044633149440
- ZoFreX 9y ago> Hopefully their mobile apps use HTTPS for everything too? Well, HSBC's didn't: https://threatpost.com/banking-apps-found-vulnerable-to-mitm-attacks/129105/ https://threatpost.com/banking-apps-found-vulnerable-to-mitm...
- stevefan1999 9y agoYes, not only your landing page should be getting HTTPS; instead all websites should have had HTTPS already, this will gave the users/customers a sign of safety and trust.
- bArray 9y agoAnyone want to hear a joke? Go to the financial ombudsman homepage [1]... Bare in mind, on their complaints page you can download a complaints Word document, fully capable of having embedded VB script [2]. Also, it took them _months_ to sort out an issue where they would only check for 3 numbers (pin) and 3 letters (password), always asking for the first, second and third characters. Also-also, I remember a while back not being able to access my card (for about a day) because a single engineer accidentally corrupted their main database. [1] http://financial-ombudsman.org.uk http://financial-ombudsman.org.uk [2] http://financial-ombudsman.org.uk/consumer/complaints.htm http://financial-ombudsman.org.uk/consumer/complaints.htm
- harel 9y agoNot defending the practice of not securing your landing page in 2017, but for balance I must say that NatWest has probably the best banking mobile app I've ever used.
- MarkMc 9y agoNatWest is also guilty of storing passwords in plain text: their login page says 'enter the 5th, 8th and 12th character of your password'
- allyant 9y agoTo be fair we can't be 100% sure of that. It is possible they simply hash all the combinations they are going to show you. Could also be stored in an HSM making it a bit more secure.
- dan1234 9y agoWho's to say they haven't just hashed each individual character of the password?
- MarkMc 9y agoDoes that offer any real protection? I could try each possible character until I find the hash.
- NickLamp 9y agoYou are correct. He was joking
- wlll 9y agoIf you're storing individually hashed characters: a: 0CC175B9C0F1B6A831C399E269772661 b: 92EB5FFEE6AE2FEC3AD71C777531578F c: 4A8A08F09D37B73795649038408B5F33 etc. then this is basically the same as storing the plaintext characters because as long as you know the hashing algorithm you can generate a pretty small map of hash -> original character and convert back.
- AngeloAnolin 9y agoWhat's concerning here is that they could have easily bought a certificate and configured it to their site. Instead what they did as preventive measure is to buy the domain name that Troy mentioned as one of the possible vector to spoof their site. Hate to say this, but whoever made that decision as a course of resolution should be axed.
- wlll 9y agoFun story, my once CC provider (the now defunct "Egg") for a period responded with three A records for their main site (egg.com or something). This is fine, except one of these A records was a 192.168.x.x address so their site didn't work intermittently. I called them to report it and they refused to listen. Claimed the site was worked as intended from their office and they wouldn't escalate.
- a_c 9y agoThere need to be a public directory for these websites. Something similar to https://haveibeenpwned.com/ https://haveibeenpwned.com/. Something like is-this-site-stupid.com. Ridiculous password policy, http home page, virtual keyboard for password, loading javascript from http and what not..