11 ms·
Barclays Bank Using Internet Archive as CDN for JavaScript Files?
- rvnx 6y agoIt's cute but probably just a consequence of a content editor at Barclays who has copy-pasted some old content. A technical solution could be to add a strict CSP policy but in general the problem is broader and applies to a lot of banks. The real issue is that banks (and it's not specific to Barclays) are loading JavaScript code from third-parties. The fact that it is InternetArchive (yet another Internet cache) is not more worrying than GoogleUserContent.com for example. Otherwise, the "asking money for redemption/forgiveness" part to Barclays is a bit borderline in my opinion.
- raxxorrax 6y agoWell, as a guesture it would be nice if they could just add some money for the lawsuits against the archive. Aside from being an unwilling CDN, it has quite some other perks.
- curryhoward 6y agoContent editors should not be able to add arbitrary code to a bank's website unless it undergoes review from someone who understands web security. If there is some kind of content editing tool, it should only allow content (not arbitrary scripts) to be edited.
- wolfgke 6y ago> Content editors should not be able to add arbitrary code to a bank's website unless it undergoes review from someone who understands web security. Hardly anybody really understands web security.
- HenryBemis 6y agoI've audited e-banking websites before. Every file, every element needs to be accounted for. This is beyond "an honest mistake" and it should have been caught by any of the (many) scans the bank orders for its websites. And the scan/report should have caught that. Who does their scans/reports? What is the scope of these scans? Who reviews these reports? This is not about content. Content is "make a new page with that template and add a photo and the new text about XYZ product". Not a new functionality/code. I wonder who signed this off prior to.release and what does their wiki/Jira mentions. Edit: e-banking and other banks websites/online presence(s). Edit2/rant: I have been the go-to audit/sec/compliance guy for more than a decade. It amazes me in this forum that there are very few discussions/POVs on the audit/security element. In most cases (like this one), an experienced auditor would have picked this up in 20mins. If only Barclays (in this case) bothered to escape the fixed-10 years old checklist/audit program these would never have happened.
- chrisan 6y ago> This is beyond "an honest mistake" and it should have been caught by any of the (many) scans the bank orders for its websites. And the scan/report should have caught that. Who does their scans/reports? What is the scope of these scans? Who reviews these reports? It is partially baffling at least. We had to do a standalone website ad campaign for a bank (same level/recognition as barclays) once, some kind of rewards program where all you could do was browse what was possible to redeem your points for. No accounts, no cart, no integration whatsoever, it was basically a static site (with some user interactivity). We'd get scanned constantly and were always made aware of mistakes or issues, one of them being 3rd party resources. On the other hand, I wasn't too impressed with their security scanning. Two issues had come up that made me dubious of what all good this actually did. First was some kind of ssh vulnerability. We were using an older (but still supported) amazon linux ami. The ssh was actually patched but the version did not match what they wanted in the security tool's version. We had to get them to talk with AWS to ensure it was an actual patched version of ssh and the security scanning tool just wasnt accepting it as valid. The other was some kind of javascript vulnerability in a library. There was an open cve on the library, an open issue on github, with comments on how to fix it, but the library itself wasn't being updated. I manually patched it and named it version x.y.z-patched or something. Report comes back that its still a vulnerability. I'm like what? Impossible I just patched it and tested it myself. The CVE no longer works. So I just renamed it to x-patched.y.z and poof, we pass validation. This was my version time with vulnerability testing and I was kinda let down by it. I assumed they had people (or tools) actually trying to exploit the site like how I tested the patch for the javascript library prevented the CVE from working instead of just looking for version numbers and comparing to a list of known issues.
- ownagefool 6y agoThis doesn't make the scanning dubious; it's just shows it's limitations of simply being a check of known vulnerabilities. If you hadn't scanned, would you have fixed the CVE at all?
- VBprogrammer 6y ago
- BattyMilk 6y agoUntil about a year ago I was working as a FE developer for a major intenrnational bank. All the processes and knowledge were in place to make sure all considerations were taken with our software with regards to security. But... all that good work and intention goes out the window when the marketing and analysis teams could pretty much, on a whim dump any old JS onto a production page via GTM. During my 18 months there, there were numerous issues (thankfully not security issues - at least that we know of) indroduced via this method inc a full outage of the customer onboarding journey.
- ethagnawl 6y agoWhat is GTM?
- arez 6y agoGoogle Tag Manager https://tagmanager.google.com/ https://tagmanager.google.com/
- deleted 6y ago[deleted]
- jcahill 6y ago"customer onboarding journey" sounds altogether twee for a major international bank. Banks are mattresses with insurance policies. Why is there even a journey to be broken?
- gpm 6y agoBecause they have to know who you are in a fair bit of detail both to comply with the law and to know who they should let take money out of the account. Because they need you to agree to a bunch of contacts. Because they need to get you things like a bank card. Because they need to decide if they want to lend you money (most often in the form of a credit card). And so on and so forth.
- tweetle_beetle 6y agoI see GTM being used (abused?) by marketing teams regularly, but I'm really surprised that a bank with its own development team would allow it. It is really powerful and sometimes incredibly useful in some scenarios (e.g I once built a schema.org metadata system that scraped the pages on the fly for a site with a broken CMS). Simo Ahava does clever things with it. But from what I can tell, it seems to be a way of avoiding communication between teams, or a political power grab inside bigger companies - a parallel CMS. And the silly bit is that it's normally not doing much more than could be achieved by copy and pasting a few lines of code into a template.
- wastedhours 6y agoWhen I was coming up as a CMS operator there were a lot of jobs to undertake site updates for banks and law firms - the JDs were always caveated about needing to understand both regulatory as well as security issues. I never applied as I like pushing the boundaries when it comes to using CMSs, but if they're calling it out from Day One it's also on the operator to not do it even if they could.
- onion2k 6y agoAdding scripts might be considered OK (content editors could be given light-weight developer tasks), but modifying the site's CSP definitely isn't. There aren't many things you can do to stop an attacker injecting code in to your site, but having a CSP that whitelists servers under your control and blocks everything else is something that you can implement. Changes to the CSP should not be done lightly. The fact that the CSP is whitelisting archive.org makes this look like an attack to me, or at least a test run before a real attack. I don't believe this was a simple mistake.
- mijoharas 6y agoI'm gonna invoke hanlon's razor (never attribute to malice what can equally be explained by stupidity) here to assert that this isn't an attack. Looks like their main homepage doesn't have a CSP policy at all https://cspvalidator.org/#url=https://www.barclays.com https://cspvalidator.org/#url=https://www.barclays.com I really hope they have a postmortem and actually implement a CSP for their site, pretty crazy not to, especially for a bank.
- yyyk 6y ago"implement a CSP for their site, pretty crazy not to, especially for a bank." I just checked some of the local banks. Oh dear...
- iforgotpassword 6y agoSure, but this is Barclays. Fun story: I had a Barclaycard once. I chose to get bills/invoices via snail mail because I'm old fashioned. Didn't use the card for almost a year after signing up and then finally bought something online with it. Got an invoice next month and paid it. Then got another invoice the next month over 60ct for the invoice sent via snail mail. Fair enough, they stated that when I signed up. But then I got another bulk the following month because, you guessed it, the invoice for the invoice was sent via mail. I tried to be clever then and paid 1.20€, but that doesn't work since I still got a letter saying there's still enough money in my account covering the invoice. So after four or five months I just gave up and canceled my account.
- jacquesm 6y agoWith a $19M liability hanging over their heads the archive could do with some extra cash.
- pjc50 6y agoIt's kind of bizarre how many people are out to defend Barclays here. Normally HN is the first to criticize websites for bad Javascript, ugly fonts, scrolljacking, etc. It's not the TSB IT fiasco but it's still an error on their part.
- edw 6y agoIf people are cutting Barclays slack, perhaps it's because the guy on Twitter is painting this as a satanically evil deed when it was probably just someone making a stupid mistake. Additionally, the aggregate bandwidth cost of delivering that JS file during its lifetime is probably less than $0.05. How many copies of this file would need to be concatenated to equal the size of David After Dentist? No one levels up on the Internet — and especially Twitter — by being calm and reasonable.
- stefan_ 6y agoI looked at the Tweet (you know, it's also the article title) and it does no such thing - even referring to this as the Internet Archive CDN. This is entirely a strawman you are burning down to make light of the fact that far from a stupid mistake, this is recklessness enabled by the joke of an "web development" industry. This stupidity is common practice and certainly no one in this thread seems even slightly inclined to clean it up.
- fomine3 6y agoYou can do any stupid things in any development environment. Let's execute a SQL from Android App to Oracle in Bank!
- edwinjm 6y agoLoading JavaScript from an external website is not "just someone making a stupid mistake". It means they don't have their security in order, they're a bunch of amateurs and their banking license should be revoked.
- Spooky23 6y ago
- baybal2 6y ago> A technical solution could be to add a strict CSP policy but in general the problem is broader and applies to a lot of banks. The Web is broken, and CORS/CSP headers will only be able to fix only some individual cases, of a bigger, currently unfixable design problem. The tons of random JS APIs brought into the browser without a any real critical review are making the initial design of scripts on the web being inherently secure, to them not being so. The state of things needs to be brought back to the point where arbitrary JS simply cannot mess up your browser by design, and when you can load resources from everywhere safely regardless of tricky settings of now 10+ CSP related headers. Or alternatively, there needs to be a solution to completely shut down those APIs, any "advanced" functionality to load 3rd party resources, reinforced by cryptohashes, and signature checks to verify loaded resources.
- secondcoming 6y agoWASM needs to be killed with fire before it's too late.
- baybal2 6y agoFully agreed!
- jfengel 6y agoWhy? I don't know much about WASM, but surely it is better than the cobbled together monstrosity that is JavaScript.
- bioipbiop 6y agoAll the insecurity of js, but with the opaqueness of assembly.
- yellowapple 6y agoHard disagree. WASM is as good an opportunity as any to enforce better security habits, and indeed seems to be designed specifically with browser security/sandboxing in mind. "Killing" WASM does precisely nothing to fix the status quo around JS insecurity.
- lilSebastian 6y ago> It's cute but probably just a consequence of a content editor at Barclays who has copy-pasted some old content It's unlikely that a content editor would be able to do this, given the industry.
- eska 6y agoIt's really annoying how people like him blow these things out of proportion to shame and extort companies.. Seems like he didn't even make a serious attempt to message them.
- immunda 6y agoTwitter author here. I didn't make any assertions about the impact of this issue. A respondent to the Tweet said they found this earlier and had already disclosed it to Barclays. I also tried to contact them for another issue and spent over 6 hours on hold before giving up. It's really annoying how people love to moan on HN without context.
- nix23 6y agoJust saying, that's NOT the way to do it: >How about @BarclaysUK pay @internetarchive for bandwidth usage and make a donation to @BlackGirlsCode for good measure.
- flumpcakes 6y agoIt screams virtue signalling to me. I'm not even sure where @BlackGirlsCode even comes into it apart from to announce to the world that the author cares about social justice issues.
- ben509 6y agoAnd cares so much that Somebody Else needs to donate to them.
- ohyeshedid 6y agoYou're doing some signaling of your own, intentional or not, when your only contribution to this thread has nothing to do with the overall topic and instead chose to make accusations without any information. I know you're capable of doing better than that.
- wun0ne 6y ago
- deleted 6y ago[deleted]
- gpmcadam 6y ago> Barclays Bank Using Internet Archive as CDN for JavaScript Files The original title is disingenuous, you're assuming they did this on purpose when they very much likely made an error.
- hvdijk 6y agoThe title is accurate and does not make assumptions about intent. Even as an accident, it is still using the Internet Archive as a CDN.
- OJFord 6y agoIt doesn't say 'decided to use' or 'deliberately using', it is 'using', that doesn't connote malintent, that's just the state of things.
- seanwilson 6y ago"using as a CDN" implies a deliberate choice to me. Why not "because it was a convenient way for their developer to include it"? You don't know why. A lot of web developers don't know what CDNs are for too.
- erinaceousjones 6y ago"because it was a convenient way for their developer to include it" implies it was a deliberate choice also, when there's no way in hell someone didn't do this as a mistake lol. PLUS, "using as a CDN" is what the site was literally doing, from a functional standpoint. It was pulling that script from Internet Archive, using their upload bandwidth.
- seanwilson 6y ago> "because it was a convenient way for their developer to include it" implies it was a deliberate choice also I didn't word it well but that was my point. For the same reason, I wouldn't pick the "CDN" headline as it gives a possibly false narrative too. > PLUS, "using as a CDN" is what the site was literally doing, from a functional standpoint. It was pulling that script from Internet Archive, using their upload bandwidth. I'd be fine with "using their bandwidth". I don't see how the Internet Archive having a CDN or not is important to the story, and including this fact in the headline makes it sound important.
- HenryBemis 6y agoAnyone from BarclaysUK internal (IT) audit team reading this? I wonder what your scope is when you run audits on your webs... Also.. that vulnerability scanner and pentester.. what kind of reports do they issue that they don't mention this JS source??
- bArray 6y ago"Move Fast and Break Things" is not the motto you hope to see your bank adopting... I had a problem with Natwest online banking where the "random" character entry was the same each time (first, second and third characters) - which reduces the security incredibly.
- HenryBemis 6y agoIn a French bank 10 years ago, their e-banking system was recording the actual values you typed in, their order in your 6 digit PIN, and your username. The logs were dropped on a share drive so that backup can pick them up. The shared drive was read only to "Everyone". IT fought hard and long on the risk of this whole 'setup'. They agreed when I reconstructed 5 PINs (I stopped at 5, point was made). CTO was cool about this, insisting "what are the odds of this happening?" COO & CEO had a totally different (more sensible) opinion.
- miga 6y agoIt is extremely concerning, because it indicates how quality control is abandoned in search for every lower costs. Embarassing if one considers that most of these issues should be caught by automation before code review even happens. Such a symptom indicates extremely sloppy development process, and low security culture. It would be interesting to use such fragmentary news to correct stock pricing, with respect to current management and processes.
- pldr1234 6y agoPost titles like these always completely overscope the action. Something more accurate would read "A team at Barclays Bank".
- geofft 6y agoWhile that's true in terms of root cause analysis, the browser doesn't see it that way - all content on barclays.co.uk is equally trusted by the browser, so every other team is impacted by this.
- deleted 6y ago[deleted]
- billpg 6y ago"We need to roll-back (JS file) to an earlier version." "Which one?" "The one at (archive URL)." "I'm on it."
- jmvoodoo 6y agoThis reminds me of the time I caught my mortgage lender using javascript loaded directly from a github repo on their mortgage application process. I reported it to them and they didn't understand the problem.
- vmception 6y agothat's pretty funny but what is the problem with that? direct link, possibility of updating, same possibility of 404 as anything else, CDN and caching included
- khalilravanna 6y agoIf it’s straight up linking a non-versioned file (e.g. live file) it implies the owner of that Github repo has direct access to update and run code in client’s browsers. Could start shooting off API requests dumping the contents of cookies/localStorage, set up keylogging, etc. IMO seems like a pretty big security hole.
- robflaherty 6y agoThe Internet Archive rewrites contents of scripts to inject the archive URLs. A better explanation than OP's clickbait is that someone went to the archive to copy/paste misplaced tracking code.
- LordDragonfang 6y agoEveryone assumes that is the case yes. That doesn't make the title factually incorrect, though.
- robflaherty 6y agoBased on the replies to the tweet very few have assumed this is the case and no, “using as a CDN” and “accidentally linked to” are not the same thing.
- giancarlostoro 6y agoInternet Archive as version control, I love it. There's some good comments in there, one guy determined it had been like this for a month, yikes. Peer review anybody? Or maybe they only have one web dev and he's a junior so the seniors dont inspect it as harshly.
- MattGaiser 6y agoI used to work for a bank. I suspect that they found it near impossible to get $50 for a CDN approved.
- pier25 6y agoA bit off topic but... my bank renewed its web app a couple of years ago and still uses jQuery v1. I imagine they invested in auditing it and keep using the audited version... Is this very common?
- jgalt212 6y agoFor sites with a large % of the same people coming back on a daily or weekly basis, there's probably not much to be gained by serving static files from a CDN.
- awadheshv 6y agoputting an executable js file under /content/dam, is pretty much a crime, when you are working with adobe experience manager.
- chaz6 6y agoFrom a security standpoint it is not unsafe to reference resources on an untrusted third party so long as you use subresource integrity. [1] [1] https://www.w3.org/TR/SRI/ https://www.w3.org/TR/SRI/
- gregsadetsky 6y agoOoh, this reminds me that I saw a file being included straight from github.com on flyporter.com (Canadian regional airline) Actually, extremely weirdly, they didn't include the "actual" file (the raw version of it) but ... they included the github page in the <script> tag...?? Go through a checkout on flyporter.com (use dates > Aug 31st as they're resuming service then) and you'll see `<script src="https://github.com/furf/jquery-ui-touch-punch/blob/master/jquery.ui.touch-punch.js"></script>` https://github.com/furf/jquery-ui-touch-punch/blob/master/jq... in the source code which makes no sense (try that URL in your browser!) I contacted everyone I could find on LinkedIn who's working as CTO/CIO/etc. there, AND emailed them but never heard back. (this was 9 months ago... the issue is still there) Isn't this how the British Airways checkout ended up being hacked?