5 ms·
> Content editors should not be able to add arbitrary code to a bank's website unless it undergoes review from someone who understands web security. Hardly any
by wolfgke 6y ago
> Content editors should not be able to add arbitrary code to a bank's website unless it undergoes review from someone who understands web security.
Hardly anybody really understands web security.
- HenryBemis 6y agoI've audited e-banking websites before. Every file, every element needs to be accounted for. This is beyond "an honest mistake" and it should have been caught by any of the (many) scans the bank orders for its websites. And the scan/report should have caught that. Who does their scans/reports? What is the scope of these scans? Who reviews these reports? This is not about content. Content is "make a new page with that template and add a photo and the new text about XYZ product". Not a new functionality/code. I wonder who signed this off prior to.release and what does their wiki/Jira mentions. Edit: e-banking and other banks websites/online presence(s). Edit2/rant: I have been the go-to audit/sec/compliance guy for more than a decade. It amazes me in this forum that there are very few discussions/POVs on the audit/security element. In most cases (like this one), an experienced auditor would have picked this up in 20mins. If only Barclays (in this case) bothered to escape the fixed-10 years old checklist/audit program these would never have happened.
- chrisan 6y ago> This is beyond "an honest mistake" and it should have been caught by any of the (many) scans the bank orders for its websites. And the scan/report should have caught that. Who does their scans/reports? What is the scope of these scans? Who reviews these reports? It is partially baffling at least. We had to do a standalone website ad campaign for a bank (same level/recognition as barclays) once, some kind of rewards program where all you could do was browse what was possible to redeem your points for. No accounts, no cart, no integration whatsoever, it was basically a static site (with some user interactivity). We'd get scanned constantly and were always made aware of mistakes or issues, one of them being 3rd party resources. On the other hand, I wasn't too impressed with their security scanning. Two issues had come up that made me dubious of what all good this actually did. First was some kind of ssh vulnerability. We were using an older (but still supported) amazon linux ami. The ssh was actually patched but the version did not match what they wanted in the security tool's version. We had to get them to talk with AWS to ensure it was an actual patched version of ssh and the security scanning tool just wasnt accepting it as valid. The other was some kind of javascript vulnerability in a library. There was an open cve on the library, an open issue on github, with comments on how to fix it, but the library itself wasn't being updated. I manually patched it and named it version x.y.z-patched or something. Report comes back that its still a vulnerability. I'm like what? Impossible I just patched it and tested it myself. The CVE no longer works. So I just renamed it to x-patched.y.z and poof, we pass validation. This was my version time with vulnerability testing and I was kinda let down by it. I assumed they had people (or tools) actually trying to exploit the site like how I tested the patch for the javascript library prevented the CVE from working instead of just looking for version numbers and comparing to a list of known issues.
- ownagefool 6y agoThis doesn't make the scanning dubious; it's just shows it's limitations of simply being a check of known vulnerabilities. If you hadn't scanned, would you have fixed the CVE at all?
- VBprogrammer 6y agoI get what you are saying but I also think the parent has a point, if it was that easy to do an end run around the scanning (accidentally or otherwise) then it's not really suitable for auditing external parties. For your internal teams you can probably have some level of confidence they will fix it in good faith.
- ownagefool 6y agoYeah it's complicated. Scanning is useful to automate a "thing" but your audit is multifaceted and should probably require peer review (pull/merge requests). In simple terms, scanning should _hopefully_ help a dev who wants to do the right thing, but it won't help a malicious dev, so you're gonna need something else. Peer review, least privileged access, protective monitoring, etc.