3 ms·
The security breaches reported here have been detected by SRI checking bank websites using https://gitlab.com/markalanrichards/access-test/ https://gitlab.com/m
by markarichards 2y ago
The security breaches reported here have been detected by SRI checking bank websites using https://gitlab.com/markalanrichards/access-test/ https://gitlab.com/markalanrichards/access-test/
If anyone wishes to help improve this test suite or fork it for other purposes, please go for it.
Some may trust Google, Microsoft and co, and I'm sure some used to trust Fujitsu.
However, I encourage you to look at the companies in the list against the banks and see how broadly some banks give remote access to various types of third party companies.
Barclay's bank aren't on the list because the test suite didn't find anything. I might have to look into how to move my accounts there.
- mrbishalsaha 2y agoWhat is the solution to these issues? Banking has always been on a very old tech stack.
- markarichards 2y agoThe technical fix to this exact issue is remove or SRI and review third party code. None of these features are a must have requirement for online banking. However, the breadth of this problem indicates the fix is bigger, else this will just pop up again without being noticed and should be tackled from two directions. Technically: in the context of non-repudiation, web browsers are insecure for users. Significant user requests (make a payment, consent to terms, etc) are not stored client side, not signed and were a user to discover an audit log feature there is no distinction between what JS did and what a user did. This should and must change for the web to evolve to protect users. Business: the failure across most of the banking sector suggests that all who should be holding the banks to account (share holders, creditors, regulators, customers, etc) are failing to monitor the banks and given there has been prior warning of this for some (regulators) failing to act. If a third party uses their remote access to hack customers, then I'm sure they will react but that may be too late. When we want security in our physical environment we have watchdogs whose responsibility is not just to react, but to proactively monitor the environment: spot the river has chemicals in it. Banking is significant enough that it probably needs a watchdog tasked with specific objectives regarding information security.