Bank of America -FAIL #
Posted Thursday 11th September 2008 03:34 GMT
I'm disappointed.
Posted Thursday 11th September 2008 04:37 GMT
If the testing method described in the last para of the article is sound
Posted Thursday 11th September 2008 06:00 GMT
TD Canada Trust banking seems to work fine.
Posted Thursday 11th September 2008 10:30 GMT
A few unsecured cookies, but without the secure ones; you're logged out. 8^)
Posted Thursday 11th September 2008 10:30 GMT
Paris - because it's obviously Phorm-related
Posted Thursday 11th September 2008 10:30 GMT
Assuming validity of the test of course
Posted Thursday 11th September 2008 10:30 GMT
Both allow cookies over "any type of connection"
Posted Thursday 11th September 2008 10:30 GMT
Assuming I followed instructions properly
Posted Thursday 11th September 2008 10:30 GMT
Seems to have passed but I hope someone else tries the test.
Posted Thursday 11th September 2008 10:30 GMT
just the personal side, didn't try the business side.
Posted Thursday 11th September 2008 10:30 GMT
But the banks, and others, say to always logout, so that would surely (?) avoid this situation? Also all banks that I have used automatically log you off if unused for a few minutes.
Anyway, will try a few...
Posted Thursday 11th September 2008 10:30 GMT
Showed no cookies as secure, so didn't erase anything after the first clearing.
Posted Thursday 11th September 2008 10:30 GMT
Only one cookie from the internet banking server, and it's "encrytped connection only".
Posted Thursday 11th September 2008 10:30 GMT
Next, clear all cookies marked as "SECURE" (in Firefox, go to preferences > privacy > show cookies. Delete only the cookies marked as "Encrypted connections only").
What if you visit the site and it doesnt have "marked as SECURE/Encrypted connections only" It has JSESSIONID, WT_FPC, and a couple of Apache... is that good or bad :s
Posted Thursday 11th September 2008 10:30 GMT
Didnt even need to delete any cookies. As soon as I closed the Bank of Scotland tab, and then reopened it, I was logged out.
Posted Thursday 11th September 2008 10:30 GMT
Out of 10 banking an investment sites I've logged in to, only one is even using cookies set to "secure connections only", the rest are all "any connection", so I suspect the problem is extremely widespread.
Posted Thursday 11th September 2008 10:30 GMT
(Assuming I'm following the guidelines correcly - there weren't any cookies marked as secure)
Posted Thursday 11th September 2008 10:30 GMT
This is a man in the middle attack run on a local network, you can do far more than nab cookies to sites.
And it is amusing people don't understand how cookies work, Lou Montulli is probably spinning in his grave (ok he is not dead, well not that I know off), but the mechanism has been in for ages to only transmit over a secured channel.
And you would have thought with all this phorm business, people would have looked into how they were handling their cookies, but a lot of folks use frameworks and obviuosly people who don't know what they are doing have been building those.
It is a little bit of a storm in a teacup, but the fix is so trivial, it is called not hiring cowyboy coders.
Posted Thursday 11th September 2008 10:30 GMT
... it's not only your bank account. ebay.co.uk fails as does ebay.de
Posted Thursday 11th September 2008 10:30 GMT
Couldn't do that on Firefox for some reason, but the cookie manager in Opera says Lloyds TSB's online service cookies are secure.
Posted Thursday 11th September 2008 10:30 GMT
There's one safe way to secure our online bank accounts...don't have them online!
We've managed perfectly well for many years without online accounts.
Think I'll put up with the slight increase in inconvenience by using a bricks and mortar bank account.
Posted Thursday 11th September 2008 10:30 GMT
Konqueror reports all cookies as ... "Secure: No".
Posted Thursday 11th September 2008 10:30 GMT
In FF3, didn't see any encrypted cookies etc, but deleted the many other new ones related to the session, then clicked on a button in the banking window - immediately booted right out...
Anonymous as I don't want anyone to know who I bank with!
Posted Thursday 11th September 2008 10:30 GMT
Just rang them, and was told "we are aware of it" without me even saying what the issue was??
Posted Thursday 11th September 2008 10:30 GMT
Thankfully they get something right!
Posted Thursday 11th September 2008 10:30 GMT
I feel somewhat relieved, but then I remember I'm in court with the gits and it all comes crumbling down again :p
Posted Thursday 11th September 2008 10:30 GMT
Just tried out the student finance site which is full of lots of lovely personal info, and they're as open as.. (on the internet, must keep clean...) a really, really, really wide open thing. *cough*
Posted Thursday 11th September 2008 10:30 GMT
Gnatwest - OK
(they did something right for a change!)
Posted Thursday 11th September 2008 13:49 GMT
TD Ameritrade passes after removing secure cookies from 'ameritrade' and 'tdameritrade' domains.
Posted Thursday 11th September 2008 13:51 GMT
boohoo... no secure cookies. gonna report it now
Posted Thursday 11th September 2008 13:51 GMT
Damn! not a Secure Cookie in sight!
-dZ.
Posted Thursday 11th September 2008 13:51 GMT
If you use an external proxy server you could easily be vulnerable to a Man in the Middle attack, but then if you're accessing sensitive sites via this method, you should step away from your PC.
Of course, there is the additional problem of the ubiquitious "transparent caches" employed by some ISPs, also.
I noticed that at least one person commenting above didn't understand the instructions properly, btw.
Posted Thursday 11th September 2008 13:51 GMT
I see no "secure connection only" cookies after logging in to the co-op bank website, so presumably they're vulnerable.
Curiously Halifax do send one "secure only" cookie, however removing it doesn't cause the session to close so presumably it's one of the "any type of connection" cookies that actually matters.
Pathetic. Let's see how long it takes them all to fix it.
Posted Thursday 11th September 2008 13:51 GMT
That's a clever little hack, goes to show there's no easy way to check your balance on the coffee shop's free wifi connection. Have to admit I didn't know about secure cookies until I read this, I'd start using SSL on all my sites if certs were a whole lot cheaper :-)
Posted Thursday 11th September 2008 13:51 GMT
Flooded me with cookies but none were marked as secure.
Deleting the cookies logged me out.
Posted Thursday 11th September 2008 13:51 GMT
Royal bank of scotland fails for the login but now requires the use of crazy encrypto calc to do any sort of transfers outside of your own accounts.
So, someone could come in and transfer money between my own accounts, but would not be able to set up direct debits, transfer to someone else's account etc.
Not great, but at least its something. Just in time too. This is brand new,
Posted Thursday 11th September 2008 13:51 GMT
So does American Express - pass
Posted Thursday 11th September 2008 13:51 GMT
I see the 2nd comment above, but logging in to https://www.mybank.alliance-leicester.co.uk/index.asp it seems like a PASS, it *always* asks for my PIN anyway, so I'm not sure if that means it was safe already.
Sign up, sign up for The Register's weekly IT security newsletter - click here