TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bank harrasses user because he tweeted screenshot of their SSL certificate

163 pointsby passepartoutabout 10 years ago

10 comments

spectre256about 10 years ago
It&#x27;s dangerously close to a passive-agressive pitchfork mob, but I propose that many people start tweeting to greek banks regarding their SSL configurations. The National Greek Bank, for example, scores an F on the SSL Labs Test because they are using TLS 1.0 and are vulnerable to POODLE:<p><a href="https://www.ssllabs.com/ssltest/analyze.html?d=nbg.gr" rel="nofollow">https:&#x2F;&#x2F;www.ssllabs.com&#x2F;ssltest&#x2F;analyze.html?d=nbg.gr</a><p>their twitter account is: <a href="https://twitter.com/ibanknbg" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;ibanknbg</a><p>EDIT: The most effective outreach will be friendly and respectful, if anyone chooses to do this. Also, all the other major greek banks score poorly:<p>Piraeus Bank Score: F! <a href="https://www.ssllabs.com/ssltest/analyze.html?d=www.piraeusbank.gr&amp;s=199.83.134.245" rel="nofollow">https:&#x2F;&#x2F;www.ssllabs.com&#x2F;ssltest&#x2F;analyze.html?d=www.piraeusba...</a> twitter:<a href="https://twitter.com/skepsouprasina" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;skepsouprasina</a><p>Alpha Bank: B <a href="https://www.ssllabs.com/ssltest/analyze.html?d=www.alpha.gr&amp;s=193.193.185.72" rel="nofollow">https:&#x2F;&#x2F;www.ssllabs.com&#x2F;ssltest&#x2F;analyze.html?d=www.alpha.gr&amp;...</a> twitter: <a href="https://twitter.com/alpha_bank" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;alpha_bank</a><p>Eurobank: Score: F! <a href="https://www.ssllabs.com/ssltest/analyze.html?d=eurobank.gr" rel="nofollow">https:&#x2F;&#x2F;www.ssllabs.com&#x2F;ssltest&#x2F;analyze.html?d=eurobank.gr</a> twitter:<a href="https://twitter.com/Eurobank_Group" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;Eurobank_Group</a>
评论 #9198493 未加载
评论 #9198181 未加载
评论 #9199289 未加载
评论 #9198459 未加载
评论 #9199003 未加载
madaxe_againabout 10 years ago
You&#x27;re all talking about the bank&#x27;s response - but I actually think his employer&#x27;s reaction was worse.<p>Threatening to fire him for a tweet from a personal account? What Kafkaesque bullshit is this? Frankly, I&#x27;d be taking them to a tribunal - and I&#x27;m an employer. The idea of pulling that kind of shit on anyone fills me with disgust.
评论 #9199628 未加载
simonmalesabout 10 years ago
I really hope the bank gets a lot of bad publicity out of this.<p>Marketing opportunity for other banks to jump on the bandwagon and share there public keys on social media.
评论 #9199708 未加载
评论 #9199402 未加载
评论 #9198173 未加载
评论 #9199165 未加载
WizKidabout 10 years ago
A friend went through the Swedish banks and ranked them (post in Swedish <a href="https://friendlybit.com/security/hur-sakra-ar-svenska-banker/" rel="nofollow">https:&#x2F;&#x2F;friendlybit.com&#x2F;security&#x2F;hur-sakra-ar-svenska-banker...</a> and Google translate <a href="https://translate.google.com/translate?sl=auto&amp;tl=en&amp;js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;u=https%3A%2F%2Ffriendlybit.com%2Fsecurity%2Fhur-sakra-ar-svenska-banker%2F&amp;edit-text=" rel="nofollow">https:&#x2F;&#x2F;translate.google.com&#x2F;translate?sl=auto&amp;tl=en&amp;js=y&amp;pr...</a> )<p>The response he got was the banks starting fixed their problems. He had one group of banks that he classified as you should stay away from. All those banks fixed things so they are not longer in that category
评论 #9198918 未加载
some_furryabout 10 years ago
&gt; Firefox suggests some security concerns in the firefox console on both sites. Especially about how weak is sha1 algorithm. Both sites have a 2048 public cert, the one use TLS1.2 but the other TLS1.0 and one of them have a 128bit private key size. You all understand that from a security point of view, these things arent best practices. Especially if you are a bank !<p>128 bits for symmetric key ciphers is actually fine. Especially with AES.<p>TLS1.0 and SHA1 certificates? I&#x27;d expect better.<p>&gt; The second bank has also a cross site javascript script and that’s for sure not a best practice. Again that’s not a security hole. They just pull a javascript from their official web page (although a different url&#x2F;domain from their web banking).<p>Yay, watering hole attack vectors.
评论 #9198214 未加载
评论 #9198496 未加载
jvehentabout 10 years ago
Along the same line, there are currently around 4,000 sites in Alexa&#x27;s top 1 million that only support RC4. Nothing else.<p>Some of these sites have large user bases too, and it&#x27;s making it hard to disable RC4 in Firefox. <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=1138101" rel="nofollow">https:&#x2F;&#x2F;bugzilla.mozilla.org&#x2F;show_bug.cgi?id=1138101</a>
评论 #9199089 未加载
andrewriceabout 10 years ago
Site seems to be down.
评论 #9198085 未加载
评论 #9198157 未加载
sandstromabout 10 years ago
Someone created a site called https-watch, to list banks, government sites etc. that aren&#x27;t using HTTPS properly but should be.<p>It has a built-in &#x27;tweet to this entity&#x27; link, similar to what this guy did by himself.<p>Perhaps someone can open a Greek sub-section on the site, with links to these banks.<p><a href="https://httpswatch.com/global" rel="nofollow">https:&#x2F;&#x2F;httpswatch.com&#x2F;global</a>
woahabout 10 years ago
Which bank was it?
评论 #9198927 未加载
评论 #9198309 未加载
VieElmabout 10 years ago
I support the author and what the bank did is just absolutely wrong and outrageous, but I just want to clarify that this is not a freedom of speech issue. Freedom of speech refers to government restrictions on limiting the right to voice your opinion. The government wasn&#x27;t involved and he didn&#x27;t legally have to remove the tweet (but I would have removed the tweet as well if it threatened my job). I totally support the author, but this is not a freedom of speech problem. Sometimes we limit what we say because there can be negative consequences that have nothing to do with the government.<p>I recommend creating an anonymous Twitter account to remove negative pressure that can affect employment.
评论 #9198360 未加载
评论 #9198240 未加载
评论 #9199149 未加载
评论 #9198405 未加载