Is it OK to hold credit card numbers in cookies, Santander?
seclists.org
seclists.org
Was considering switching my personal account to Santander, have been looking to move away from Natwest for a while now. Natwest are a dismal failure of a bank to the extent I'm always happy to go out my way and dissuade people from associating with them in any way. I'll be writing Santander off my list for sure now. How on earth can you trust them after seeing this?
For a business who HAS to take security seriously, for a business with a LOT of resources, for a business who hold YOUR cash this is utterly pathetic and inexcusable on their part.
Leaving them might be a good idea for your personal security, unfortunately the UK is a little short of good banks. Would love to see someone shake up banking like Stripe has shaken up online payments.
If this technique is good enough to make sure that you still are who you said you were when you logged in, why is this not good enough for storing other sensitive information? And if it's not good enough for session management, then you're in deep trouble anyway, since someone else can now log in as you and funnel all your money into their Swiss bank account.
Edit: As it turns out, it seems that most cookie-based session data is only stored cryptographically signed, rather than encrypted. The reason for this seems to be that HMAC signing is up to 4X faster than encrypting with Blowfish.
For session management - that's not the only way to handle user information. Often the web server will store a unique hash value and temporarily store the users information on the server with the associated hash. Note: if you're not using sticky sessions on server connects or a distributed server side session object that users info will be lost on reconnect if they hit a different web head.
And no, it is not entirely good enough for session management, which is why when you're on amazon.com or other online sites and you go to your account you are prompted to reenter your password. It is another level of security, but nothing is perfect.
Amazon/ebay/etc would usually do this because they have unencrypted parts of their site you can be directed towards, or unencrypted services, which would expose the cookies in transmission for session information [although I'm pretty sure they've got secure cookies for some parts of their acct mgmt]. Online payment processing force https for cookies and for session management and sets server & client side session timeouts, expire the cookie to prevent any possible future session hijacking, as well as many other procedures to secure their online services. There's a lot to PCI compliance.
edit: as phil said, HMAC is good policy if you store information on users on the client side, but I wouldn't put anything more than user tracking or analytics info in there.
No, that's not how session tracking works. The server uses a cookie to assign you a temporary ID, and then creates a corresponding storage area "server side" which can contain data like credit card numbers.
> Rails 2 introduced a new default session storage, CookieStore. CookieStore saves the session hash directly in a cookie on the client-side. The server retrieves the session hash from the cookie and eliminates the need for a session id. That will greatly increase the speed of the application, but it is a controversial storage option and you have to think about the security implications of it:
If you're using cookie sessions, you should know better than to store sensitive information in the session.
This approach seems strange to me. Why is this approach taken? Why not encrypt everything?
I only really know anything about writing server-side web code from using Play Framework, which provides a "session" object for storing information in the browser using the cookies mechanism. Everything in the session object is kept encrypted on the client in a cookie.
The most common use for the session information is to store a user ID and/or a session ID, but I believe it not uncommon to use this to store additional small bits of information if this will take some load off of your database and/or cache, and to help the server be more RESTful/stateless.
Edit: It turns out that I was not quite correct about Play. Like Rails, it seems to only sign the session cookie, rather than encrypting it. From looking at some benchmarks for the performance of HMAC vs Blowfish, it seems that signing with HMAC can be up to 4X faster than encrypting with Blowfish.
We at Phusion have created an encrypted session store in the past (http://blog.phusion.nl/2010/04/13/announcing-encryptedcookie...). However we've found it to be of limited use (and indeed, it doesn't look like many people use it). If your data is sensitive then you're better off storing it on the server. If your data is not sensitive then encrypting it doesn't help you.
I don't want to think about how many rails user don't know this and send sensitive data to the client.
Edit: wouldn't have written this if I'd seen FooBarWidget's more detailed remarks first.
Ah, yes I see. I just found a benchmark that shows HMAC to be up to four times faster than Blowfish. Well, that explains things.
Ah, another reason to hold REST in contempt...
They could do without a (full) CC number there. Ergo, it's a violation.
It's simple defense in depth, and does reduce the risks - say, if the encryption you thought was secure really isn't, etc.
UK is definitely missing a trustworthy, ethically sound bank though.
http://www.co-operativebank.co.uk/servlet/Satellite/11932063...
As another commenter wrote, their online banking is "primitive", but it's usable.
Particular nits are: - pressing the browser 'back' button triggers an immediate logout - they don't use email for anything except to tell you they've sent you a "secure message" that you have to log in and read - no data export (though there are greasemonkey scripts)
Their customer service I've found to be fine unless you want anything usual, complicated, or to be done in a timely fashion. Much like any large company, really
For example, I can pay in a cheque or withdraw funds over the counter in a Coop Bank branch, but if I want to set up a foreign bank transfer I have to use the an online secure message. When I asked why I was told over and over "smile is an online bank". Which I suppose is true, up to a point.
In lesser annoyances, they make you do a stupid amount of typing to log in, about the only bit of which is actually secure is two randomly selected digits from your 4-digit PIN. All other info is insecure: account number, sort code, first school attended, yada yada yada. All in all they make you enter something like 30 characters spread across 3-5 input boxes and two pages, all for about 6 bits of actual entropy. Unless, of course, you're the sort of person who when asked to tell your bank what your first school was, replies "8EOHzxdO6QnJ".
> Another mutually-owned business, and a clear best buy in the report is the Co-operative Bank. Since 1993 – and in response to the kind of concerns shown above – it has been developing detailed public position statements on who it will and who it will not lend to. These now cover seven human rights areas, five environmental areas, four international development areas and five animal welfare issues. More details are available at www.co-operative.coop/corporate/ethicsinaction/ethicalpolicies. It also uses your money to campaign on key issues of the moment such as unconventional fossil fuels or the decline of bees. Although other banks have come up with similar policy statements, none come close to the Co-operative’s for clarity and ambition. One of the most frequently asked questions at Ethical Consumer is how the Co-operative can be a best buy when its score is much lower than other providers. Our answer is that its relatively low score is the result of it being part of the Co-operative Group which – as a supermarket – is involved in animal farming and other activities which its banking competitors are not. Best Buys are there for us to apply a sense check to our mechanistic, but largely useful, rankings. In other areas, we weight key categories for the sector when choosing the best buys – such as workers' rights and supply chain management for clothing. In banking, having a clear ethical lending policy is a prime concern, which is why the Co-operative tops the pile.
http://atlanticyardsreport.blogspot.com/2012/06/t-shirt-im-s...
Barclays Center is built above a rail yard, which wasn't really doing much for the neighborhood either. All the hate for Barclays Center is completely misguided and the complaints are just the NIMBY types looking for something to whine about.
So I don't understand how anyone could possibly call redeveloping a rail yard into a stadium "shady". Maybe you don't want the foot traffic in your neighborhood, but it's hard to blame Barclays for that.
This is the real issue. Banks can certainly afford to hire qualified engineers; Santander apparently chooses not to.
because their customers chose not to care (at least, until shit hits the fan). A bank (or any conservative organization) will only really react, as it is too slow to become proactive (otherwise, it'd be by definition, no longer conservative! ala, google, facebook etc).
The banking rules should be so that even an immoral Scrooge would see proper security as the cheaper, cost-efficient way compared to screwing their customers with shoddy systems.
If a bank teller violates financial privacy by leaking his customer's transaction lists, it carries criminal penalties in many countries. Why should a manager who intentionally violates banking privacy of thousands of customers face less prosecution?
While security and encryption are definitely not easy (and far less so when you're talking about adhering to PCI-DSS Level 1, which somehow actual banks never seem to do), there are plenty of well-tested libraries that make it significantly easier. Having said that, I'd prefer to see the data stored in plaintext - obviously bad - rather than using easily-broken encryption (short keys, re-used keys, bad key storage, poor algorithm, etc) which looks OK at the surface but provides a serious false sense of security.
What really blows my mind is that Visa and Mastercard never seem to require PCI certification for their issuing banks. Being deep in the industry I realize how many middlemen and layers of misdirection there are with this kind of thing (usually to get around these security requirements), but Visa's diligence process is actually quite thorough - at least in the US. I've been interviewed by PCI auditors, and my experience was that they were actually asking the right questions, and required demonstrations to prove your claims. But for all I know, that varies widely from auditor to auditor.
I find it difficult to imagine someone new entering this market place, other than "people" like Virgin and Tesco with deep pockets to back them.
[1a] http://www.guardian.co.uk/tv-and-radio/tvandradioblog/2012/j...
[1b] http://www.ft.com/cms/s/0/2ba372d4-d80b-11e1-80a8-00144feabd...
They force a 640px popup window that deliberately hides addressbar, so you can't easily check if it's HTTPS.
My browser warns me that their site still has SSL renegotiation vulnerability unpatched.
You are the first and only person to mention the SSL issue so far as I can see, given the quality of your other comments I am inclined to disregard this as you not understanding what you were being told or because you are using a defective browser.
EDIT: I've just logged in, my popup window (Firefox, OS X) does have an address bar. My instinct was correct, you have no clue.
Safari obeys their wishes fully.
Run this in JS console before clicking "Internet Banking"
window.open = function(){console.log(arguments)}
and you'll see: ["/1/2/pib-service", "pib", "toolbar=0,location=0,directories=0,status=1,menubar=0,scrollbars=1,resizable=1,width=780,height=510,top=0,left=0"]
Note "toolbar=0,location=0,menubar=0" which is a quite strong attempt to hide all window chrome.Just as a countering data point, I've been with NatWest for 14 years both for personal and business banking (plus a business credit card) and have had nothing but an excellent experience with them (the only negative I can think of is their online banking goes down for maintenance at 2-3am sometimes for an hour or two).
- I have no idea if it's PCI compliant (I would hazzard a no here)
- Obfuscation is such weak security it should be considered as pretty much worthless
- It's vulnerable to cookie jacking over non HTTPS
- It's vulnerable to theft if you have access to a computer where someone has logged on
There are other ways of doing it, putting it in a short live cookie is one of the worst ways
Say obfuscation = encrypted.
> It's vulnerable to cookie jacking over non HTTPS
That's why you use the secure and httponly flag for the cookie.
> It's vulnerable to theft if you have access to a computer where someone has logged on
Pretty much everything is vulnerable to theft if you have access to a computer where someone else has logged on.
Are there any actual crypto experts reading who'd comment on the dangers of encrypting multiple credit card numbers with the same key? Keep in mind for a single bank the first 4 digits of a credit card will all be one of two choices (their Visa or Mastercard prefix) and for a single branch I think the first 6 digits will be the same for every customers Visa card, which only leaves 9 digits (and the checksum).
Surely a naive approach like:
$encrypted_cookie_text = any_encryption_function($sixteen-digit-cc-number,$global_key);
could be brute forced pretty readily, with a knowledgeable guess at the first 6 digits and an understanding of the checksum algorithm, you're only left with one billion possible numbers. (In fact, I wonder if rainbow tables already exist for this for various values of any_encryption_function()?I don't see how that follows. Storing credit card details on the server is generally a bad thing to do and takes a lot of work to get it to be PCI compliant.
What would be wrong with a different key/salt per user stored on the server, with the credit card number stored in a short-lived, secure, httponly cookie?
Also you didn't address the most important point, PCI compliance.
The method Santander employs is unquestionably a bad way to do things.
My question to them was "what happens if I don't have a mobile phone?" and "What do I do when I am on holiday abroad?" and their responses were (paraphrasing) "You won't be able to use online banking at all in either of those cases."
In order to just get this response I got transferred between like four or five different customer service reps. So I quit my bank of like ten years and when I quit they didn't even care enough to ask my WHY I was quitting.
I almost always have my mobile handy, even abroad, however trying to find & use that darn HSBC dongle every time I want to login or add a payee drives me nuts.
I can certainly understand that it's a bit silly if they don't have a workaround for when you don't have a mobile though.
HSBC works quite well but the login system (with a RSA key) is annoying. I can accept it for actions like transfers but most times I just login to check my balance and transactions, requiring a token seems to much for me. Their design, even if not great, works.
MetroBank seems great from the outside but their system has some issues. First, to login you need your account number, a password and three digits from a 8 digits PIN. After logging in, you can do everything without any other measure. The systems fails to login most times unless you realise you can just click on the link in the error message and logged in you are. A friend told me to use the incognito mode in Chrome and it seems to fix this issue, probably with sessions. Their design is not the best. On the transactionspage you can only see 3 or 4 transactions on the screen at a time (without scrolling, that is).
I am waiting to try Santander (which I will avoid now) and Northern Rock.
Any good experiences?
tl;dr: It took me weeks to register; they refused to expedite new codes to me after a cockup at their end; then when they eventually allowed me to use the service they declined EngineYard and Google apps payments every single month for over a year for "fraud prevention reasons".
In the process of switching… not sure who to yet.
--
Over a year ago I began the process of opening a business bank account with HSBC over the telephone. I'd already completed incorporation of my business and had a provisional acceptance from HSBC via their online application system. Someone was to phone me to ask some cursory questions. Through this conversation it emerged that one of the directors in the business had somehow mistaken his gender when filling out his paperwork, and there was a pause while we waited for Companies House to update their records.
A few days passed, and with the records amended, I ventured into the Fulham Broadway branch of HSBC to complete this process. I explained to the gentleman hovering menacingly near the doors what I needed to do.
"I see. Come with me to The Business Centre," he said solemnly, visibly annoyed that I was wearing yesterday's jeans and no socks.
He deposited me in a chair and assured me that someone would be over to see me shortly. Instantly, another gentleman arrived and inquired as to what I needed. I explained my situation again. Ah, yes, of course. I needed to see a Business Advisor. Did I have an appointment? No, but the office was empty. Ah, yes. Right this way.
The second gentleman led me to a third representative of HSBC's towering capacity for inefficiency. A portly lady squeezed into a too-tight uniform, tucked inside a glass livestock enclosure; she motioned wordlessly to a chair. I ventured that I had a reference number. She pecked away with her exquisite fingernails on the tiny plastic keyboard in front of her and then abruptly stood, and stalked to a printer, rolling and heaving her monstrous body against a uniform visibly weakening at the seams.
"What," she said, looking at her screen and then, for the first time, at me, "did you hope to do today?"
I explained, for the third time, that I needed to conclude the opening of my business account–a process I'd started over the telephone and had been assured I could pick up in a real life, physical, open-now-on-Sundays-thanks-to-Nat-West retail bank. She nodded.
"So all we need really is to physically ID the other directors and we're done."
Nobody had mentioned of this, and one of them was in France.
"Sorry, there's nothing we can do until then."
Could I just drag them into another branch and have them sign something? I could. Splendid.
Thus resolved, Director #1 and I went to the London Bridge branch of HSBC a few days later. He was clutching a disparate range of proofs of his identity, from bank statements to utility bills.
We explained to the 'Customer Host' what we needed to do. He ushered us up some stairs to The Business Centre, a grandiose term for two offices, a deserted reception area and a jolly looking woman stationed in a narrow glass booth.
After being left alone for several minutes, with no more obvious option, I approached her and, for the second time that day and the fifth overall, explained what Josh and I needed to accomplish. She motioned to the first office, which had an open door. "My colleague will be able to help you with that."
We went into the office. The man behind the desk looked up from the screen, creating the illusion of progress.
"Can I help yeh?" He asked, through the indolent, Americanised drawl of an east London schoolboy.
Once more I explained. Keep count.
"Yeahyeah, if you just take a seat, someone else will help you widdat."
Widdat, we sat and chatted about central American politics for a few minutes.
Another man, with a hole where it seemed obvious an earring usually was, walked past us into the office with Widdat in it. He gesticulated in our direction and then cast a wary glance over his shoulder at us.
He approached us and, as you might have expected, asked us what it was we were there to do, in a mumbling approximation of Widdat's voice which might have seemed like a parody if the intellectual bar set by HSBC's staff so far hadn't been so terribly, terribly low.
He explained, in a roundabout way, that he had to do some work and had an appointment coming in ten minutes, but that a lady would be along to see us very soon indeed, and that if she wasn't, he'd take care of us.
We resumed our discussion for what seemed like a very long time–and not because of Josh's constant oversimplification of the complexities of US paternalism. Eventually, Widdat #2 came back out and invited us into his office, muttering about the receptionist not being at her desk.
Instead of asking what we wanted to do, he began to faff about with his computer. I trotted out the most succinct version of my mission to date.
"I started the process of opening a business account with you. I was told I needed to bring in ID for the directors so you could verify them. I have one of them with me, with his ID."
"Right yeh but there's loads of paperwork to do to conclude and everything, it's maybe 25, 30 minutes and I have appointments and that."
We didn't need to do the paperwork. Could he just scan or photocopy the ID and say that he had seen it?
"I can take the ID from you but I can't give it back to you. We have to keep it. Sorry. You can either go into another branch and try to get it done or come back here and see me."
There is a box on the form for HSBC's Business Banking application which asks you how much you intend to deposit into the account. I assume Widdat #2 hadn't seen it, because I wouldn't ordinarily expect to fight someone to give them or their business several tens of thousands of pounds.
I lost interest. I told him it was ludicrous. He didn't disagree. We left. As a last chance I dropped into their deserted Clerkenwell branch and spoke to a business advisor who told me the previous HSBC employees I'd dealt with were all idiots and that it was very simple. We had the account opened in minutes.
Internet banking is very important to me because A) it's 2012, and I don't see a very good reason for highstreet banks to exist and B) I quite like the internet. So we registered for internet banking (which you have to do separately: is there really anyone who doesn't have or use the internet nowadays?). There are three parts of the verification system for this. HSBC posted me a 25-digit activation code, a cryptographic dongle thing, and another shorter code.
Ignoring the fact that a 25-digit activation code = 25! possibilities, which means HSBC have leave to create, I don't know, a BAJILLION online bank accounts, it's a fucking usability nightmare. Typing this stupid code into a computer, it's absolute overkill.
Oh, and they sent me two. Neither of which worked. The second one canceled the first, apparently (although they arrived at the same time), so I had to wait for a third code to be sent out. Nobody can do anything over the phone. You have to wait for the codes to arrive by post. They can only send them to the business address, meaning that you have to be in the office to pick them up. I spoke to a manager on the phone and politely asked what they could do to speed up the process of getting the code to me, since it was their mistake. Nothing at all, as it happened. They couldn't give it out over the phone, they couldn't send it recorded delivery, they couldn't courier it to me. Thanks for making amends for your mistake!
So after entering this 25-digit code, and another code which was a mix of alphanumerics, and picking a unique username, and specifying a password, and using my secure key dongle to generate a unique entry code, I finally get access to online banking about five weeks after the process begins, and I can finally pay our providers who have been patiently waiting (because they understand our pain–they also bank with HSBC).
We're a web business. Every month we pay a bunch of money to our web hosts (the brilliant EngineYard), Google Apps, AWS, etc. WE DO THIS EVERY MONTH. THE SAME AMOUNT OF MONEY. And every month an Indian dude calls me in the middle of my lunch, asks me to confirm a load of security questions, and then asks me to confirm the same transactions that I confirmed with him the month before that, and the month before that and EVERY MONTH SINCE OUR JOURNEY OF PAIN WITH HSBC STARTED.
Meanwhile EngineYard are sending us polite emails saying "Please pay us, your card was declined." The upshot is that we have a bad relationship with our hosts. I'd imagine that HSBC's website is hosted internally, because I know for sure that if it was hosted externally it would GET TURNED OFF ONCE PER MONTH BECAUSE YOUR FRAUD PREVENTION TEAM STOPPED PAYMENT FOR IT.
Three months ago I called HSBC and pointed out that this happens every month. "Ah yes Mr. Spencer, I can see that in your account. I can confirm that we will not phone you again about these transactions." Bull. Shit. Two months ago when they called back I brought it up again, in a slightly more irate manner. "Ah yes Mr. Spencer you need to speak to my colleague about that, hang on." I spoke to his colleague and explained it all AGAIN.
Then they called back a few weeks ago. I explained it all again. Everything was fine, again; no fraud or unusual activity (SO WHY DID YOU CALL?). The card is fine and working, the EngineYard payment will go through, I'm told. I explain to the guy that if I ever have a phone call like this again where I have to explain, for the millionth time, why my business uses American hosting providers, I will change banks and never look back. "No, no Mr. Spencer, I'm trying to help you. You just need to speak to my colleague..."
No, I don't. I've spoken to everyone. Nobody I have ever dealt with at HSBC has any respect for my time. I've repeated myself dozens of times with HSBC to no avail, at every step of the process, to different staff members who can't pass a message along to save me from having to explain it again.
I tell the Indian guy that I'll leave him to resolve it. If he can't then that's fine, we'll switch banks.
He calls back to say it's all resolved. A week later, an email from EngineYard. Card declined.
Cheerio, HSBC.
Her situation is that she visits family in Canada once a year. They won't make a note of her being out of the country if she calls them beforehand. The fraud people then call her if she needs to use her card at unsociable (for Canada) hours and never leave answerphone messages. When they do get her, they require her to answer security questions without identifying themselves first. If she calls them, the person she speaks to has no way of knowning if anyone has been trying to call her for any reason.
They are, in my opinion, the "Worlds worst Bank"
Still, at least unlike NatWest, it didn't take 3 weeks of dealing with different customer services staff to withdraw some cash, and I never got their online banking to work at all... after repeated attempts. Every customer service staff member would make excuses about not being able to help me due to their security restrictions.
I've done this both online and via the phone.
Now I'm not saying this is appropriate or not, I'm just explaining the reference.
+ there is a cultural gap, so sometimes it's hard to communicate about certain things; even though their English is good.
i opened an account online (US) in ... 2006? Transferred some money in - maybe $500? I don't know for certain because... read on.
In 2008 I went to check my balance. Whoops... can't remember my password. Whoops - you tried 3 times and we locked you out. Whoops - our 'internet banking people' aren't available 24/7. 3 days later - whoops - we'll have to sent you something via the postal mail to reset your password (after I'd already answered 5 ID questions on the phone). 7 weeks later... nothing in the post. Call up - resend via post. 6 weeks later - nothing. "Sorry, there's nothing else we can do for you." "Can I have my money back?" "Sorry, we can't confirm who you are".
2010 - Letter from HSBC closing my account for inactivity. So... they know how to get a physical letter to my house. They know who I am. They know how much money I have (and have reported $1 interest to the IRS for 1099 tax forms filed every year), but they can not see fit to actually deal with me as a customer, even after holding my money for 6 years.
My experience with going in to big megabanks is that the 'internet' and 'branch' worlds are two completely separate worlds. I would expect HSBC at a branch to sit me down at a phone to talk to someone on their 800 number, like BoA does when I have a problem there.
If it would have helped, why would HSBC people on the phone not have suggested I go to a branch to resolve things?
HSBC is as you describe - seems pretty secure, but enormously frustrating that you need the dongle just to check balances etc. They'll only provide a single dongle, which is annoying as I want to access my bank from both work and home. The dongle is small enough that you could fit it in a wallet if you wanted to avoid that, but then you're more at risk of losing it.
For Smile, to login you just need your numbers, including 2 digits from a 4-digit PIN selected via drop-down. I guess this is to avoid keylogging but seems a bit odd as a shoulder-surfer could see quite easily. For any new/ unusual payments, the card-reader is needed. They were happy to provide me with a second reader so I can bank from home and work. The reader is too bulky to carry around though, so this is necessary.
The other thing Smile do is heavily plug "Trusteer" software on every login. Fortunately this is not yet mandatory.
On the whole I prefer Smile's approach, though I'd be happier if they could provide a smaller dongle that would be easier to travel with.
I have been utterly thwarted in this plan. The damn thing refuses to stop working.
There's no ridiculous calculator-shaped hardware token. To log in, FD requires 3 characters from your password, and a "secret answer" — effectively, another password. Infuriatingly, they disable the Enter key in the log in form, so a mouse click is necessary.
FD's web UI is stuck firmly in the 90s, with nested menus, cramped screens, and plentiful transitions. Even the log out button redirects to another screen, in order to ask for confirmation.
Finally, FD give you £100 as an incentive to switch, and an additional £100 if you switch back out.
I just need the token if I'm doing 'something' with money
And no Indian accent on phone service
Another bank I know uses your card as a token, requiring you to have your card + a card reader. Better in some aspects, worse in others.
Logging in to HSBC's web UI requires me to "Generate and enter the six digit security code", using my hardware token, which I never have when I need it.
You can hit Tab (will select proceed) and then hit Enter. Much less annoying :)
This is bad in such an amazingly awful way on a "secure" banking website that I'm surprised that this bank even has an IT team, let alone a development team!
How did this not get picked up in QA testing, or even in a cursory audit?!?
Shit like this just shows that being a PCI DSS level 1 certified means absolutely nothing in the real world.
Stupid thing to ask. The only key things a software vendor can really answer is that they don't store credit cards in their database, or if they do then they don't display them to anyone. Everything else (well, almost everything else) can be dealt with on the infrastructure side of the equation.
Creating a racket. PCI is designed to control merchants and extract money, not for security.
If you look at the DSS, it's eminently sensible and in fact if you implement it properly you will most definitely have a secure environment for credit card transactions. If you do not follow it, then you are leaving yourself at significant risk to be being breached and credit card data being stolen.
I'm curious though: what part of the PCI-DSS merely creates "a racket", and what parts "extract money"?
None of these things are being done.
The PAN data -- the cookie -- is encrypted in transit, and if it's encrypted at every point in Santander's network then technically they could be compliant to the letter of the rules. I have no doubt that a company so dumb as to store your PAN data in a cookie is probably breaking a myriad number of PCI-DSS rules, but the card-data-in-cookie may not be one of them.
My password used to include special characters, until a transfer to their new web interface year ago. After they did it,I could not log into my account - it kept telling me that my password was incorrect. So I rang them up,and a lady on the phone asked,if I had any special characters in my password. I said yes - and then she told me to try logging in without them,as the new system does not accept them and they were automatically stripped during the transition to new interface.
At first I was like - ok, at least now I can log into my account. But then it hit me - how the holy fuck could they remove special characters from my password???? The only way they could do that is if they had access to its plaintext, which is completely unacceptable.
I complained to Santander about it,only to receive a letter stating that they appreciate my concerns but their system is safe.
I've got all the correspondence with them if anybody wants to see.
They do use 2-factor authorisation for any new payees, so it's not totally insecure.
On the other hand, their recent 'get cash from the nearest ATM with a code we send to your phone if you've lost your wallet' app was soundly compromised by criminal gangs within days, and the service had to be pulled entirely. They're still advertising it on the homepage, but when you click through it says "We're sorry. Get Cash is not available at the moment. We are currently updating this service to increase the level of security around it."
Reading the blurb for the Get Cash service made a likely compromise route immediately obvious to me: it seems very likely that anyone who's had sight of your debit card could register an arbitrary phone & extract cash from your account, because the only details needed to verify your phone were on the card, or easily guessable (NatWest customer numbers are extremely predictable unfortunately).
If there was anyone obviously better I'd be dumping NatWest, but it's not obvious that any of the other major banks are much of an improvement :(
There's no technical reason, but you may as well just store it as plain text.
Even assuming everyone used all the available Unicode symbols (~110,000 according to Wikipedia) an eight character password would only require calculating 880,000 hashes in order to brute force every character.
Assuming a more realistic A-Za-z0-9, an eight character password is an absolutely pathetic 496 hashes. A 1,024 character password (good luck remembering that) is still a paltry 63,488.
For comparison, hashed as a whole that same A-Za-z0-9 at eight characters is 218,340,105,584,896 (62^8).
Hashing the characters individually changes adding more characters from exponentially increasing the work involved to linearly. It's good as useless.
Going to go email them and tell them I'll be closing my account if they don't start taking their security seriously.
Their security practices for online banking are pathetic in comparison to HSBC. HSBC gave me a one time key dongle which breeds more confidence than the various articles about santander's lax security I've read.
The caller would say "I'm calling from First Direct" and then get confused when I asked for proof of this.
You get called by a computer that asks you to identify yourself by picking a piece of personal information from a list. It might ask for the month and date of your birth, for example, and give you 5 options.
Because there are 365 possible month + date combinations, and yours appears in the list, you know they already have this information so you're safe to confirm it, and they also get to confirm that you are (likely) who they're intending to talk to.
With banking websites I just want to click that link and be sure I am logged out. I don't mind logging in again if I clicked by accident.
1. As explained in the original email XSS attacks now lead CC exposure, very bad
2. If the cookies are not session cookies. It's horrible, then anyone who got access to that computer later can read the cookies and Credit Card. But also don't forget tons of websites still keeps auto-complete enabled!!!! in freaking CC fields.
3. If the cookies are not marked as "secure" (or issued over HTTPS) then it's totally messed up and invalidates PCI etc. directly. Now your credit card transmitted over HTTP.
4. Other than this even though it's rather pointless thing to do, there is not any more direct attack I can think of.
Put it this way, this is not worse than a XSS vulnerability in a website as an XSS can lead more serious issues directly.
The data is not just one base64 chunk, but multiple space separated chunks that base64 -d chokes on after a bit. I am probably missing a step.
Edit: although when you get logged out for inactivity or you click log out it seems to get rid of this cookie.
Ain't capitalism grand?
Now usually there is professional insurance that consulting companies have to purchase for liabilities just like this. If you are consulting firm implementing systems for banks they will require you carry $2 millions/dev of insurance should there be a screw up like this.
Maybe this is the best option because I'm not exactly behind supporting measures to certify or regulate our industry, but I fear bad behavior like this might force it. This is a hack rookie mistake. I'm fully aware of the ramifications of doing something like this, but I'm not immune to mistakes that could result in the same damage. However, a law like this would treat me the same way as these hacks.
The scary part is that the 'alias' id is actually one of the 2 passwords needed to log into the account. So in fact if someone had that and my card number all they would need is the 5 digit numerical code to log in
If you navigate to their homepage - in prime view you'll see a section that says:
"Great ideas come from great conversations"
Under this is feedback from customer - 90% of the feedback is incredibly negative. For example:
""Tell your customers the truth how bad a silver account is. Premium numbers to contact and register, cannot register mobiles for ..."
"Natwest is an embarassment, you have lost a customer for life".
This just sums up how out of touch banks are today with the internet. Don't advertise this sort of feedback! Especially on a homepage! What are they thinking?
Sounds like they're pretty brave to me :-)
EDIT: typo
WhiteHat finds a security vulnerability. They tell the company. But, with banks, it's pretty hard to find the right person to tell. What steps should WhiteHat take to satisfy responsible disclosure? Just a printed letter to banks registered address is enough? (Banks, and everyone really, should have a "please use this address for responsible disclosure" - that would reassure me as a customer that they are taking security seriously).
But then, in England, we have a potential further step with the regulatory bodies. There's the ICO (information commissioner's office) who are overworked and will do nothing about this. And then there are the card companies who will, I'd have thought, be keen to protect their customers from fraud. Would responsible disclosure include a step to involve these third parties, if only to provide some clue pressure to the insecure site?
Back when I used to read the disclosure lists, I'd see people ask "I need a security contact as XYZ Inc." all the time.
http://dalevisser.wordpress.com/2012/07/18/how-to-fix-firefo...
It is correct that these options are in "Privacy". The good thing is that you don't need to worry about tracking cookies because your browser is already tracking you ;)
(I'm half joking / half serious here; this is off-topic anyway)
Santander bought A&L a few years ago when they got into trouble during the credit crunch. Before then, Santander was not trading in the UK.
Given the recent IEEE clear text passwords stored on an FTP server fiasco we need to transition from shock and outrage and switch to resignation and ennui.
I got the XML with an userID field, but that's all. Also the cookie was removed when I logged out. Seems fine to me.
This bank probably didn't believe in storing sensitive information in publically accessible places clearly
/sarcasm
No really, whenever I think there is no display of utter incompetence in software systems programming that will surprise me, here's another big name, ready to make standards sink to a new low. I wonder who and how much they paid for such a nicely done job.
I was able to reproduce the NewUniversalCookie which showed my `username` and `userid`.
I'm a rather young adult (22) and had used Sovereign solely because my parents had used it, but now I'll be happily moving elsewhere.