Worthless security claims
troyhunt.com
troyhunt.com
I've been selling my photo-deblurring product on the web for about a year now. I've always processed payments through Stripe, and I've always served the entire web site using SSL. The green padlock is in the address bar.
And yet, back in the early days, I got questions from potential customers several times a month asking if my purchase form was secure.
My solution? I added the text "Payments processed securely" and a generic padlock icon near the credit card info part of the purchase form. In the eight months since then, I haven't had a single person ask me whether or not my site was "secure." Silly, but effective.
While, unlike most of the badges you see on sites, we do not perform recurring or daily scans, we still field requests for this type of seal all the time.
It's our policy to refuse them outright.
Our reasoning for this is twofold: primarily, it provides a false sense of security. As the article rightly points out, having a badge on your site does not make you secure. Sure, maybe it'll find some "low-hanging fruit" that you can fix, but it's not going to address major security concerns.
The second reason is to protect our own reputation. Security scans, at best, provide a snapshot in time--even if it's a recurring snapshot.
Security is a process, not a state; these seals and logos do everything to lull people into forgetting that.
http://lcamtuf.blogspot.com/2012/06/this-page-is-now-certifi...
> 2) 65% of consumers agree that a website displaying the Norton Secured Seal is safe to browse and won’t give them a virus. > 3) 55% of consumers agree that a website displaying the Norton Secured Seal means that the website protects their online privacy.
In other words, customers primarily think that the seal means the website is legit and unlikely to intentionally mess up their computer. When browsing an online store you don't know, that kind of assurance is fairly valuable.
But of course, nothing prevents an illegitimate site from putting those logos up, too.
The gist of it is that just having "256bit AES" tells nothing if it is properly implemented with a robust block mode, proper key generation and if it is signed.
http://www.mcafee.com/us/mcafeesecure/resources/results.html
Everything I've seen points to these logos having a noticeable impact, consumers do look for them. It's an important thing to learn for tech people: you are not your customer.
Edit: I don't mean HN should buy an SSL cert from whomever, you can just copy the image.
The best outcome for most of them is that they've reviewed your business practices and documentation and you conform with some sort of sanity check. Thats kinda what the ISO certifications are about, and a fair amount of what PCI/etc were about. For the most part though, the PCI certification was arbitrary at best, but required if you wanted to process credit cards/etc. There are still plenty of places that pass PCI style audits, but you'd never want to have your credit card number pass through.
The "scan" business is also interesting because it also doesn't really prove much, other than you might have a firewall or some sort of packet filter. Which is good, but not really great, but better than zero :)
(That is, considering they're paying for the Norton thing and not hotlinking the images from Symantec)
We put a padlock image on our payment pages even though it does absolutely nothing for security, but it might help the conversion rate, so there it is.
My bank also had these logos, and despite me having a mitm attack going on, those logos stayed up. I failed to find a single scenario under which they went away!
How is that a security hole? It's actually .Net having a bad default configuration for ASP.Net MVC, a lot of us made this same mistake when doing our first MVC projects. It's not actually exposing anything dangerous (in fact it's hiding the actual error like it should do).
The actual error will be something like this:
http://stackoverflow.com/questions/5967103/a-potentially-dan...
It's .Net disallowing at the root level and if you don't know about it, you can't code for it.
Or am I missing something? Given it's Troy Hunt who's usually quite knowledgeable about this stuff, I'm confused?
Those might not seem a big deal, but you've just provided quite a lot of hints about what the attack surface looks like. Most vulnerability scans will flag up "leakage" of data. IIS also does annoying things by default like "powered by IIS" type HTTP headers (it's not alone in that of course). You'll usually be warned to switch that off because you don't want to make attacks easier than they otherwise would be. Internal error form leakage is just another example.
So that's not what I, or I would think any reasonable developer, would considered even a vague security concern as an experienced developer with exposure to a few different frameworks can often tell the platform, and thus the probable server, by just looking at the HTML.
If it were a serious security concern MS would have patched the header by now! Instead they've added even more with MVC.
So are there any other reasons? Or is Troy just wrong in this instance?
More info: https://asafaweb.com/Scan?Url=telegraphcottages.co.uk#Custom...
But what does that even mean? We've already discussed below that thinking you can hide an ASP.Net MVC site is wishful thinking unless you totally strip out every identifying part of the framework client-side, there are so many ways I can think of, including the ones below, like the js libraries, the CSRF style, the CSS style the validation uses, the wrapping of JSON responses in a object named d, etc. etc.
I even have vague recollections of coming across odd behaviours in IIS when it sends the allow-continue header in certain scenarios that no other webserver does. Though I can't remember the details now so might be wrong there.
I think you should stop classifying this as a vulnerability and just call it what it actually is, a misconfiguration.
I do like asafaweb, nice tool.
So, here, the OP submits a post using the article's original title ("Why I am the world’s greatest lover (and other worthless security claims)"), and you then change the text of the HN link to the article's boring sub-head?
Mods, why do you treat the HN readership like children?
It's more of a conversion/marketing tactic as it's well known that showing such badge on your checkout page increases revenue.