Never mind Heartbleed, Santander are using a cert that expired a year ago
myonlineaccounts2.abbeynational.co.uk
myonlineaccounts2.abbeynational.co.uk
Yes they should have taken MOA offline and removed the DNS entry
But anyhow an expired cert still works just as well as a 'current' cert. It isn't stripped of its crypto-skillz just because an arbitrary date has passed.
Source: being an Abbey retail customer; we were informed of this change.
It doesn't automatically indicate insecurity, but it does indicate that there is a system that isn't being actively maintained properly but is still up.
Qualys SSL lab fails them immediately because they can't even connect via TLS. Opera says I'm connecting with, "RC4_128bit with an MD5 RSA signed key." I'm actually surprised their public modulus is 2048 bits long.
Yeah...