How not to respond to Heartbleed – CBA, an Australian bank (read the comments)
commbank.com.au
commbank.com.au
> A source close to CBA tells me only CBA's main website was impacted by #Heartbleed. It uses Amazon ELB, which was vulnerable (cont...)
> Main CBA website now has a new certificate dated Friday, April 11 (you can check yourself in your web browser) (cont) #Heartbleed
> Now, considering CBA's main website was vulnerable, according to source, it could've been subject to a man in the middle attack #heartbleed
> An attacker could've sat in between connection on Wi-Fi or on carrier side and seen who visited site. So they only get IPs #heartbleed
> Next question becomes could attacker have used man in middle to change iframe login on main CBA site to collect credentials? #Heartbleed
I guess management instructed them to do this.
I would advise against changing banks over this though. Knowing banks, this is not going to be the only one or even remotely the most serious security bug they ignored. And their competition is just not going to be better. The way security works at banks is threefold : (a) screw inattentive customers (b) watch backend systems for transactions like a hawk (c) call the police over every small problem claiming (correctly) that the financial system could fail if they don't track the culprits down for their current problem.
(For those that dont know, the bank's slogan used to be "Which bank? The Commonwealth Bank."
Also, when there is a rash of stories surrounding a single event, like Heartbleed, HN only needs the most significant or interesting articles. Otherwise it'd be all too easy for the front page to consist of nothing but stories on that one subject—most of which would at best be auxiliary.