To say it's secure is a stretch, so say it's completely unsecure is also inaccurate. There were multiple improvements I recommended to the service, but I think I only got 1 or 2 approved. Lets just say this, the front door is secure, but the once you're inside, its not so great. It's not incompetency, its just we (the security guys) are always fighting an uphill battle against change.
Also, I could tell you worst stories about other services all the banks use that would make anyone cringe worst than this, some simple cross bank privilege escalation, oh yeah and the developers said thats not really going to happen... I resigned within a month of that.
As the client, though - we uploaded via SFTP, the connections were IP restricted and the files were PGP encrypted.
I know that doesn't address what happens after we send the bank the file - but that's not our concern, right?
Other story: I've add access to a FTP server which also served as a way to submit JCL at an escalated privilege to an IBM server!
Mostly "enterprise" security is a joke; it depends on the people not the technology.
Yes, I know the difference between FTP and SFTP. In this case the technical details are important: SFTP is effectively a bolt-on file transfer protocol which requires an already established (authenticated) connection. It is most easily used with SSH, but as far as I recall, it could be implemented to work from any protocol that has the concept of a session. (And if my memory serves me right, SILC implemented it as a logical replacement for DCC.)
The other security measures you list also make me feel better. From other posters I have already learned that NACHA transfers have an integrity check file which may be, in some systems, ignored. If the files are indeed PGP encrypted, then that may be less of an issue. The message integrity checks in PGP are certainly robust. :) [Corruption-in-transit becomes a moot point, and the same applies for route hijacking.]
I give you wholehearted thanks, and want to offer an apology for my earlier tone. However, I still have a reason to cringe.
Just let me cringe at the article author instead.
There's also FTPS, which is FTP with TLS. That's closer to "secure FTP," but as @segmondy pointed out, this isn't what they use.
When I read it I thought the author was claiming plain FTP was secure too.
http://www.differencebetween.net/technology/internet/differe...
From wikipedia (http://en.wikipedia.org/wiki/File_Transfer_Protocol#Secure_F...) "The SSH file transfer protocol or secure FTP (SFTP)..."
Multiple google searches also yielded similar language.