Navy Federal Credit Union Web Site Operating with Security Issue

Navy Federal Credit Union Login FormOnlinebanking users are hopefully aware of the need to login to their banksweb-based system using secure means, such as via a web site protectedusing SSL encryption. (Editor's Note:  "Yeah Right!" SSL encryption is flawed...as is the more supposedly advanced  "EV SSL" encryption. (see my posts on the subject below)
Zusman and Sotirov have also demonstrated that the same flaw can be leveraged to launch browser cache poisoning attacks against EV SSL protected web sites. Both attacks can cause significant exposure and silently expose "encrypted" ...
 

EV SSL Sessions are Safe...Yeah Right! Part Deaux
Jul 14, 2009

They say it is, heck there was the https, then the SSL and after those were all breach they came up with EV SSL.Well, what's next? How about just realizing that hackers will get pastany security you can come up with...unless it's done ...
 
Jul 08, 2009
 
Extended Validation (EV) SSL is considered by all to be more secure than SSL: Calls for widespread EV SSL implementation are on the rise as SSLExtended Validation Secure ... threats increase. Two years after its rollout, the "more secure"
Every legitimate bank offers suchprotection, normally disallowing customers the ability to login viaunsecure means. But not every bank appears to be conscious of themyriad of potential security risks associated with their site. Navy Federal Credit Unionis plagued by a huge security vulnerability on their web site and ispossibly the easiest bank on which to perform a phishing expedition
.
Updated – August 12, 2009: Added correspondencefrom the RSA Anti Fraud Command Centre and SliceHost Support regardinga take-down notice and trademark infringement claim. This littlearticle has apparently generated some interest and visibility by anNFCU “security” contractor.

Updated – August 15, 2009
: The sagaappears to have come to an end as the RSA AFCC responds to SliceHostafter TechMiso stipulates the content was not infringing. The attackdogs are ostensibly caged for now.

Read the full story …

Reblog this post [with Zemanta]

Posted by John B. Frank Monday, August 17, 2009

0 comments

Payments Industry News Blog

Search the PIN Debit Blog by Subject

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers