Bitcoin Forum
November 16, 2024, 10:00:59 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Good luck reporting any security vulnerabilities to your UK Bank. My Experience  (Read 1644 times)
RxCrypto (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 08, 2014, 09:44:12 PM
 #1

This morning as you might be aware the OpenSSL bug called Heartbeat was announced. Here is my and others experience with HSBC, Barclays and Nationwide.

HSBC

I called HSBC, this my personal bank. They seemed to pretend like they knew what I was talking about. I asked to be transferred to some security report line or be given an email. HSBC informed me that everything is fine and as far as they were aware, I had nothing to worry about. I knew that they probably weren't lying considering how long I was on the line. Plus their site and mobile apps don't seem to be running on OpenSSl so I trusted them (Yes, I trusted a Bank.)

Barclays

My parents are on Barclays and use their internet service but I was also more personally invested in this. As many of you, I use the application called pingit. According to this page, http://www.barclays.co.uk/Mobile/BarclaysPingitSoftwaretermsandconditions/P1242607867693 the app uses OpenSSl. Due this being a mobile application it's hard to find out if Heartbleed is being used.

I decided to call them so I can report the possible vulnerability. My experience can be summed up in three points.  
  • 1) They have no security report line or email
  • 2) Customer service didn't seem to care
  • 3) Even calling head office and reporting the issue they were unable to transfer me to a security team or didn't seem to be worried

After 40mins and 5GBP spent on calls later, I was told the internet fraud email. This a internet fraud prevention email not a security report bug email.  Either way, I wrote to them:

Quote
This morning a serious security flaw was announced in the OpenSSl certification.  This certification is currently being used by your mobile banking app pingit as outlined on your site here: http://www.barclays.co.uk/Mobile/BarclaysPingitSoftwaretermsandconditions/P1242607867693 . The security Vulnerability in question is called HeartBleed (http://www.bbc.co.uk/news/technology-26935905) . While doing some testing on my personal servers and trying to confirm the bug, as an outsider attacker on my personal servers I was able to get access to:  user ids, passwords, documents and any communication between users.  In banking this could lead to a lot more problems so please investigate if any of your software especially PingIt is affected as soon as possible.

This turned out no results and I still haven't received an email back. I assumed that this was useless and tried to reach them on twitter. That also turned out no reply.

Nationwide

This not my personal experience and I only know small details of the experience. I was in talks with someone on twitter about this problem, their bank is Nationwide. They were unable to got any results.


Conclusion

I find it amusing how every single Bitcoin exchange has dedicated security emails and even phone lines but massive Banks such as HSBC and Barclays don't. It might be amusing for now but in the long term this a serious problem that has to be addressed.
bitsmichel
Sr. Member
****
Offline Offline

Activity: 518
Merit: 250



View Profile
April 08, 2014, 10:18:16 PM
 #2

Banks are like MtGox  Smiley

RxCrypto (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 08, 2014, 10:20:44 PM
 #3

Banks are like MtGox  Smiley

Probably the best analogy for my experience, I'v heard so far.
kuroman
Hero Member
*****
Offline Offline

Activity: 588
Merit: 501


View Profile
April 09, 2014, 02:15:17 AM
 #4

Don't waste your time reporting to them, the only thing you should be ready for, is that if you lose money be ready to sue the heck out of them since it's their fault for not being as secure as they claim to be
Teka
Hero Member
*****
Offline Offline

Activity: 840
Merit: 1000



View Profile
April 09, 2014, 12:12:44 PM
 #5

I had pretty much the exact same experience with Barclays, tried twitter and they completely ignored me.
Lethn
Legendary
*
Offline Offline

Activity: 1540
Merit: 1000



View Profile WWW
April 09, 2014, 12:30:23 PM
 #6

If you're serious about this, it may be a good idea to report it to someone in government so they can have an excuse to go yell and lecture the banks, not much but it would get attention, you could even show the responses of the banks.
act now
Member
**
Offline Offline

Activity: 166
Merit: 15


View Profile
April 09, 2014, 01:44:15 PM
 #7

If you're serious about this, it may be a good idea to report it to someone in government so they can have an excuse to go yell and lecture the banks, not much but it would get attention, you could even show the responses of the banks.
Nah it's just a waste of time in my opinion. No one in the government is interested in minor problems of some random guy.
Teka
Hero Member
*****
Offline Offline

Activity: 840
Merit: 1000



View Profile
April 09, 2014, 02:07:03 PM
 #8

If you're serious about this, it may be a good idea to report it to someone in government so they can have an excuse to go yell and lecture the banks, not much but it would get attention, you could even show the responses of the banks.
Nah it's just a waste of time in my opinion. No one in the government is interested in minor problems of some random guy.

Plus let's be honest at the end of the day we all know who pays their bills.
Bitcoin Fiction
Member
**
Offline Offline

Activity: 138
Merit: 10


View Profile
April 09, 2014, 02:11:11 PM
 #9

If you're serious about this, it may be a good idea to report it to someone in government so they can have an excuse to go yell and lecture the banks, not much but it would get attention, you could even show the responses of the banks.
Nah it's just a waste of time in my opinion. No one in the government is interested in minor problems of some random guy.

Plus let's be honest at the end of the day we all know who pays their bills.
Indeed. It's futile. Smiley

hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3990
Merit: 2717


Join the world-leading crypto sportsbook NOW!


View Profile
April 09, 2014, 02:15:46 PM
 #10

Don't waste your time reporting to them, the only thing you should be ready for, is that if you lose money be ready to sue the heck out of them since it's their fault for not being as secure as they claim to be


If you lose money due to fraud ot security problems on their end they'll give you it back. Can't say the same for bitcoins though.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
RxCrypto (OP)
Newbie
*
Offline Offline

Activity: 4
Merit: 0


View Profile
April 09, 2014, 02:29:57 PM
 #11

Don't waste your time reporting to them, the only thing you should be ready for, is that if you lose money be ready to sue the heck out of them since it's their fault for not being as secure as they claim to be


If you lose money due to fraud ot security problems on their end they'll give you it back. Can't say the same for bitcoins though.

That's true but it also takes time plus there really isn't an excuse for not having security emails. Another thing you have to consider is that Banks also store your details and most have scans of your passport so security vulnerabilities could lead to identity fraud which is a serious problem.
hilariousandco
Global Moderator
Legendary
*
Offline Offline

Activity: 3990
Merit: 2717


Join the world-leading crypto sportsbook NOW!


View Profile
April 09, 2014, 03:25:49 PM
 #12

Don't waste your time reporting to them, the only thing you should be ready for, is that if you lose money be ready to sue the heck out of them since it's their fault for not being as secure as they claim to be


If you lose money due to fraud ot security problems on their end they'll give you it back. Can't say the same for bitcoins though.

That's true but it also takes time plus there really isn't an excuse for not having security emails. Another thing you have to consider is that Banks also store your details and most have scans of your passport so security vulnerabilities could lead to identity fraud which is a serious problem.

No bank I've ever banked with has held any photo ID, but identity fraud is always an issue with any place you give your details.

  ▄▄███████▄███████▄▄▄
 █████████████
▀▀▀▀▀▀████▄▄
███████████████
       ▀▀███▄
███████████████
          ▀███
 █████████████
             ███
███████████▀▀               ███
███                         ███
███                         ███
 ███                       ███
  ███▄                   ▄███
   ▀███▄▄             ▄▄███▀
     ▀▀████▄▄▄▄▄▄▄▄▄████▀▀
         ▀▀▀███████▀▀▀
░░░████▄▄▄▄
░▄▄░
▄▄███████▄▀█████▄▄
██▄████▌▐█▌█████▄██
████▀▄▄▄▌███░▄▄▄▀████
██████▄▄▄█▄▄▄██████
█░███████░▐█▌░███████░█
▀▀██▀░██░▐█▌░██░▀██▀▀
▄▄▄░█▀░█░██░▐█▌░██░█░▀█░▄▄▄
██▀░░░░▀██░▐█▌░██▀░░░░▀██
▀██
█████▄███▀▀██▀▀███▄███████▀
▀███████████████████████▀
▀▀▀▀███████████▀▀▀▀
█████████████LEADING CRYPTO SPORTSBOOK & CASINO█████████████
MULTI
CURRENCY
1500+
CASINO GAMES
CRYPTO EXCLUSIVE
CLUBHOUSE
FAST & SECURE
PAYMENTS
.
..PLAY NOW!..
kuroman
Hero Member
*****
Offline Offline

Activity: 588
Merit: 501


View Profile
April 09, 2014, 03:34:46 PM
 #13

Don't waste your time reporting to them, the only thing you should be ready for, is that if you lose money be ready to sue the heck out of them since it's their fault for not being as secure as they claim to be


If you lose money due to fraud ot security problems on their end they'll give you it back. Can't say the same for bitcoins though.

The blockchain in principale is safe, and you use your wallet on your indiscretion, You might be refering to exchanges but that's a regulation problem.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!