Stories
Slash Boxes
Comments

SoylentNews is people

posted by mrpg on Sunday September 10 2017, @07:56AM   Printer-friendly
from the world-class-digital-solutions dept.

Submitted via IRC for Bytram

The team behind Scotiabank's Digital Banking Unit isn't impressing some customers, after forgetting to renew the security certificates for their own website.

The DBU was set up last year to sell "world class digital solutions" to electronic banking customers around the world. But Jason Coulls, CTO of food safety testing company Tellspec and a former banking software developer, tipped off The Register that the bank's hipster factory certificates had expired nearly five months ago.

"Tuesday next week is the five month anniversary of the certificate expiring and no one has noticed," he said. "This from a group supposed to showcase how smart the bank's IT people are. The irony is strong in this one."

[...] In 2016 he spotted that the bank's mobile app had some rather unusual features – notably that the programmers had laden the code with f‑bombs. He informed the bank in April and got no response, so let the regulators know. Scotiabank fixed the code within 24 hours.

Source: Scotiabank internet whizzkids screw up their HTTPS security certs


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Sunday September 10 2017, @09:29PM (1 child)

    by Anonymous Coward on Sunday September 10 2017, @09:29PM (#566036)

    IT's good policy. By limiting the number of characters to only a..z and 0..9 you can enforce real security by having the customer use LONGER passwords. The Tr0ub4d0r style passwords are known to be weak anyways.
    Good policy should include a biometric identifier and a 6 to 9 digit PIN
     

  • (Score: 2) by hendrikboom on Monday September 11 2017, @12:11AM

    by hendrikboom (1125) Subscriber Badge on Monday September 11 2017, @12:11AM (#566067) Homepage Journal

    But they use a four-digit PIN.