{"id":155805,"date":"2016-02-24T13:35:10","date_gmt":"2016-02-24T11:35:10","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=155805"},"modified":"2016-02-24T13:39:12","modified_gmt":"2016-02-24T11:39:12","slug":"absa-internet-banking-security-concerns","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/155805-absa-internet-banking-security-concerns.html","title":{"rendered":"Absa Internet banking security concerns"},"content":{"rendered":"<p>Following the disclosure of the the OpenSSL Heartbleed bug in April 2014, numerous tools appeared online to test whether websites were vulnerable to it.<\/p>\n<p>Qualys SSL Labs&#8217; server test was one such tool, and at the time <a href=\"http:\/\/mybroadband.co.za\/news\/security\/100676-sa-banks-networks-online-shops-ssl-security-rankings.html\"><strong>we used it to check the strength of the security<\/strong><\/a>\u00a0of many South African websites.<\/p>\n<p>Absa\u2019s Internet banking site scored a B back then. This has <strong><a href=\"https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=ib.absa.co.za\" target=\"_blank\">improved<\/a><\/strong> to an A-.<\/p>\n<p>However, a MyBroadband reader dug around on Absa\u2019s site and discovered that when you enter your account number and PIN and click next, your credentials are sent to a different server: vs1.absa.co.za.<\/p>\n<p>For this domain, the results of the SSL Labs test look different.<\/p>\n<p>Not only does SSL Labs report that this Absa domain is still vulnerable to the POODLE attack disclosed in 2014, it also supports insecure negotiation.<\/p>\n<p>However, Absa has said that clients need not be alarmed by the SSL Labs test results.<\/p>\n<p>\u201cWe are aware of the issues the reader has raised and we\u2019re confident that they do not pose a risk to customers,\u201d said Absa.<\/p>\n<p>The bank said it gets independent vendors to perform penetration tests against the platform regularly.<\/p>\n<p>\u201cVulnerabilities identified in such tests and which reach us through other channels, such as reports from the security community, are evaluated for exploitability and impact on the customer, and are addressed with priority where it is found the vulnerabilities pose a risk.\u201d<\/p>\n<h3 id=\"related\">More security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/100676-sa-banks-networks-online-shops-ssl-security-rankings.html\"><strong>SA banks, networks, online shops SSL security rankings<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/hosting-storage\/155402-critical-security-bug-hits-south-african-websites.html\"><strong>Critical security bug hits South African websites<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/155272-paying-your-tv-licence-online-watch-out-for-this-security-flaw.html\"><strong>Paying your TV licence online? Watch out for this security flaw<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/155302-anonymous-nailed-3392-sites-on-webafrica-this-is-how-they-got-in.html\"><strong>Anonymous nailed 3,392 sites on Webafrica \u2013 this is how they got in<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/155278-anonymous-hacks-and-leaks-south-african-government-data.html\"><strong>Anonymous hacks and leaks South African government data<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Absa has stated that clients are not at risk from the security flaws Qualys SSL Labs lists for one of the bank&#8217;s domains.<\/p>\n","protected":false},"author":15,"featured_media":145205,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[2186,35,27136,7913,20787,35639],"class_list":["post-155805","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-absa","tag-headline","tag-poodle","tag-qualys-security-labs","tag-secure-socket-layer-ssl","tag-ssl-labs"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/155805"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=155805"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/155805\/revisions"}],"predecessor-version":[{"id":155811,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/155805\/revisions\/155811"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/145205"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=155805"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=155805"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=155805"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}