ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

HSBC accused of 'scandalous' security glitch

Tom Espiner ZDNet.co.uk

Published: 10 Aug 2006 10:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Banking giant HSBC has been accused of leaving its online accounts exposed for over two years due to a security flaw, according to reports.

The bank left 3.1 million customers exposed due to a defect in how people access their online accounts, The Guardian claimed on Thursday.

Criminals who had harvested banking information using keylogging malware would be able to change account details and transfer money, according to researchers at Cardiff University, who claimed that any account could be broken within nine attempts.

However, full details of the security flaw were not made available. It's understood that it involves a security procedure where a customer is asked to supply randomly chosen letters from within their password.

It's also not clear if the alleged flaw has ever been exploited.

"There are serious issues here," said Professor Antonia Jones, who led the research team. "Banks are in the business of safeguarding your money, and if they tell you that it's safe then you assume that's the case. But as long as this flaw exists, customers are at risk. For banks or institutions that are making huge amounts out of their customers, not to protect them is pretty scandalous," she told The Guardian.

HSBC downplayed the severity of the situation, saying that the supposed flaw had not been exploited by criminals, and that it would be "interested to hear any expert commentary on the security of its personal Internet banking service".

"It is an extremely sophisticated attack that would require a particular and time-consuming focus on one individual victim. It is therefore not likely to be a profitable way for criminals to behave," said HSBC in a statement.

Security expert Richard Clayton of Cambridge University confirmed to ZDNet UK that the vulnerability existed. He believes that it will be "very trivial" to construct a fix and roll it out.

"On the HSBC online banking scheme, after you type in your name and password, you have to provide some characters from a secret phrase. The idea is that even if there is a "keylogger" on your system — and most viruses come with keyloggers as standard these days — it will not know the positions within the phrase you have been asked for," explained Clayton.

"Unfortunately, the Cardiff researchers have realised that there is a way around this — and hence once you have a keylogger on your system then you will not be protected in the way that HSBC hoped," he added.

Alan Phillips, chief executive of security company 7Safe, said there are ways to avoid keystroke loggers stealing PIN numbers and passwords. One method is to use an on-screen keyboard in Windows XP or one provided by the online bank when typing in confidential details.

"There are some ways around keyloggers," Phillips said. "Other banks like Credit Agricole have their own on-screen keyboards. This way you can't get hit by a keystroke log. The other way is with a drop-down box. Barclays do that."

But Graham Cluley, senior technology consultant for antivirus company Sophos, argued keylogging software can beat on-screen keyboards. "Any keylogger is likely to be part of a more complex piece of spyware. That allows the hacker access to everything on your PC, such as monitoring the screen and mouse clicks. Similarly, drop-down boxes are not immune to hackers grabbing information from them."

Silicon.com's Dan Ilett contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
1932 out of 2037 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Voice Engineer - Nortel Meridian Succession, Investment Bank, London

Your expert level Programming experience on Meridian Succession will be complemented with increased exposure to a wealth of Banking Voice platforms. ...

Account Director

The role: Reporting directly to the Managing Director the Account Director will be responsible for: The development of key accounts and the ...

Database Developers ( SQL / T-SQL / SSIS / ETL ) - Chatham Maritime

A production mentality is a must with the ability to understand management information and interpret data analysts requirements beneficial - ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment