⬆️ ⬇️

Secure SSL / TLS Russian Internet Banking

Today, many people and organizations use the services of Internet banking. Banks periodically conduct security audits of their systems, issue instructions and recommendations for safe operation of the Internet Bank, but users do not always know whether the connection to the Internet Bank they are used to using is well protected.



In this article, we will assess the security of connections to the online services of the TOP 50 Russian banks (by assets) .



The security of user connections to Internet banks is ensured by the use of SSL / TLS protocols. Currently known are “loud” SSL / TLS vulnerabilities, which even were given names and / or logos (Beast, Poodle, Heartbleed, Freak, Logjam). The well-known SSL / TLS vulnerabilities also allow decrypting sessions, intercepting and replacing data transmitted between the user and the server, which for obvious reasons is overlooked by most users.

')

Often the problem lies in the use of outdated and weak cryptoalgorithms with the current level of computing power, and somewhere by the presence of unresolved vulnerabilities of the software used. All this jeopardizes the security of payments made by users in Internet banks.



SSL / TLS security level of Russian banks



To assess the security level of the SSL / TLS configuration on the servers, you can use the free tool “SSL Server Test” from Qualys SSL Labs. Using this tool, independent researcher Troy Hunt made a summary of the appropriate level of security for Australian banks .



In the comments to the article of Troy, you can see links to similar tables for different countries: Lithuania , Denmark , Holland , Holland-2 , Czech Republic , United Kingdom .



I have prepared a similar table (dated 05.22.15) for TOP-50 Russian banks.

In general, the situation is far from ideal. Among the top ten banks, there are four F ratings and this is a bad indicator compared to other countries.



Except for Logjam, quite a lot of time has passed since the discovery of these vulnerabilities and problems of protocols / cryptoalgorithms, which at least indicates the lack of periodic monitoring by many banks of the security of their web resources or of corresponding compensating measures.



Each web resource is assigned a score of "SSL Server Test" with a scale from A to F. A plus and a green color means that there is no corresponding vulnerability / problem. Minus and red color indicate otherwise. Some web resources could not be verified for the reasons given in the table.







The full table (TOP-50) is available at the link: drive.google.com/file/d/0B6tNPM-Uwa5ZNWJkcFRuWjlkYk0/view



Main conclusions





These estimates lose their relevance over time, which may require rechecking using the SSL Server Test. For example, at the time of writing, the assessment of the Telebank web server VTB24 changed from “F” to “A-”, and the vulnerability of Poodle was eliminated on the website of the Rosbank Internet Bank.



Recommendations



The results of the SSL Server Test checks provide recommendations for resolving the identified problems, which can be summarized into the requirements for configuring SSL / TLS on web servers:



Users are also advised to carefully disable SSL 2.0 and SSL 3.0 in the browser settings and enable TLS 1.0, TLS 1.1 and TLS 1.2 support (cautiously, because there were banks supporting only SSL 3.0 from the server). And, of course, when connecting, users should take a closer look at the server certificate and its status in the browser.

Source: https://habr.com/ru/post/258735/



All Articles