R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Lloyds TSB plugs security gap at last

A security hole in Lloyds TSB's internet banking service is finally to be fixed, nearly two months after a customer alerted the bank to the problem.

Andy McCue, Computing, Computing 19 Oct 2000
ADVERTISEMENT

A security hole in Lloyds TSB's internet banking service is finally to be fixed, nearly two months after a customer alerted the bank to the problem.

The hole was discovered in August by prominent IT services analyst Richard Holway, whose company is a Lloyds customer.

"The first thing I did was to telephone the customer care people, all the way up through these stupid lackeys giving me this party line that I could turn it off if I wished and that was up to me," he said.

"They only responded differently when I identified myself as an industry analyst."

Holway finally received a letter from Lloyds TSB dated 13 October saying that after an investigation, the 'AutoSave Password' feature is to be disabled from its service.

The flaw occurs if the AutoSave Password feature on a customer's desktop is enabled. A cookie that stores the Lloyds TSB account username and password allows anyone with access to the PC to enter the account.

"After logging in once, the username and password were automatically remembered. In other words, anyone using my PC had unrestricted access to my account," said Holway.

The flaw is similar to one discovered by Barclays' online customers in August, whereby using a browser's back button after logging out still took customers back into the account, without the need for logging in again.

Barclays said at the time it was working on a process to automatically delete the cache after logging out, but a spokeswoman this week said this would not be done until the next website update, sometime before the end of the year.

"It is something we are developing, and it will go live with our next release of software," she said.

First published in Computing

See also:

Lloyds TSB has scrapped the launch of its UK internet bank, Evolvebank, and will instead concentrate on an online venture with Centrica.  14 Dec 2000
The UK's online banking pioneers have run into some problems. We look at what they are doing to turn around their fortunes.  08 Dec 2000
UK bank Lloyds TSB has denied that it will put back the UK launch of its internet bank following recent security concerns at other online banks.  29 Nov 2000
BondRoger Moore, who played British secret agent James Bond in the 1970s and 1980s, has had his Swiss bank account details published on the web following an error by bankers Credit Suisse.  09 Nov 2000
Online-only banks will have to consider establishing bricks-and-mortar branches if they want to survive as long as their high street competitors, says the ebusiness man at the Chartered Institute of Bankers.  02 Nov 2000
The Royal Bank of Scotland (RBS) is hoping to benefit from users' distrust of spending online by routing ecommerce payment requests directly through its own network.  02 Nov 2000
Forget the European currency debate, electronic money is set to radically change the way we buy goods and services.  20 Oct 2000
Interpol wants to extend its reach and become a global cybercrime police force.  19 Oct 2000
Think-tank the Foundation for Information Policy Research today launched a scathing attack on the UK's internet banks.  11 Oct 2000
Back-office staff at Lloyds TSB had to work frantically this afternoon to smooth out glitches with its internet banking service after a connectivity problem left customers unable to access their accounts.  09 Oct 2000
While the threat caused by recent security beaches at a raft of online banks may have been exaggerated, such organisations need to take the initiative in educating users about security procedures if they are to boost consumer confidence.  03 Oct 2000
Amid much criticism of high street banks' treatment of online bankers, LloydsTSB today announced measures to ensure that its internet customers get the same level of service as its telephone customers.  15 Aug 2000

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
Software / User Interface (UI) Analyst / Engineer - Work for an award winning organisation in Nottingham bursting at the seams with challenging projects and new clients! Working on behalf of an award winning solutions ... more >
| Computer People
Software Implementation Consultant –J2EE/Oracle -£55k –Berkshire Key Skills: Software Implementation, Software Engineering, Post-Sales, J2EE, Web Applications, XML, Oracle, Weblogic, Websphere, JSP, Servlets. My client is a leading Financial Software vendor. Due to increased demand for ... more >
| Computer People
Facebook API Developer –Asp.net/Facebook API –Woking -£35k Key Skills: Asp.net, VB.Net, C#, SQL Server, Facebook API, Social Networking, Web Services, Flash, Ajax. n.b. You must have experience of Facebook APIs or Social Network Application Development ... more >
| Computer People
Web Applications Consultant –Asp.net/C# -Sheffield -£40k Key Skills: .Net 2.0/3.5, Asp.net, C#.Net, SQL Server, Web Applications, Javascript, Ajax, Asp.net, Database Architecture, E-Commerce, Flash, AS3. My client is a leading software services organisation based in central ... more >
More job opportunities