Researchers discover online banking security problem

August 10, 2006 A row of Apple computers at a cybercafe

Two researchers working within Cardiff University's School of Computer Science, Professor Antonia J Jones and Joseph R Rabaiotti, together with a third independent researcher Stuart P Goring, have today released details of a problem with HSBC's online banking system. The bank was informed of the issue prior to publication.

The researchers demonstrated (without in any way hacking, or even entering, the system) that the problem they observed, together with the illegal use of a keylogger (a device which records keystrokes and can later play them back), would in principle allow an attacker to gather all the necessary information required to enter any customer account.

HSBC and Cardiff University are now working together to address a number of issues raised by this research.

No illegal access took place during this research. It is generally assumed that to be in a position to prove that a gatekeeper system has a weakness one must have broken the law. However, the researchers were able to demonstrate that this is not the case. In this case they showed that by perfectly proper use of the system (a legal log-in which fails due to a typing error) and by intelligent observation one can logically prove a weakness without even passing the gatekeeper or entering the system. While they were able to do this because of a rather trivial problem, an interesting point of principle has been established and a significant loophole identified.

Professor Jones said: "What is truly amazing about this particular problem is that it apparently has not been illegally exploited for at least two years, during which time all user accounts were in principle open to the access procedure we describe.

"This fact alone raises some serious questions about the wisdom of having any sensitive system online and about online banking in general."

Source: Cardiff University


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 2.8 /5 (22 votes)


August 10, 2006 all stories

Comments: 0

2.8 /5 (22 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Multitasking may be Achilles heel for hepatitis C
    created 13 hours ago | popularity not rated yet | comments 0
  • Visual assistance for cosmic blind spots
    created 18 hours ago | popularity not rated yet | comments 0
  • Diabetics show alarming increase in morbid obesity
    created 21 hours ago | popularity not rated yet | comments 0
  • New cancer target for non-Hodgkin's lymphoma
    created Nov 22, 2009 | popularity not rated yet | comments 0
  • Gene mismatch influences success of bone marrow transplants
    created Nov 22, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Base Isolation Systems in Skyscrapers?
    created 10 hours ago
  • Need to interview a Computer Hardware Engineer for school project
    created 12 hours ago
  • transient heat transfer
    created 19 hours ago
  • Trying to adapt a fuel gage circuit
    created Nov 22, 2009
  • More from Physics Forums - General Engineering

Other News

NREL Uncovers Clean Energy Leaders State by State

NREL Uncovers Clean Energy Leaders State by State

Technology / Energy

created 34 minutes ago | popularity not rated yet | comments 0

(PhysOrg.com) -- That California and Texas still lead the United States in generating renewable energy probably is no surprise. But, NREL's 2009 State of the States report shows that several smaller states ...


Opera logo

Stable Opera 10.10 browser with Unite now available

Technology / Software

created 1hour ago | popularity 5 / 5 (2) | comments 0

(PhysOrg.com) -- The web browser Opera 10.10 has been released as a stable version, and it has a number of new features to enhance the browsing experience, including "Unite", which is a group of applications ...


Key scientist says politics behind stolen e-mails

Technology / Other

created 2 hours ago | popularity not rated yet | comments 3

(AP) -- A leading climate change scientist said hackers breaking into a university's computer server and then posting documents online show the nasty politics of global warming.


Just in time for Black Friday: students turn iPhone into barcode scanner

Just in time for Black Friday: students turn iPhone into barcode scanner

Technology / Software

created 13 hours ago | popularity 4.7 / 5 (3) | comments 0

(PhysOrg.com) -- Comparing prices over the Internet has become a common practice for consumers. Now, just in time for Black Friday, a group of Missouri University of Science and Technology students is putting ...


IBM Researchers Lower Language Barrier With Text Translator

Technology / Computer Sciences

created 15 hours ago | popularity 4.5 / 5 (4) | comments 0

IBM Researchers are helping to break the language barrier with the advent of technology dubbed "n.Fluent" -- smart software that translates text between English and 11 other languages. IBM employees use it to instantaneously ...