St.George rushes to close Net security breach

By
15 February 2002 10:53 AM
Tags: ebanking, st.george, esecurity, colley, internet security
St.George has moved quickly to close a potential security hole discovered by one of its customers early this week.

The customer contacted ZDNet Australia after discovering that a BPay confirmation receipt e-mailed to him from the bank contained financially compromising details.

"What St.George hasn't thought through is that the BPay reference number used when paying off a credit card is in fact the [customer's] full credit card number," he said.

St.George's Web-based online banking transactions are secured by encryption technology, however, knowledge that the bank is transmitting sensitive information across insecure segments of the Internet has outraged the customer.

"Any server that was used to forward this e-mail on to me now has my credit card number unencrypted for anyone to see," he said.

According to Adam Cook, corporate affairs manager at St.George, the security weakness only affects a small number of customers that request to be notified about regular payments.

"He has the choice of not getting a receipt and had he chosen not to this issue wouldn't have appeared," Cook said.

However, after ZDNet Australia contacted St.George bank to discuss particulars of the security issue, it immediately chose to alter its receipt generation policy.

The bank says that it will now hash the first twelve digits of credit card numbers included in future customer receipts.

Advertisement

Talkback 1 comments

    The response of St George's Ad ...Anonymous -- 15/02/02

    The response of St George's Adam Cook to this very real concern should be identified as a lesson in Career Limiting Comments. What he is effectively saying is this: Thank you Mr. Customer for alerting us to an issue that could have potentially cost us millions in liability suits, however, we really wish you hadn't."

    The customer in question should invoice St George for his time as recent events make it clear St. George are wasting the squillions spent with big brand consultants who fail to spot the most obvious of potential difficulties.

    A disgusting response from Mr. Cook.

    Yours truly,

    A now 'insecure' St George customer.

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured