Re: Cahoot

Adrian Midgley <[email protected]> Wed, 06 May 2015 19:36:38 +0000
Newsgroups gmane.law.cryptography.uk
Message-ID <CAN2jWyjw=JVFhuDg4tz_J04AmQLOKtf0oKB0HKcBQV3N34TFFQ@mail.gmail.com>
TLS 1.0 is a bit obsolete and breakable I think.

It isn't any riskier than last month, but is more risky than the year
before last, is how I read it.  The pictures don't really need encrypting,
I think, but the bank should upgrade its secure layer.

On Wed, 6 May 2015 at 17:42 Francis Davey <[email protected]> wrote:

> My apologies if this is a stupid question, but someone might be able to
> give me some perspective.
>
> If I navigate to https://www.cahoot.com, Chrome seems less than happy. It
> complains about the cryptographic technology being obsolete and also that
> the site does not possess a public key certificate (if I am interpreting
> correctly). The icon it displays suggests a fairly qualified acceptance of
> the site.
>
> If I then click on the log in button I am sent to securebank.cahoot.com
> for which Chrome has other (but slightly different) complaints. Also: in
> the process a window very briefly appears and then vanishes again (which is
> always unsettling).
>
> Is it safe for me to go forward and enter my security details to access my
> account, or should I contact the bank and ask them to fix it (or rather to
> wait in their customer service queue to be told "no" after much
> incomprehension I suspect).
>
> Thoughts? I am keen not to have my bank account hacked.
>
>
> --
> Francis Davey
>
>