Re: Cahoot
Mark Lomas <ukcrypto-Qv/Mekd6ICy057r0afFFoQC/[email protected]> Wed, 6 May 2015 22:02:16 +0100
| Newsgroups | gmane.law.cryptography.uk |
|---|---|
| Message-ID | <CACAki+vMtwwGkW9Z4Ubds72UsCF24znW1MuGnB82ePg0vontZA@mail.gmail.com> |
Francis, The site appears to be vulnerable to several possible attacks. You may be interested in what Qualys thinks of that site. https://www.ssllabs.com/ssltest/analyze.html?d=https%3A%2F%2Fwww.cahoot.com I wouldn't use that site at present. I suspect that part of the problem is that if they fixed the major problem they would break compatibility with older browsers. Mark On 6 May 2015 at 17:41, Francis Davey <[email protected]> wrote: > My apologies if this is a stupid question, but someone might be able to > give me some perspective. > > If I navigate to https://www.cahoot.com, Chrome seems less than happy. It > complains about the cryptographic technology being obsolete and also that > the site does not possess a public key certificate (if I am interpreting > correctly). The icon it displays suggests a fairly qualified acceptance of > the site. > > If I then click on the log in button I am sent to securebank.cahoot.com > for which Chrome has other (but slightly different) complaints. Also: in > the process a window very briefly appears and then vanishes again (which is > always unsettling). > > Is it safe for me to go forward and enter my security details to access my > account, or should I contact the bank and ask them to fix it (or rather to > wait in their customer service queue to be told "no" after much > incomprehension I suspect). > > Thoughts? I am keen not to have my bank account hacked. > > -- > Francis Davey > >