Hacker News new | ask | show | jobs
by leethax0r 4836 days ago
It is safe for banking. Have you heard of encryption?
2 comments

Oh, encryption. Why didn't anyone else think of that!

Have you noticed the spate of attacks against SSL lately? BEAST, CRIME, Lucky 13, RC4 in general? https://en.wikipedia.org/wiki/BEAST_%28computer_security%29#... Not profitable for some things, maybe, but definitely worth mounting such an attack for banking info.

Have you noticed that the certificate authority system is totally broken? http://www.theregister.co.uk/2011/04/11/state_of_ssl_analysi... Heard of DigiNotar? Comodo? http://arstechnica.com/security/2011/09/comodo-hacker-i-hack... These aren't hypothetical attacks! Google got MITM'd by Iran https://blog.mozilla.org/security/2011/08/29/fraudulent-goog...

That is assuming your endpoint is secure.

Most people's personal finance is probably safe to do on the Internet because of legal requirements on banks. Small businesses are another matter.