We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
I was linked into an online bank account!
Options
Comments
-
I don't see this as a major security flaw by the bank.
The only reason that the OP could access the link was because some computer illiterate individual managed to copy and paste a live link from her account page, and send it to him. If she had not done that, there would be no problem.
It is a security flaw.
The live link should never have allowed the page to be displayed without checking that the correct session cookies/ip address (or whatever they use for security) was in place. The only person able to view that page should have been the customer - anyone else should have been shown a log in page (or similar)0 -
Perhaps a warning should go out to people not to copy and paste their online bank details?0
-
I've emailed the link of this topic to the lady concerned and asked if she would like to comment.0
-
I’ve just spoken with the IT internet security helpdesk at Nationwide online banking and they said that they think the only way it could be possible to link and gain access to another persons online bank details from another PC in another location is when their session is still open.
However, when I spoke to the lady last night she had ended her session and whilst I was speaking to her I emailed back the link clicked on and accessed her account with and she could not access her own details, yet I still could.
It’s staggering to think that all anyone would have to do is randomly check the link at times when it is most likely that a person may be logged into a session of their online bank account.
Surely this can’t be right?0 -
I’ve just spoken with the IT internet security helpdesk at Nationwide online banking and they said that they think the only way it could be possible to link and gain access to another persons online bank details from another PC in another location is when their session is still open.
Even in this case it should not be possible. As I said before, their system should be creating session cookies on her machine, so even if she was logged on it wouldn't let you access it - as you wouldn't have the cookie.
If what the Nationwide helpdesk say is true then it looks like another hefty fine might be coming Nationwide's way.0 -
I don't know much about how it should be or how it shouldn’t be, all I know is that it is possible as I managed to gain accesses to this online account without any difficulties... in fact you could say I was directed to it!
And if there are fines involved then so they should be for allowing this to happen.0 -
Perhaps some of the more techy people can comment: In the past one reason for such a security hole is that data is cached in intermediate computers and the accidental view is via that cache. Such holes are supposed to be well known and plugged by now. But the real mystery on this one is the fact that https appears to be in use.
Surely with https, unique keys have to be exchanged in order for the page to be decrypted. How can a different PC have got access to the correct key?
It was probably not wise to publish that link as it offers hackers around the world a profile of the link structure for a security hole that is as yet not plugged.0 -
It was probably not wise to publish that link as it offers hackers around the world a profile of the link structure for a security hole that is as yet not plugged.
Agreed, getoblast it might be an idea to edit your earlier post that had the link in it so that the link is removed.0 -
I have now edited the link, but cledor may need to do the same as this member has quoted the details in their post.0
-
Looks like it's checking sessions fine to me, if I try to access it even in a different browser window on the same machine it throws it out, back to the login screen.0
This discussion has been closed.
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.1K Banking & Borrowing
- 253.1K Reduce Debt & Boost Income
- 453.6K Spending & Discounts
- 244.1K Work, Benefits & Business
- 599K Mortgages, Homes & Bills
- 177K Life & Family
- 257.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards