Published 2004-10-16 10:11:17

This week saw an amazing jump forward in internet banking security in Hong Kong, HSBC's security rating jumped from bungling idoits to have trained chimpanzees. Kind of reminds me of Microsofts attitude to security. Features first, until something starts going wrong.

HSBC Hong Kong, probably overflowing with compaints from people who had been caught out with phishing attacks, and transfered their life savings to some nice guy in nigeria. Finally put a stop to transfers outside of registered accounts..

I had quite a long conversation 6 months ago, when I though It might be quite usefull to monitor my bank account on-line.

"So can I sign up for a read only account?"
"Sorry we dont offer that facility..."

Well duh, yeah, they only offered the "give your money to compete strangers" type of facility..

Of course it's pretty damn obvious that to do internet banking properly, any kind of transaction should be confirmed via SMS or simple automated phone calls.. But since the banks only wanted to say 'we have internet banking', rather than actually doing it properly. We end up with a plug and prey banking system.

I bumped into an 'unnamed source' involved with IT at HSBC, while he didnt know much about the internet farce there, he did reveal something even worse.

HSBC HQ in London have decided to go with Windows XP for their next generation ATM's. Well, in kind of nice to know that hong kong hasnt got a monopoly on stupid decisisions.. They did have a few redeaming facts, it was being written in Java.. (I bet it would quicker/simpler/more reliable in PHP/Python.. - but suit's and smart IT dont always go together).. And they did retain the option to use Linux. (although their major suppliers appear to have been slacking on delivering that option)..

Maybe it's time to start moving the savings to a safer bank.. like sticking it under my mattress :)



Mentioned By:
google.com : hsbc security device (144 referals)
google.com : april (81 referals)
google.com : december (51 referals)
google.com : how hsbc security device works (38 referals)
google.com : HSBC Security Device how it works (28 referals)
google.com : How safe is HSBC (11 referals)
google.com : hsbc security device problem (9 referals)
google.com : "how safe is hsbc" (8 referals)
google.com : how the hsbc security device works (6 referals)
google.com : php for banks (6 referals)
google.com : banks that are safe (5 referals)
google.com : how does the hsbc security device work (5 referals)
google.com : how hsbc security device works? (5 referals)
google.com : hsbc "security device" (5 referals)
google.com : ATM bsod (4 referals)
google.com : hsbc security device how work (4 referals)
google.com : hsbc security problems (4 referals)
google.com : are banks really safe? (3 referals)
google.com : ATM NCR photos (3 referals)
google.com : atm phishing device pictures (3 referals)

Comments

It 's funny to see ATM bank cash because of Windows. In my country, Vietnam, bank use ATMs from NCR, running outdated Windows NT workstation 4.0. I do not know why NCR clain they are 4th generation but have no concept of OS for embed device. I will post picture of ATM clash/restart for anyone interested :-)
#0 - Mike NGuyen ( Link) on 2004-10-16 12:47:00 Delete Comment
In Sweden many ATM:s use windows. We laughed in the beginning, especially when "blue screen of death" started to appear. But the fact is that after the initial problems they have been running for many years without any major (public) problems. They just work. And to be hones - I really don't care what they use as long as it works.
#1 - dotvoid ( Link) on 2004-10-18 23:17:43 Delete Comment
Up until the beginning of this year, I actually used to write the programs that run on the cash machines of one of the largest banks in the UK. I've never been a particular fan of micro$oft, but I never once saw a BSOD on any of my test machines, and they got pretty rigorous testing as I'm sure you can imagine. I personally would have loved to seen the cash machines running linux/unix, but the ATM manufacturers themselves (i.e. NCR and Wincor Nixdorf) simply don't support those operating systems, because remember it's them who have to write the drivers for all their proprietary devices. To this date I don't even think they are considering moving to anything non-M$, which is a great shame.
#2 - Richard Green ( Link) on 2004-10-19 05:44:00 Delete Comment

Add Your Comment