Natwest changes website security following heated exchange with cyber experts

The bank's website wasn't served over an encrypted connection

Natwest bank

Natwest bank has said it will update the security of its website following a heated online exchange with a number of security experts who spotted the vulnerability.

Liam Blizzard, a web developer, found that Natwest's customer-facing website wasn't secure, then security researchers Troy Hunt and Stephen Kellett pointed out that this meant the login link on their website couldn't be trusted.

"The homepage is insecure so you can't trust anything on it. The link to the login page is on it. You can't trust the link to the login page. Make sense?," said Hunt.

Natwest responded with a curt tweet telling Hunt "sorry you feel this way" which in turn prompted Hunt to state that the bank was "fundamentally misunderstanding the technology".

Hunt explained in a blog post that since the website is served over HTTP it's not an encrypted connection and data flowing to and from it can be intercepted, read, and modified, and requests could be redirected to other locations.

Hunt was also frustrated with the fact that although the online banking service, which is linked but separate from Natwest's main site, was secure, an attacker could still intercept the traffic between the two sites and redirect visitors trying to access the online banking service via the homepage from its official address nwolb.com to something similar such as nuuolb.com.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

After publishing the initial blog post, Hunt revealed: "NatWest went and registered that domain in what I assume is an attempt to stop a man in the middle intercepting their traffic and making a visually trivial change to a URL. Alarmingly though, nw0lb.com is still available as is nuu0lb.com and it-doesnt-matter-because-that-isnt-the-point.com."

A spokesperson for Natwest told IT Pro: "We have now fixed the issue which was affecting some of our customer facing websites. It has now been fixed -- see blog below" and linked to Hunt's blog post.

The bank later added: "Our websites now enforce the HTTPS protocol so that customers visiting the website via either http:// or https:// will be sent to the protected site."

Hunt did praise NatWest's rapid response to the issue, but it still serves to highlight how even some of the largest companies don't always have the processes and oversight in place to ensure their security is up-to-date and resilient to cyber attacks and opportunistic hackers. 

Image source: Shutterstock

Featured Resources

Key considerations for implementing secure telework at scale

Identifying the security risks and advanced requirements of a remote workforce

Download now

The State of Salesforce 2020

Your guide to getting the most from Salesforce

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Rethink your cybersecurity strategy for the new world

5 steps to secure the enterprise and be fit for a flexible future

Download now
Advertisement

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
Police use of facial recognition ruled unlawful in the UK
privacy

Police use of facial recognition ruled unlawful in the UK

11 Aug 2020