E-Trade Says It Has Fixed Password Security Hole
- 27 September, 2000 12:01
- Comments
E-Trade has released a more secure version of the software it uses to store passwords after learning that it had been leaving accounts at the online brokerage vulnerable to access by outsiders.
The company stores information about customer passwords in cookies, which are stored on customers' computers. Until Sunday, the password information was protected by a scrambling technique that proved to be a weak form of security. E-Trade spokeswoman Heather Fondo said the company has since strengthened the scrambling technique.
"At no point was any customer information compromised," she says. "E-Trade is always very vigilant in its security efforts."
But the vulnerable cookie was not the only problem. E-Trade's Web site also is susceptible to what is called a "cross-site scripting attack," whereby an attacker could create a Web link allowing access to the cookie and the passwords it contains if an E-Trade customer were to click on that link. The links could then be sent to target victims in e-mail or could be hidden on Web sites.
Making it more difficult to gain access to the password stored in the cookie, which E-Trade said it has now done, should solve the immediate problem. However, the cross-site scripting attack, which affects browsers and many other sites, could still pose problems with other unsecured information stored in cookies.
The password vulnerability was discovered by Jeffrey Baker, who wrote about it on the BugTraq mailing list Friday. Baker said in his posting that he notified E-Trade about the problem a month earlier but nothing had been done, so he felt compelled to alert E-Trade customers to the potential risk.
Baker recommends that in order to protect their accounts, E-Trade customers should disable JavaScript in their browsers; avoid using the six-month login feature on the Web site; always close and restart the browser before and after using E-Trade; remove E-Trade cookies after using the Web site to make the cookies file read-only; and firewall outgoing requests to all hosts that are not from E-Trade's Web site when using the brokerage's service.
If exploited, the vulnerability could have allowed unauthorised users to manipulate the stock market by buying and selling stocks from accounts they illegally access, said Elias Levy, CTO of security portal SecurityFocus.com.
This is not the first time a security hole has been found at the Web site of a financial institution. In a much-publicised case back in February, a technical glitch at H&R Block Inc.'s Web site exposed customer tax information to other customers.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
- Book 1 - The Practical Guide to Assuring Compliance
- OVUM TECHNOLOGY AUDIT: HP Application Lifecycle Management
- Book 3 - The Executive’s Guide to Managing Risks
- Fibre Channel over Ethernet in the Data Center: An Introduction
- Cloud printing in the enterprise: liberating the mobile print experience from cables, operating systems, and physical boundaries
- iPhone 5 rumour rollup for the week ending February 10
- 3D mapping revives underwater city
- Academic challenges Turnbull over NBN satellite criticism
- What are you saying: Telstra’s customer service slowly improving, SA minister urging Facebook to overturn its photo ban
- In pictures: Capgemini opens new Canberra office
-
Maingear's six-core laptop has 1.8TB of SSD storage
-
After Megaupload shuts, BTJunkie follows
-
Windows Event Viewer phishing scam remains active
-
NeuroSky MindWave: Fun with Brainwaves
-
20 popular Ubuntu Linux apps you may want to try
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Microsoft Office
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies®












Comments
Post new comment