'Here's how you rob banks using Microsoft software'

'...and for my next trick...'

NEWS A former hacker has demonstrated how to break through the online defences of internet banks by breaching the security of Microsoft's web server software. An unidentified Swedish hacker-turned-security-expert showed a Reuters reporter how he could by-pass the security guarding three of Sweden's four biggest banks in a matter of minutes. While the hacker did not break into individual accounts he reportedly made it clear that he could have set up money transfers from one account to another. He even showed how it was possible to then cover his tracks to avoid detection. This revelation will be a further embarrassment for Microsoft whose server security has been a cause of industry concern on many occasions in the past. It will also damage the reputations of online banks who are constantly waging a battle against inertia among customers unwilling to move online due of concerns about security. According to Reuters, the former hacker relied on various weaknesses resulting from Microsoft's implementation of Secure Socket Layer (SSL) - the industry standard for transmitting sensitive data such as credit card numbers and passwords via the internet. However, Microsoft isn't solely to blame for the vulnerabilities. The former hacker said the bank's own network administrators, who have failed to properly install Microsoft's software, must take a large share of the blame.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your silicon.com account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ

Get silicon.com's daily newsletter

  • Register on silicon.com

    Enter your email to register

Keep in touch with silicon.com

silicon.com newsletters