Slashdot Mirror


Online Billpay Provider Loses Control of Domains

An anonymous reader writes "Several sites are running a story about a domain hijacking at Checkfree, the largest provider of online bill payment services to numerous banks and credit unions. According to Network Solutions, someone logged in to the domain administration page using Checkfree's account, and redirected its domains to a site in the Ukraine configured to serve up malware to unsuspecting users." Things like this make me nervous about switching to otherwise-tempting online bill payment, but checks are dangerous, too.

7 of 232 comments (clear)

  1. Some more details... by Darth+Muffin · · Score: 4, Informative
    My wife works for a CU, and has been giving me details on this all day. I guess the cats out of the bag now and I can say something :) Your financial institution is not to blame, but in my wife's case they're offering to help clean up infected user's computers.

    Anyhow, what I know is that the malware is new and still being analyzed -- they're not fully sure what it's for yet (capturing accounts, spamming, botnet, or probably all of the above). For now they are recommending that people udate their virus scanners and Acrobat Reader. They must suspect Acrobat as an infection vector somehow.

    --
    Real programmers use "copy con program.exe"
  2. Re:Summary's analysis doesn't make much sense. by Tablizer · · Score: 5, Informative

    If there were a Slashdot feature to transfer money out of your bank account...

    The /. HTML was hijacked, and odd jumpy misaligned CSS was put up instead ;-)
           

  3. Don't be stupid... by NoKaOi · · Score: 3, Informative

    For US Bank anyway, when I tried to go to my bill pay when this was going on my browser gave a nice message that the SSL cert was self signed and issued to localhost.localdomain. Any modern browser makes is pretty clear that something bad is happening in this case, although I'm sure there's still plenty of ignorant users willing to click through.

    True, my financial institution (US Bank) may or may not be to blame, HOWEVER, you'd think it wouldn't take a bank a full day to let users know or take away the bill pay link or something along those lines. When I saw the invalid certificate, I still needed to cancel an automatic payment so I decided to contact my bank. Their response was basically, "we take security very seriously, please make sure you're using a compatible browser, move along now, nothing here to see." It wasn't until at least a day later that they notified users when logging in that bill pay was down. I wonder how many users clicked through during that one day period, which could have easily been prevented by a faster response?

  4. i 3 usa by Vegeta99 · · Score: 5, Informative

    When I was 16, I discovered that with a ruler, an exacto knife, and some elmer's glue you could make up your own checks. They also had "MAC Check" machines that would scan a check - even from a non-customer - and cash them.

    When I was 19, I worked in a junk mail plant that at times printed the 25% interest rate personal checks that credit card companies send out to new cardholders. All night we would watch "CONGRATULATIONS ON YOUR NEW $100,000 CREDIT LIMIT!" with 6 checks attached go whizzing by at 5MPH. When that roll of checks breaks, printed-but-junk checks dump on the floor, 7 feet per second, and if I wanted, I could pocket the sonsabitches and spend like hell - before the recipient even activated their new card. We sent those out, too.

    Can our banking system really be that insecure? I open an account based on a supposedly unique ID number, hand them a photo ID that doesn't even reference my SSN. Then, they give me another number - my account number - and tell me to keep it private. Three weeks later, I get my checks that ten minimum wage slaves have already gotten to see. Every check I hand out has my private account number printed at the bottom.

    Most banks hold you responsible for any automated clearing house fraud, and yet, to authorize a transfer out, all that is needed are the numbers at the bottom of every personal check you write and the "assurance" from the receiving institution that you have "authorized the transfer".

    When ya think about it, it's no wonder they charge you $2 to withdraw from an ATM, $3 to use a teller, and $35 for an overdraft - it's easier to roll the dice to get an account number than it is to roll the dice and win the lottery!

  5. Re:Aging brain dead old Re:Benefits of Paper Check by cgenman · · Score: 3, Informative

    Bank of America allows you to pay online via systems that accept it, and mail checks to those who don't. Strangely enough, most of the people I pay bills to here in Massachusetts accept digital billpay through whatever system they use. But even paper checks are automatic and free.

    BofA is a bunch of greedy bastards, yet they found a way to make it worthwile and simple. It's slowly filtering over to America.

    It's like Cellphones: Companies don't feel like they can change one territory in the US at a time... they have to go all or nothing. So we get systems 10 years after the rest of the world has piecemeal brought themselves into it. Otherwise nationwide rollouts are untennable.

  6. Use a better registrar by Animats · · Score: 3, Informative

    Domain registrars come in several tiers.

    • Enom and its many other identities - use only for bulk junk domains
    • GoDaddy - low-end service; use for unimportant blogs.
    • Network Solutions - use for general business domains (ibm.com)
    • MarkMionitor - use for high value domains (gm.com, ubs.com)

    MarkMonitor is in the business of protecting "brands", so they have lawyers and technicians on staff to swing into action if somebody pulls something. If you have to ask how much they cost, you can't afford them.

  7. Re:More secure pages... by LunaticTippy · · Score: 3, Informative

    This scheme does nothing. Let's pretend you are, through whatever means, on a malicious copy of your Merrill Lynch site. Merril1-Lynch.com just logs in to merill-lynch.com and hands everything back and forth. They give your real site your username. The real site gives a picture. They give you the picture. Etc. Nothing is gained. It is security theater.

    Someone figured that out, and some sites now register your IP address or a cookie and if it is different they ask you for your mother's maiden name or whatnot. Guess what? My IP address and cookies change all the time. So now I have my mother's maiden name and favorite movie flowing around everywhere, and malicious sites can simply pass these questions and answers on, then get to the serious business of forwarding the pictures, then get involved in the boring financial transactions.

    --
    Man, you really need that seminar!