WebApp Sec mailing list archives

Re: Should login pages be protected by SSL? (and comment to moderator)


From: Amir Herzberg <herzbea () macs biu ac il>
Date: Tue, 21 Jun 2005 17:12:00 +0200

Andrew, thanks a lot! But, actually, I didn't find in this document a specific requirement to (use SSL to) authenticate the form used to request the credit card number. One may argue that the document allows an implementation that invokes SSL only to encrypt the credit card after the customer filled it in, and not to authenticate the form. Of course I do _not_ recommend this and I think this is vulnerable to many common spoofing attacks; but as I noted, there are important sites that take this approach.

So if there is a specific requirement to send an authenticated page, I'll really appreciate it.

Comment to moderator: sending to this list results in a crazy number of bounces... you may want to consider pruning them or even better, sending with the name of the list not of the submitter...

Best, Amir

Andrew van der Stock wrote:
Amir,

it's required. See Attachment A from the PCI Guidelines. It's very clear, particularly on page two with the diagram. If you deal with CC numbers, you must encrypt the communications over the Internet.

Eg, for the asia-pac region:
http://www.visa-asia.com/secured/includes/AP_Encrypt_Clarification.pdf

thanks,
Andrew

On 21/06/2005, at 8:07 PM, Amir Herzberg wrote:

The Visa/MC PCI guidelines are quite stringent on applying reasonable controls to this data.

Well, actually, I've worked with the card people a lot but am not aware of a specific requirement to use SSL to protect the form sent to the consumer and not just to protect the CC# in transit. Do you know? If you can give me some reference, I'll appreciate. I can also ask my contacts. I am very interested, as one of the companies which uses unprotected login is Amex, and in fact we had a long argument with them on these questions...



.


--
Best regards,

Amir Herzberg

Associate Professor
Department of Computer Science
Bar Ilan University
http://AmirHerzberg.com

New: see my Hall Of Shame of Unprotected Login pages: http://AmirHerzberg.com/shame.html


Current thread: