Online banking hosted on IIS...

beatmix01

Golden Member
Jun 22, 2001
1,008
1
0
I just found out my banking institution uses IIS as their platform to run their online banking. For some reason this does not sit well.

 

yllus

Elite Member & Lifer
Aug 20, 2000
20,577
432
126
Which version of IIS? The latest is pretty secure.
 

vi edit

Elite Member
Super Moderator
Oct 28, 1999
62,484
8,345
126
So long as the admin isn't a complete chucklehead it's not as insecure as people think.
 

gshock888

Banned
Mar 28, 2003
1,762
1
0
if my bank uses IIS i would feel like my money is slow... very slow

other than that, i think it's as secure as it being hosted in java or whatnot.
 

Rogue

Banned
Jan 28, 2000
5,774
0
0
Originally posted by: beatmix01
Well it is either 5.0 or 6.0, I have yet to figure that out.

Why might you need to "figure it out"?

Are you some kind of super admin or security guru and have a well versed knowledge of the security concerns with IIS or are you some /. weenie who reads a headline and thinks he knows everything about something? Start a poll to answer that question please. Thanks.
 

beatmix01

Golden Member
Jun 22, 2001
1,008
1
0
Originally posted by: Rogue
Originally posted by: beatmix01
Well it is either 5.0 or 6.0, I have yet to figure that out.

Why might you need to "figure it out"?

Are you some kind of super admin or security guru and have a well versed knowledge of the security concerns with IIS or are you some /. weenie who reads a headline and thinks he knows everything about something? Start a poll to answer that question please. Thanks.


Actually I am a security guru / admin... However, from the rest of their web site/ infrastructure, I am not sure how well their internals are managed.
 

gshock888

Banned
Mar 28, 2003
1,762
1
0
north fork is a huge bank and is FDIC insured. who cares if they got hacked and you lose all your money. the feds got your back unless ur bill gates-rich.
 

Rogue

Banned
Jan 28, 2000
5,774
0
0
Originally posted by: beatmix01
Originally posted by: Rogue
Originally posted by: beatmix01
Well it is either 5.0 or 6.0, I have yet to figure that out.

Why might you need to "figure it out"?

Are you some kind of super admin or security guru and have a well versed knowledge of the security concerns with IIS or are you some /. weenie who reads a headline and thinks he knows everything about something? Start a poll to answer that question please. Thanks.


Actually I am a security guru / admin... However, from the rest of their web site/ infrastructure, I am not sure how well their internals are managed.

Then I'm guessing that you're freelancing right now or you're violating some type of privacy agreement. Either way, go ahead on if you feel it's right. Seems to me you're up to something though and posting your inquiry results to a public forum doesn't seem prudent for a "security guru/admin" looking to gain trust from an organization.
 

everman

Lifer
Nov 5, 2002
11,288
1
0
It just depends on what kind of people are managing things there. Even Apache can be terribly insecure if you have a complete moron managing it.
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
Originally posted by: beatmix01
I just found out my banking institution uses IIS as their platform to run their online banking. For some reason this does not sit well.

when you say online banking....what do you mean? can you transact online or are you just viewing your statements and checks online?

Also, IIS6 is pretty secure. And even if someone hacked into the bank, they'd need intimate knowledge of how the banking software and backend infractructure is setup in order to get to the data.

Now if their tapes were stolen like Bank of America and your data was on it...then you're screwed ;)
 

beatmix01

Golden Member
Jun 22, 2001
1,008
1
0
Online banking to perform transactions online. Regarding the Bank of America tapes... wouldnt you think the data backed up on the tapes would be encrypted?
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
Originally posted by: beatmix01
Online banking to perform transactions online. Regarding the Bank of America tapes... wouldnt you think the data backed up on the tapes would be encrypted?

you'd think....
 

MrChad

Lifer
Aug 22, 2001
13,507
3
81
Originally posted by: vi_edit
So long as the admin isn't a complete chucklehead it's not as insecure as people think.

:thumbsup:

An incompetent admin can setup Apache more insecurely than IIS, so what's your point?