Lloyds TSB plugs security gap at last

A security hole in Lloyds TSB's internet banking service is finally to be fixed, nearly two months after a customer alerted the bank to the problem.

Andy McCue, Computing

A security hole in Lloyds TSB's internet banking service is finally to be fixed, nearly two months after a customer alerted the bank to the problem.

The hole was discovered in August by prominent IT services analyst Richard Holway, whose company is a Lloyds customer.

Advertisement

"The first thing I did was to telephone the customer care people, all the way up through these stupid lackeys giving me this party line that I could turn it off if I wished and that was up to me," he said.

"They only responded differently when I identified myself as an industry analyst."

Holway finally received a letter from Lloyds TSB dated 13 October saying that after an investigation, the 'AutoSave Password' feature is to be disabled from its service.

The flaw occurs if the AutoSave Password feature on a customer's desktop is enabled. A cookie that stores the Lloyds TSB account username and password allows anyone with access to the PC to enter the account.

"After logging in once, the username and password were automatically remembered. In other words, anyone using my PC had unrestricted access to my account," said Holway.

The flaw is similar to one discovered by Barclays' online customers in August, whereby using a browser's back button after logging out still took customers back into the account, without the need for logging in again.

Barclays said at the time it was working on a process to automatically delete the cache after logging out, but a spokeswoman this week said this would not be done until the next website update, sometime before the end of the year.

"It is something we are developing, and it will go live with our next release of software," she said.

First published in Computing

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Lloyds TSB scraps e-bank plans

Lloyds TSB has scrapped the launch of its UK internet bank, Evolvebank, and will instead concentrate on an online venture with Centrica.

Online banking hangs in the balance

The UK's online banking pioneers have run into some problems. We look at what they are doing to turn around their fortunes.

Lloyds TSB denies web bank delay

UK bank Lloyds TSB has denied that it will put back the UK launch of its internet bank following recent security concerns at other online banks.

James Bond exposed in Swiss bank blunder

Roger Moore, who played British secret agent James Bond in the 1970s and 1980s, has had his Swiss bank account details published on the web following an error by bankers Credit Suisse.

Related whitepapers

Related jobs

Most watched

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation