Misc
1050 posts in Misc
Belgian banks & SSL -- part 2
I previously wrote about Belgian banks & SSL. Updated version (15/02/2015) here.
Going through my Google Analytics I noticed some noteworthy network domains, which Google discribes as “The fully qualified domain names of your visitors’ Internet service providers (ISPs)”.
Belgian banks & SSL
Tested using SSL Labs on 20/01/2015. Updated version 01/02/2015 here and 15/02/2015 here.
Only providing the weak points. Once there is one SHA1 key in the chain, I will report everything as weak.
Check SSL Labs for a full report, including what they actually did good (if anything).
Grade A
- Rabobank (A+): no known issues. Support for HTTP Strict Transport Security and prevented downgrade attacks.
- Triodos (A): no downgrade attack prevention.
- Belfius (A-): weak signature (SHA1), no Forward Secrecy.
Grade B

