Scarborough Building Society pulls insecure 'print' form
Ticked all the wrong boxes
Regcast training : Hyper-V 3.0, VM high availability and disaster recovery
Scarborough Building Society has pulled an insecure form from its site after it emerged that sensitive information was sent over an unencrypted connection.
An online application form for various types of savings accounts invited prospective investors to fill in various categories of sensitive personal information before printing off the form and sending it in to the society by conventional post. In reality, data was exchanged with the society's servers as checks were made to ensure the form was filled in correctly. This contradicts what the society told customers at the bottom of the form and what was implied by the procedure of posting off information they had typed in.
Not only that, but as Reg reader Alan Iwi was quick to notice this data was sent over an insecure (unencrypted) connection, leaving it vulnerable to potential eavesdropping attack. Scarborough reacted quickly on notification, and pulled the form and launched an investigation.
"We have experienced a technical issue with the form and have temporarily removed the ability to submit any form containing personal information online for checking. A technical solution to the issue will be put in place over the next few days," a Scarborough Building Society spokeswoman explained.
Scarborough Building Society was founded in 1846 and is the second oldest building society in the UK. The mutually owned financial organisation manages assets worth an estimated £2.9bn. ®
COMMENTS
"We have experienced a technical issue"
It's not a technical issue, it's incompetence.
AJAX?
I bet it was an AJAX based form, and I bet it was created using some mickeysoft (s)tool.
I mean, come on... to resolve it you don't need to remove the whole form, you need to either: make it send it's requests to a secure server; or remove the validation system for now (replacing with javascript if appropriate as time allows).
Oh well, another one bites the dust!

IT infrastructure monitoring strategies
Agentless Backup is Not a Myth
Top 10 SIEM implementer’s checklist
Steps to Take Before Choosing a Business Continuity Partner
Requirements Checklist for Choosing a Cloud Backup and Recovery Service Provider