Closed Bug 698222 Opened 13 years ago Closed 13 years ago

Finnish Nordea online banking site uses broken SSL implementation incompatible with new anti-chosen-plaintext-attack mitigations in browsers

Categories

(Tech Evangelism Graveyard :: Finnish, defect)

defect
Not set
major

Tracking

(firefox10-)

RESOLVED DUPLICATE of bug 698203
Tracking Status
firefox10 - ---

People

(Reporter: briansmith, Unassigned)

References

()

Details

(Keywords: conversion, regression, Whiteboard: [server-has-broken-TLS-implementation])

+++ This bug was initially created as a clone of Bug #698203 +++ See the explanation in bug 698203 comment comment 6. STR: Open https://solo1.nordea.fi/nsp/engine Click on 'In English' tab at the top. Expected result: A page opens asking for username and password What actually happens: The page reports an error I was reported the bug affects Linux too and it has been reproduced on both x64 and x86 versions of Nightly. And the bug isn't new, I have been suffering from it for weeks.
Summary: Nordea online banking page logs Nightly out with an error message when trying to do anything → Finnish Nordea online banking site uses broken SSL implementation incompatible with new anti-chosen-plaintext-attack mitigations in browsers
Whiteboard: [server-has-broken-TLS-implementation]
Either we have changed something, or Nordea has fixed their site, since Nordea's Solo is working with Nightlies.
It is still reproducible on Swedish Nordea. Open https://internetbanken.privat.nordea.se/nsp/engine Click on "Förenklad inloggning"
I forgot to mention, the link in the bug report can still reproduce the problem too, all with Nightly 2011-11-18.
Jumped the gun. Finnish site doesn't trigger the error anymore, but 403's on revisiting it.
I was wrong. Nordea Solo is still broken in some cases.
I'm unable to reproduce this on Firefox 10.
Which probably means they fixed the site.
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
Product: Tech Evangelism → Tech Evangelism Graveyard
You need to log in before you can comment on or make changes to this bug.