Migrosbank: Website insecure | General | Forum | Migros Migipedia

Migrosbank: Website insecure

Migrosbank: Webseite unsicher

Hello everyone.

As the topic of the Internet, security, etc. is currently becoming more and more explosive, I took an article from Golem to heart and tested Migros. The result was a bit strange, as migros.ch passed with flying colors, but migrosbank.ch failed.

Golem.de article
http://www.golem.de/news/firefox-mitgelieferte-gueltigkeitspruefung-fuer-zertifikate-1307-100700.html

migrosbank.ch at SSL-Labs
https://www.ssllabs.com/ssltest/analyze.html?d=migrosbank.ch

migros.ch at SSL-Labs
https://www.ssllabs.com/ssltest/analyze.html?d=migros.ch&s=146.67.140.135

Kind regards
kemi

All replies (7)

And the biggest thing with M.Bacnet (Migros-Bank Internet) is that a lot of time is spent on maintenance work: The weekend before last Sat and Sun, the weekend before last Sun.
Other banks only need a maximum of 10 minutes for SW updates, if at all, and then only at night when most people are not busy with banking business - and these are larger banks than MB - is this modern e-banking? No!
These (pre-announced) interruptions should be kept to a minimum at night! Thank you Migros Bank!

I'm also surprised that nobody seems to be interested in the problem. I thought that this site would be ideal because there are people behind it who have the necessary contacts in the right places.

I sent my request directly to Migros Bank at the time - a canned reply came back saying "...that you have announced this and that I have to do my banking business during the week..." and further "...For general technical reasons, these times are selected at the weekend." . General technical reasons: What's that? ;-(

"Normal" people work during the week and only have time for such things at the weekend...

Guest

Hello kemi

Thank you for your messages and for testing the two web servers. Your test results have already been forwarded internally to the relevant departments - we are of course interested in this problem and are therefore taking a close look at it.

@tickerschweiz: Thank you also for your feedback. I will also pass this on to the people responsible.

Best regards
Tanja, Migipedia team

Guest

Many thanks for the tip, kemi

www.migrosbank.ch has been online in its current form for almost 10 years. We are aware that the previous SSL implementation of this website can be optimized. The website is therefore currently being revised and, in the course of this, we are replacing the systems with a solution that meets today's security standards.

In principle, the information on our website is generally accessible. For this reason, only content that you will also find in our brochures, for example, is published there. The SSL installation using a "Class 3 Extended Validation" certificate is therefore not used for the secure transmission of data, but to identify our web server.

Migros Bank naturally guarantees the protection of sensitive information at all times. Our online portals, such as the online mortgage, the online personal loan and e-banking, are therefore perfectly secured with the highest possible security standards.

@tickerschweiz: Thank you for your feedback. We are making every effort to keep these interruptions to a minimum and to inform you in good time. Regarding the weekend, it is unfortunately the case that certain banking systems must always be available during the week and we can therefore only carry out maintenance work at the weekend. Thank you for your understanding.

Best regards
Sarah, Migros Bank

Hi Sarah_MigrosBank - thank you very much for your detailed comment. To a certain extent, I understand that maintenance work has to be carried out from time to time. Nevertheless, it should be possible to carry out this work at off-peak times.

Despite everything, I have grown very fond of MigrosBank - competence, expertise and customer-friendly conditions, that's what you want in a bank!

Best regards
tickerschweiz

tickerschweiz

And the biggest thing with M.Bacnet (Migros-Bank Internet) is that a lot of time is spent on maintenance work: The weekend before last Sat and Sun, the weekend before last Sun.
Other banks only need a maximum of 10 minutes for SW updates, if at all, and then only at night when most people are not busy with banking business - and these are larger banks than MB - is this modern e-banking? No!
These (pre-announced) interruptions should be kept to a minimum at night! Thank you Migros Bank!

Maintenance work again today...annoying.