{"id":2146,"date":"2014-09-12T14:31:23","date_gmt":"2014-09-12T20:31:23","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2146"},"modified":"2014-09-12T14:31:23","modified_gmt":"2014-09-12T20:31:23","slug":"trust-guard-and-the-false-security-of-trust-seals","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/09\/12\/trust-guard-and-the-false-security-of-trust-seals\/","title":{"rendered":"Trust Guard and the False Security of Trust Seals"},"content":{"rendered":"<p>The recent <a href=\"http:\/\/fortune.com\/2014\/09\/08\/home-depot-confirms-credit-card-breach-going-back-months\/\">massive credit card breach at Home Depot<\/a> was yet another reminder that whether offline or online, IT security is often lacking. For consumers the question then is how can\u00a0they\u00a0know that their information is secure when they provide it\u00a0to companies? Numerous security companies\u00a0have created trust seals &#8211; that can be placed on websites if they meet certain requirements &#8211; that let the public know that a website is secure. The problem we have found with\u00a0a number of these is that they are not doing basic security checks and therefore their assurances of\u00a0security are false. Last week took a look at <a title=\"SiteLock Fails To Do Basic Security Check\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/09\/03\/sitelock-fails-to-do-basic-security-check\/\">SiteLock&#8217;s<\/a> and earlier this year we looked <a title=\"Norton Secured Seal Service Doesn\u2019t Do Basic Security Check\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/02\/27\/norton-secured-seal-service-doesnt-do-basic-security-check\/\">Norton&#8217;s<\/a>,\u00a0now we will look at another bad trust seal that we ran across recently.<\/p>\n<p>While visiting the website of a client&#8217;s web host recently our Chrome extension <a href=\"https:\/\/chrome.google.com\/webstore\/detail\/meta-generator-version-ch\/fahebfpoehlhpngkmdgldkkilflkelbl\">Meta Generator Version Check<\/a> provided an alert that website was running an outdated version of Joomla:<\/p>\n<p><a href=\"https:\/\/chrome.google.com\/webstore\/detail\/meta-generator-version-ch\/fahebfpoehlhpngkmdgldkkilflkelbl\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2148\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hostica-joomla-version.png\" alt=\"Hostica is Running Joomla 1.5\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hostica-joomla-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hostica-joomla-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a><\/p>\n<p>It obviously isn&#8217;t a great sign that web host is running outdated software on their website (especially\u00a0when that <a href=\"http:\/\/docs.joomla.org\/Joomla!_CMS_versions\">version hasn&#8217;t been supported for two years<\/a>), but what was more surprising was the Trust Guard security verified trust seal at the bottom of the website:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2149\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hosticas-trust-guard-security-verified-trust-seal.png\" alt=\"Hostica's Trust Guard Security Verified Trust Seal\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hosticas-trust-guard-security-verified-trust-seal.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/09\/hosticas-trust-guard-security-verified-trust-seal-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/p>\n<p>In this case it is easy to\u00a0detect that the website is running an outdated version of Joomla since there is a meta generator tag in the source code of the website&#8217;s pages that tells you exactly that:<\/p>\n<blockquote><p>&lt;meta name=&#8221;generator&#8221; content=&#8221;Joomla! 1.5 &#8211; Open Source Content Management&#8221; \/&gt;<\/p><\/blockquote>\n<p>With such an easy to detect security issue a\u00a0trustworthy trust seal shouldn&#8217;t claim that the website is secure. We were curious to find out exactly what security checks Trust Guard was actually doing. Clicking the trust seal brought up a <a href=\"https:\/\/secure.trust-guard.com\/certificates\/www.hostica.com\">page<\/a> that explained why they are claiming the website has verified security:<\/p>\n<blockquote><p>In order for www.hostica.com to qualify for the Trust Guard Security Verified Seal, we verify that their website is using at least 128-Bit SSL Encryption on pages where private information can be entered, such as credit cards, Social Security numbers, loan information, etc. and we monitor the SSL certificates expiration.<\/p><\/blockquote>\n<p>While using SSL encryption when sensitive information can be entered is important for security it doesn&#8217;t mean a website is secure, just that someone cannot snoop on the information as it sent to the website.\u00a0For example, we have done plenty of cleanups of hacked websites in which the <a title=\"Credit Card Compromises in Magento\" href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/01\/15\/credit-card-compromises-in-magento\/\">credit card information was compromised once it made its way to the website<\/a>. Since a web browser&#8217;s\u00a0user interface already provides notice when a secure SSL connection is in use, it isn&#8217;t clear what security value the trust seal is meant to provide, but it doesn&#8217;t seem that it out ways how misleading it is to claim that a website&#8217;s security is verified based only on the fact that it is using SSL encryption.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent massive credit card breach at Home Depot was yet another reminder that whether offline or online, IT security is often lacking. For consumers the question then is how can\u00a0they\u00a0know that their information is secure when they provide it\u00a0to companies? Numerous security companies\u00a0have created trust seals &#8211; that can be placed on websites if &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/09\/12\/trust-guard-and-the-false-security-of-trust-seals\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Trust Guard and the False Security of Trust Seals&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,35],"tags":[],"class_list":["post-2146","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-outdated-web-software"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2146"}],"version-history":[{"count":5,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2146\/revisions"}],"predecessor-version":[{"id":2153,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2146\/revisions\/2153"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}