Saturday, April 18, 2015

Chase Bank Using Outdated Security

I noticed today that Chrome started showing the “secure, but with minor errors” icon for Chase bank's website.  Taking a closer look, they are using a SHA1 signed certificate:

This is with Chrome 42.  Seems amazing that a major bank like Chase would still be using a SHA1 signed certificate, even though it has been known for a while to not be fully secure.