Building society caught in middle of high street sharing a little too much on TeamViewer
- Reference: 1591008186
- News link: https://www.theregister.co.uk/2020/06/01/bork/
- Source link:
It is the turn of the Cambridge Building Society to flash its undergarments at passersby this time around.
Register reader Adam snapped the outfit's St Andrew's Street branch in the midst of a TeamViewer session over the bank holiday weekend, with the ID and password on display for all to see, as well as an unchecked box offering Easy Access for an individual who we will leave nameless.
Suffice to say we have obscured the "Allow Remote Control" details (as well as the reflection of our intrepid reader) in case miscreants might seek to do something unmentionable with whatever has exposed its posterior.
We asked the building society for an explanation, but it has yet to reply.
TeamViewer itself is one of the go-to tools for those needing to remotely diagnose issues on PCs and, as well as a freebie version, has subscription editions aimed at corporates. TeamViewer recently announced that it would be [1]dropping connection checking for its free option but would still like enterprises to cough up the readies.
The message doesn't seem to have reached whoever is running the signage in this branch of the Cambridge Building Society. TeamViewer can be seen telling anyone pausing to peer through the glass that it is very much for "non-commercial use only".
Well, a building society is a kind of mutual organisation, owned by its members but, alas, we fear the activities of most of those in the UK at least are quite definitely commercial. Still, spare a thought for the Cambridge Building Society – its [2]profits after tax (PDF) dropped to £2.8m in 2019 (down from £3.2m in the previous year) as mortgage lending also fell.
Spanking the £119.90/month requested by TeamViewer for a full-on corporate licence may have been lower down its list of priorties.
[3]
We'll be here, and so will TeamViewer
Click to enlarge
And speaking of spanking, we'd also advise anyone running TeamViewer to keep a close eye on their own credentials. An innocent rummage through Twitter for the keyword "TeamViewer" will throw up all manner of [4]very NSFW uses . ®
[1] https://www.theregister.com/2020/03/23/freebie_teamviewer_to_stop_checking/
[2] https://www.cambridgebs.co.uk/media/9653/cambridge-annual-report-2019-interactive.pdf
[3] https://regmedia.co.uk/2020/05/29/bork_1_9.jpg
[4] https://www.theregister.com/2018/07/10/teamviewer_domination_on_demand/
not just banks
Saw a payment terminal at a once-popular chalet based holiday establishment with something comparable. After reporting it to staff they called the terminal support group and an hour later Notepad was open and showing the text "Please reboot me now."
I had to remind my friend that although yes, he could use the touch screen and the open Notepad to "learn more about the system" as he put it, he works in a senior technical position at a major UK bank and really shouldn't be leaving himself vulnerable to an accusation of hacking.
His protests ended when I pointed out the ceiling based camera recording his actions.
Logowatch
Hmmmmm. Is it just me or does that building society's logo look a bit Microsoft-ish?
Inexcusable
This is inexcusable and is indicative of just how seriously banks (and clearly building societies) take security. The larger banks are worse of course because they spend billions on advertising to lie to us about how much they care about security.