The Heartbleed web security bug that's raised vulnerability concerns across much of the web and prompted the Canada Revenue Agency to block access to part of its site Wednesday is no threat to bank websites in Canada, the group that represents the industry says.
"The online banking applications of Canadian banks have not been affected by the Heartbleed bug," the Canadian Bankers Association said Wednesday. "Canadians can continue to bank with confidence."
Heartbleed is a recently discovered security bug built into the newest version of a ubiquitous software code known as OpenSSL. The software code itself is what powers the encryption process on about two-thirds of the world's secure web servers (which can be recognized by a closed lock-and-key symbol) and it ensures that only authorized users have access to the sensitive data being transmitted.
A glitch in the most recent version of the program was uncovered this week that could theoretically allow a hacker to mimic the appearance of an authorized user, and subsequently be granted access by an affected server to be able to collect sensitive information.
Although there's an easy fix to the buggy OpenSSL version, there's an added problem with the bug in that it makes it very difficult to tell after the fact who may have been granted unlawful access to data before the loophole was closed.
The Canada Revenue Agency took the bold step on Wednesday of shutting down its public website until it can address the issue. That's prompted questions as to whether other websites with highly sensitive data, such as banks, may be vulnerable.
There's no need for Canadians to be concerned about their banking information being unlawfully accessed, the CBA said Wednesday.
Toronto-Dominion bank noted that the vulnerability affects any company in any industry connected to the internet, but says customers have no added need to worry about banking.
A spokesperson for the Bank of Montreal said "customer information is safe and secure. Protection of customer information is our highest priority and we will continue to monitor our banking platforms as a precaution."
CIBC and Scotiabank both said they support the industry group's statement on the issue.
Despite the lack of a specific Heartbleed-related threat, the CBA urges banks customers to remain vigilant about what data they share online, by keeping track of statements, monitoring PINs and changing passwords regularly.
Related Stories