TARGET 8: Testing website security to ensure personal information is secure

1 year 5 months 1 week ago Tuesday, July 05 2016 Jul 5, 2016 Tuesday, July 05, 2016 5:41:00 PM CDT July 05, 2016 in Target 8
By: Nina Amedin, KOMU 8 Reporter
loading

MOBERLY - For part of this summer, the city of Moberly's online bill payment system was not a secure site according to a Qualys Lab web page test. Target 8 decided to test the security of that site and many other mid-Missouri sites after an emailed tip from a viewer.

"The city of Moberly does not appear to properly protect customers credit card information," according to the viewer tip. "Although instructions on the website noted above say the information will be transferred to a secure site, the Moberly web page, where the information is originally entered, is still not secure. It remains to be determined to what degree the information is at risk and for what period(s) this lapse in security has or remains."  

Moberly responds to concerns

KOMU 8 News reached out to Moberly's city manager, Brian Crane, and our reporter was then forwarded to Moberly's public relations manager Tristan Asbury.

"In regards to the City of Moberly's online bill payment system - the issue is being resolved as we speak," Asbury said. "We were initially under the impression that our bill payment system was secure but under further review, we have run tests and found the home page of the bill payment system is not. However, once a payment is submitted, it is encrypted to comply with all encryption standards and regulations and is extremely secure. To date, we have had no community members affected by fraudulent activity."
 
Asbury continued, "To fix the issue at hand and guarantee that community members using the online billing system are protected from fraud, we will be re-directing our bill payment system page within our website to our original encryption outlet. This will allow for constant oversight of our billing page which in turn will provide Moberly residents with nothing less than a safe and secure system from beginning to end."
 
He refused further comments as well as an in person interview. 

The University of Missouri System uses Qualys Continuous Security system to check for web insecurities. 

Target 8 tests other mid-Missouri websites

KOMU 8 News went through multiple government websites to test their security using the Qualys system. 

((SUMMARY OF FINDINGS))

The tests are given a grade rating or a "not trusted" rating. 

The grade is based on the following:

  • A website's certificate, activates the padlock and the https protocol and have to be renewed every year.
  • Protocol support 
  • Key exchange
  • Cipher strength, the strength of encryption. 

Moberly and Fulton's city bill pay websites were "not trusted" when tested on the Qualys system. 

Qualys said when a website is not trusted it could mean either the website has an invalid certificate, invalid configuration, unknown certificate authority or interoperability issues. 

How to protect yourself

There are things consumers can do to check if a website is secure said Beth Chancellor, Chief Information Security Officer for the University of Missouri System. 

"It's important to be on the right website to begin with and the only way to do that is to go to that site yourself," Chancellor said. 

She said consumers should never click on links in emails that are sent from websites like banks or utility companies.  

"They actually need to type the URL or search for the site in their browser," she said. "They could get an email that is sent to them saying 'you need to pay your bill' and it could be a fake email that could take you to a fake site that might look exactly like their site."

Another way to check for web security is to look at a web browser and see if there is a padlock image in the left corner of the URL or web browser. 

An "encrypted or secure site will start with 'https,' the 's' stands for secure, and generally there will be a padlock icon associated with that," Chancellor said. 

One issue some sites run into can be home page security, like the city of Moberly. Chancellor said home pages may not be secure at times, but that could change once you move around on the website or log in. 

"Although some sites, say the City of Moberly for example, or another one is eBay, when you go to their home site, a lot sites won't be secure at that level, but once you go to log in or once you do something on the site it will then change to https," she said. 

"There can also be application vulnerabilities," she said.  "Anyone who collects payments online and deals with collecting credit cards by the payment card industry, called PCI standards, all merchants have to meet those standards."

It's tough to get 100 percent

She said it may be that a site that was once insecure was secure at one point, but because of changes made to the site, it became insecure again.

"There are few organizations that are going to get a 100 percent clean Qualys report every time they run a scan of their server because the number of security vulnerabilities come in every single day," Chancellor said. 

She said when websites try to fix a security problem, they might turn around and create a different security problem they hadn't intended to. 

"It's sometimes hard to keep up with making sure that everything you do is secure all the time," Chancellor said. 

She said she thinks because of issues like this websites are having, more people will start using one time virtual credit cards.

"I know that Bank of America and CitiGroup offer virtual cards that are tied to your credit card so you can sign up for a virtual card and use that virtual number that is used once and then it still gets charged to your same account, but the criminals can't get access to your actual credit card number," she said.

Another tip Chancellor recommended is that consumers don't store credit or debit card information with any retailer they're doing business with online. She said there is usually a one time option you can select to complete purchases. 

"If that company gets hacked then your credit card will be exposed just like everybody else's credit card," she said. 

Chancellor said there is only a limited number of things consumers can do to make sure websites are secure enough to input their personal information.   

Moberly's website upgraded to 'A' security rating

The Target 8 team ran a Qualys test again on July 5, 2016 and Moberly's onling bill pay system received an "A" rating. 

We reched out to Asbury again on July 5 and no comment has been received so far as to what changed in their bill pay system to make it a more secure site for customers.  

 

 
 

More News

Grid
List
VERSAILLES - Prosecutors filed charges against three employees of the Morgan County Jail on Monday, including a nurse accused of... More >>
1 hour ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 7:50:00 PM CST December 14, 2017 in News
FULTON - People who are preparing to travel for the holidays are automatically at risk for robberies, road issues, and... More >>
1 hour ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 7:25:00 PM CST December 14, 2017 in News
JEFFERSON CITY (AP) — The search for Missouri's next top education official has started. The State Board of Education... More >>
2 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 6:13:24 PM CST December 14, 2017 in News
MOBERLY - Fire and law enforcement officers from three counties received radiological training Thursday at the Moberly Fire Department. ... More >>
2 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 6:09:00 PM CST December 14, 2017 in News
COLUMBIA - Here is the latest on a threat to Moberly Area Community College's Columbia campus: 6:55 p.m. ... More >>
4 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 5:00:00 PM CST December 14, 2017 in News
MOBERLY - Police are searching for a suspect in connection with the assault of two Moberly residents. Authorities said the... More >>
4 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 4:47:00 PM CST December 14, 2017 in News
COLUMBIA - The City of Columbia has new aid in fighting snowy roads this with the help of its new... More >>
5 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 4:04:00 PM CST December 14, 2017 in News
AUDRAIN COUNTY – One Missouri farmer is righting his wrong following a pig waste leakage into a nearby creek. ... More >>
5 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 3:45:00 PM CST December 14, 2017 in News
JEFFERSON CITY - Authorities are investigating a Wednesday night shooting which injured a 19-year-old Jefferson City resident, police said in... More >>
5 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 3:37:00 PM CST December 14, 2017 in News
COLUMBIA - Callaway County schools donated more than 9,200 toys to Toys for Tots Thursday. "We're excited," coordinator Melissa... More >>
5 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 3:20:00 PM CST December 14, 2017 in News
BELLEFONTAINE NEIGHBORS (AP) - The Latest on the shooting of two St. Louis-area police officers saved by their bulletproof vests... More >>
5 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 3:17:00 PM CST December 14, 2017 in News
COLUMBIA - Thursday marked the five year anniversary of the Sandy Hook shooting. In 2012, Adam Lanza opened fire... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:50:00 PM CST December 14, 2017 in News
COLUMBIA - Police now have 75 kits with the opioid overdose reversal medication naloxone, which is also known as Narcan.... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:39:00 PM CST December 14, 2017 in News
JEFFERSON CITY (AP) — The former administrator of the Pettis County Ambulance District has admitted embezzling more than $227,000... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:15:00 PM CST December 14, 2017 in News
JEFFERSON CITY - Democratic lawmakers are voicing their concerns after the Missouri Republican party presented a new tax plan for... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:12:00 PM CST December 14, 2017 in News
JEFFERSON CITY (AP) — Missouri Gov. Eric Greitens has appointed a former St. Louis-area Husch Blackwell lawyer to the... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:11:00 PM CST December 14, 2017 in News
JEFFERSON CITY (AP) — Republican Gov. Eric Greitens is praising Missouri's revamped Clean Water Commission for allowing two new... More >>
6 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 2:08:00 PM CST December 14, 2017 in News
OLATHE, Kan (AP) — A third man has been convicted in the killing of a suburban Kansas City gun... More >>
12 hours ago Thursday, December 14 2017 Dec 14, 2017 Thursday, December 14, 2017 8:46:29 AM CST December 14, 2017 in News
Columbia, MO
Broken Clouds 29°
9pm 30°
10pm 30°
11pm 29°
12am 28°

Select a station to view its upcoming schedule:

Coming Up Next

7:20p
Thursday Night Football
10:30p
KOMU 8 News @ 10
11:05p
The Tonight Show Starring Jimmy Fallon
9:00p
KOMU 8 News @ Nine on The CW
9:30p
Seinfeld
10:00p
Seinfeld

Tonight's Schedule

6:30p
Football Night in Indianapolis
7:20p
Thursday Night Football
7:00p
iHeartRadio Jingle Ball 2017
8:30p
Whose Line Is It Anyway?
9:00p
KOMU 8 News @ Nine on The CW
9:30p
Seinfeld