A few days ago, Troy Hunt published a blog post about various banks and their SSL. Using SSL Labs’ SSL Server Test, he scanned a bunch of Australian banks’ websites and summarized the results. Interestingly, very few banks achieved “all green”. Most banks lack support for Forward Secrecy and many also still support the RC4 cipher suite. A few were even vulnerable to the POODLE vulnerability. These results made me curious about how the Danish banks compare.

I threw a bunch of Danish bank URLs through the SSL Server Test and the results can be seen in the table below. It should be noted that I have taken the URL to the page displaying the NemID login form (a common login platform used by all Danish banks).

Update, 13 May: Finansbanken is no longer vulnerable to POODLE and is now supporting TLS 1.2. This improves their rating to B.

BankGradeSupports SSL 3Supports SHA1No TLS 1.2Supports RC4Forward SecrecyPOODLE
Danske BankA-PassPassPassPassFailPass
Vestjysk BankBFailPassFailFailFailPass
Spar NordBPassPass*PassFailFailPass
Jutlander BankBPassPassFailFailFailPass
Arbejdernes LandsbankBFailPassFailFailFailPass
Lån & Spar BankBFailFailFailFailFailPass
Nordjyske BankFPassPassFailFailFailFail
  • *Intermediate certificate still supports SHA1

Himmerland is actually the “old name” for Jutlander Bank, but it seems like it is still possible to login to their online banking site from the old domain.

These results seem to be consistent with the Aussie banks in Troy Hunt’s post.

