I once reported password exposure via browser caching in the login form of one of those "too big to fail" banks. (I called it in.)
I never heard anything back, but a month or so later, it was fixed.
I'm glad it was some years ago. These days, I think I'd fear that their legal team would seek to have me criminally charged and/or bankrupted, regardless. (Don't look at the password caching; that's "hacking".)
I guess you did a good thing. In this day and age, though, I almost wish they were named, as such behavior represents an extreme form of negligence. (I am not advising you to reveal them, though. See, for example, my previous paragraph.)
I never heard anything back, but a month or so later, it was fixed.
I'm glad it was some years ago. These days, I think I'd fear that their legal team would seek to have me criminally charged and/or bankrupted, regardless. (Don't look at the password caching; that's "hacking".)
I guess you did a good thing. In this day and age, though, I almost wish they were named, as such behavior represents an extreme form of negligence. (I am not advising you to reveal them, though. See, for example, my previous paragraph.)