Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I once reported password exposure via browser caching in the login form of one of those "too big to fail" banks. (I called it in.)

I never heard anything back, but a month or so later, it was fixed.

I'm glad it was some years ago. These days, I think I'd fear that their legal team would seek to have me criminally charged and/or bankrupted, regardless. (Don't look at the password caching; that's "hacking".)

I guess you did a good thing. In this day and age, though, I almost wish they were named, as such behavior represents an extreme form of negligence. (I am not advising you to reveal them, though. See, for example, my previous paragraph.)



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: