TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The Bank Job – breaking a mobile banking application

135 pointsby deprodersabout 9 years ago

7 comments

jamies888888about 9 years ago
It&#x27;s actually quite heart-breaking to see the extent gone to to reveal the bug, and then to disclose it in full, for zero reward.<p>Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.
评论 #11708292 未加载
评论 #11707833 未加载
franjkovicabout 9 years ago
The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure &#x2F; bounty program.
评论 #11706287 未加载
评论 #11706480 未加载
评论 #11706283 未加载
评论 #11706235 未加载
评论 #11708129 未加载
LukeB_UKabout 9 years ago
Cached copy because the site seems to be struggling: <a href="http:&#x2F;&#x2F;archive.is&#x2F;2FN8G" rel="nofollow">http:&#x2F;&#x2F;archive.is&#x2F;2FN8G</a>
jbaviatabout 9 years ago
Having done similar pentests on similar applications during my previous jobs, you can imagine the level of security many editors have on the pair (client app, server). And we are talking here about a banking application: banks have always been more concerned buy security than other software consumers.
forgingaheadabout 9 years ago
It&#x27;s actually important to name the vendor responsible for this mess so this doesn&#x27;t happen again.
评论 #11706991 未加载
评论 #11707807 未加载
tenerabout 9 years ago
Prediction: in the coming months we will hear about more issues of this kind. This time though it will be mafia inspired by the story, stealing money for real.
udklabout 9 years ago
This is the result of hiring mediocre developers and not performing sufficient security testing&#x2F;analysis and threat modeling.