TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

National Australia Bank compromises thousands of customer details

37 pointsby GiulioSalmost 6 years ago

6 comments

Sendotshalmost 6 years ago
It’s refreshing to see an actual acknowledgment, seemingly-sincere apology, and clear details of what they’re going to do about it.<p>Their official statement:<p><a href="https:&#x2F;&#x2F;news.nab.com.au&#x2F;nab-apologises-to-customers-for-data-breach&#x2F;" rel="nofollow">https:&#x2F;&#x2F;news.nab.com.au&#x2F;nab-apologises-to-customers-for-data...</a>
naileralmost 6 years ago
I once worked as a contractor at NAB. The kickstart file with root password, which was unchanged, for a 450M AUD corporate banking project was stored on a SMB share accessible to everyone in the bank. Project leaders didn&#x27;t care (since it would involve work to fix). I eventually had to raise it as a hint to a friendly pentester who included it in their report, finally getting it fixed.
MRD85almost 6 years ago
Name, date of birth and contact details (phone and address) are often enough data for a fraudster to commit some serious damage. If I call up my phone company or bank that&#x27;s probably going to cover the questions they ask me to prove identity. Someone transferring my phone can then get past any 2FA I hold.<p>At what point do we hold NAB liable for the potential damage they have caused?
评论 #20572936 未加载
klauslovgreenalmost 6 years ago
This is yet another example of the risks of requiring KYC if banks cannot keep it safe. We need to start to do KYB!
elisharobinsonalmost 6 years ago
i hope the boffins who mandated weaker encryption take notice of this. The congress members who supported the bill for weaker encryption should be personally DOSed.
评论 #20581566 未加载
schappimalmost 6 years ago
Title should be: “National Australia Bank customers have had &#x27;some personal information&#x27; compromised”