TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Proper procedure/etiquette for reporting a security bug to a fintech

2 pointsby mnehringover 1 year ago
Hi - For one of my side businesses, I have a business checking account with a fintech company. (That is, not a bank, but rather providing a user interface on top of an existing bank.) I&#x27;ve been plenty happy with the service (all the features I need, no fees, no hassle). In the course of using my account, I accidentally stumbled across a security bug, where the website will leak other clients&#x27; private information.<p>I tried to get in touch with some higher-ups (co-founder and lead engineer) via LinkedIn, but no luck. I emailed support asking to get connected with some higher ups to report the bug, and they thought I was asking for a job. I called support, and the rep didn&#x27;t seem to understand the nature or the gravity of the security bug, and said they were forward my report to the &quot;accounts department&quot;.<p>Anyhow, what is the normal and proper procedure you would follow to report this to the organization?<p>I appreciate the insight!

1 comment

akerl_over 1 year ago
The normal way for the average company is basically what you&#x27;re experiencing. Eventually you&#x27;ll either get lucky and get a useful response, give up, or publish the vuln to the public.<p>In medium&#x2F;large tech companies, you&#x27;ll often have a security@ or a bug bounty program or some other clear way to report a vuln, but without naming the company there&#x27;s not much we can do to guess how to contact them.