TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

They Can Be You

37 pointsby markarichardsabout 1 year ago

2 comments

HomeDeLaPotabout 1 year ago
Good writeup! It certainly seems absurd for banks, investment firms, government services, etc. to just allow third-party analytics startups to inject whatever code they want in between the user and the product.<p>It&#x27;s like if the bank hired contractors from Google, LivePerson, Tealium, and Yext to listen in on every phone call I make to the bank, for &quot;analytics purposes&quot;. Um, is it really necessary for them to hear my account number and everything? Oh, you say they&#x27;re plugging their ears?
评论 #40119996 未加载
markarichardsabout 1 year ago
The security breaches reported here have been detected by SRI checking bank websites using <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;markalanrichards&#x2F;access-test&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;markalanrichards&#x2F;access-test&#x2F;</a><p>If anyone wishes to help improve this test suite or fork it for other purposes, please go for it.<p>Some may trust Google, Microsoft and co, and I&#x27;m sure some used to trust Fujitsu. However, I encourage you to look at the companies in the list against the banks and see how broadly some banks give remote access to various types of third party companies.<p>Barclay&#x27;s bank aren&#x27;t on the list because the test suite didn&#x27;t find anything. I might have to look into how to move my accounts there.
评论 #40112655 未加载