Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are you thinking of Heroku? Heroku isn't a bank.


It was probably Santander: http://www.h-online.com/security/news/item/Santander-s-onlin..., though there have been other instances of bad bank web practices.


Putting plaintext passwords in a cookie doesn't sound anything like incrementing an integer in a URL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: