Live data from Hacker News

The Bank Job – breaking a mobile banking application

boris.in

21–30 of 42 posts

Re: The Bank Job – breaking a mobile banking application

#21
post #18
post #15

Earlier quoted context omitted.

Nice work OP. You gave them a tech analysis that should be worth some money, for free, at the same time (hopefully) bringing to their attention how bounty programs are a helpful thing for everyone. They should be feeling very lucky about it. However, the thing that worries me with these things is that, what if some "bad guys" already knew about this and exploiting it and now that the bank is aware and might close the…

He is in Sweden. So definitely safer than being in India :-) Adding to that, I don't think bad guys from the computer world would go to great lengths to harm someone from physical world.

I wouldn't be so sure of that.

Being in Switzerland definitely helps, but still, India being a very big country it wouldn't surprise me if they had some really-bad-guys(TM) mafias capable of hurting people in other countries.

Of course, a small thing like this wouldn't necessarily pop up in their radars but still...

I guess part of the reason I think this way is because I live in a country where this is a real threat. Where posting things that real-bad-guys(TM) don't like can literally get you tortured and killed.

Re: The Bank Job – breaking a mobile banking application

#22

Earlier quoted context omitted.

I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.

I lost my wallet once and someone turned it into a nearby business, but with all the cash taken out. Not sure if the finder or the business took the cash but I guess they got their own reward. Not what I would do, but I'm glad they didn't take the cash and trash the wallet..

Don't feel too bad. Could have been a thief at first that just left it on the sidewalk.

Re: The Bank Job – breaking a mobile banking application

#23

Earlier quoted context omitted.

I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.

The interesting question is "Would you pay a reward to a finder (~10%)?".

I would not. It's an insult.

Re: The Bank Job – breaking a mobile banking application

#24

Earlier quoted context omitted.

I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.

The options aren't just returning it or stealing it, they can simply leave it where it is to avoid the hassle of having to return it. Hence why having a custom of paying a reward might be beneficial for wallet losers in general.

Hassle free return, drop it in a mailbox. Leaving it is an option, but the custom of returning things to their owner exists because one good deed begets another.

Re: The Bank Job – breaking a mobile banking application

#25

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

Don't think of it as a bounty. Think of it as payment for services rendered.

Re: The Bank Job – breaking a mobile banking application

#26

It's actually quite heart-breaking to see the extent gone to to reveal the bug, and then to disclose it in full, for zero reward. Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.

The next bug found will be sold on the blackmarket. False economy.

Re: The Bank Job – breaking a mobile banking application

#27
post #7

The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.

OP here. I knew the bank wouldn't pay. But I wanted to initiate a discussion with the bank so they know that paying bounty for disclosures is a thing.

The value of the write-up is a reward at least.

Re: The Bank Job – breaking a mobile banking application

#29
post #17

It's actually quite heart-breaking to see the extent gone to to reveal the bug, and then to disclose it in full, for zero reward. Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.

Presumably any reward would need to be approved by an executive other than just the IT director since clearly they have no policy in place. The IT director would not want his department's incompetence to be known higher up the board. As an aside, the OP claims it took 12 days to resolve but it is possible they took more immediate action by disabling the mobile app's ability to do transfers until they had resolved all…

ah, the benefit of the doubt.

I used to give that out like candy, too.

Re: The Bank Job – breaking a mobile banking application

#30

Earlier quoted context omitted.

The interesting question is "Would you pay a reward to a finder (~10%)?".

I would not. It's an insult.

You should never expect a reward.

You should always give one. Claiming it's an "insult" to thank someone for going out of their way to do something they didn't have to do (v. doing nothing or throwing the wallet out) sounds like an easy excuse to be cheap.

Post reply on HN