Hacker News new | ask | show | jobs
by zxcvbn4038 2122 days ago
This is why we can’t have nice things! Citibank had the same issue five or six years ago where once you logged in you could change the URL to any account. I think they lost something like $36 million before the hole was plugged.