Hacker News new | ask | show | jobs
by chriserin 5485 days ago
Along those same lines, if a hacker took advantage of a vulnerability in the banks application, but only after gaining access to that vulnerability through credentials stolen from a client/customer, is the client responsible for weak credentials protection in that instance as well?

This is a slippery slope.

1 comments

That would probably be awarded 50/50.
If the theft was abetted by a product fault in the banks own code, my guess is that the client would get 100 + legal fees.