Hacker News new | ask | show | jobs
by smnrchrds 1870 days ago
I thought duping customers [0] to think they were entering their credentials at their bank website while they were giving them to Plaid was bad. But this is some next level malice. How are they still in business?

[0] https://www.ctvnews.ca/business/td-bank-files-lawsuit-agains...

2 comments

They got me with that one once, the frame looked exactly like my bank's login and I thoughtlessly assumed it was some kind of federated authentication handoff. This is apparently enough of a problem that my bank is flagging them as likely fraud.

Seems like this is going to wind up in court sooner rather than later.

I don't understand how this hasn't resulted in criminal charges when they went after Aaron Schwartz for so much less...

If you trick someone into giving your their credentials and use them, how is that not the textbook definition of unauthorized access?