Hacker News new | ask | show | jobs
by bionicbrian 5365 days ago
Oh my gosh man. That's so bad. You simply replace the account ID parameter in the request URL? That's so bad. So so stupid on the bank's part. They should be showering this guy with gifts for pointing out such a stupid mistake to them and they should be going after whoever set up their system like that.