Hacker News new | ask | show | jobs
by varispeed 1274 days ago
> – The online browser-based system was telemetry and JS heavy, replacing a far leaner page

I remember one of those banks using the "leaner" page also had heavy telemetry turned on at some point. I type very fast, so I noticed that when I was entering my user id, it was lagging heavily. Then I turned on developer tools only to see that they were logging all keystrokes to analytics. Including username and password. At first I thought I got a virus or something, but these appeared to be legit scripts from the bank. So I decided to not use that bank account for a while. I wonder why would they turn something like that on.

1 comments

Report that to the regulators.

If you're in the US I know for a fact the regulators listen to and review complaints.

https://www.federalreserve.gov/faqs/credit_12666.htm

You can also report serious problems to FinCEN and the OCC