Hacker News new | ask | show | jobs
by LonelyWolfe 806 days ago
This shouldn't be done directly from the bank but as a third party that is supported by the bank and a bunch of other companies concerned about this.

That way the bank doesn't have to worry about any legal or good will issues from doing this.

1 comments

This is what I had in mind.

Bank.com hires pen-testers to trick people to go to Bank.evil, spill their ID/Password/OTP.