Hacker News new | ask | show | jobs
by tedunangst 4899 days ago
Are you thinking of Heroku? Heroku isn't a bank.
1 comments

It was probably Santander: http://www.h-online.com/security/news/item/Santander-s-onlin..., though there have been other instances of bad bank web practices.
Putting plaintext passwords in a cookie doesn't sound anything like incrementing an integer in a URL.