Hacker News new | ask | show | jobs
by lclarkmichalek 4901 days ago
It was probably Santander: http://www.h-online.com/security/news/item/Santander-s-onlin..., though there have been other instances of bad bank web practices.
1 comments

Putting plaintext passwords in a cookie doesn't sound anything like incrementing an integer in a URL.