thewayne: (Default)
[personal profile] thewayne
Basically, Citibank is a bunch of morons. Apparently your credit card number appears in your browser's address bar, so they would type in another number and that account's information would come up.

So it sounds like they validated the account number once, then when the hackers changed the account number, it was never revalidated and Citi's system assumed all future page accesses were valid. VERY bad form when dealing with money.

It is not difficult to pass information back and forth through secure sessions. In fact, it's pretty darn fundamental. I don't understand why a megacorp like Citi couldn't properly implement something like that.

http://www.dailymail.co.uk/news/article-2003393/How-Citigroup-hackers-broke-door-using-banks-website.html

http://it.slashdot.org/story/11/06/14/2046216/How-Citigroup-Hackers-Easily-Gained-Access

Date: 2011-06-18 06:30 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
...I thought it was a tenet of security now that, wherever possible, you don't use important data in your URIs, or at the very least, you don't let your sessions wander around...

Date: 2011-06-18 10:41 pm (UTC)
From: [identity profile] thewayne.livejournal.com
It is. It is a definite tenet. Obviously it doesn't apply to such an important megacorp as Citi.

Date: 2011-06-18 11:29 pm (UTC)
silveradept: A kodama with a trombone. The trombone is playing music, even though it is held in a rest position (Default)
From: [personal profile] silveradept
Clearly not. I have this sinking feeling that when people demand that Citigroup invest the capital that everyone has and is waiting for the "uncertainty" to go away, they'll shrug and say "Sorry. Hacked. Stolen." while their executives light up another cigar with a 100-dollar bill.

January 2026

S M T W T F S
    1 23
45 6 7 89 10
11 12 13 14 15 16 17
18 192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 23rd, 2026 10:29 pm
Powered by Dreamwidth Studios