Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Whether it's common or not isn't the issue, it's whether it's done at _all_ by banks and suchlike.

My bank on their online site asks for my account number, a memorable piece of data and a 6 digit passnumber that they generate (and I can't change). The passnumber is entered using pull-down menus for each digit, always ordered 0-9.

So, no, an attacker wouldn't have access to all the information they need, but they'd certainly have access to more than they should, in this case, if they're able to take advantage of this, that is.

And it's not just for general users, some sites do often additional functionality in this field for users with accessibility requirements (large on-screen number pads, etc).

So, yes, I'm sure the % of affected sites is low, but just 1 bank whose online system is comprised by this is 1 bank too many.

Even if mouse position tracking is permitted, it should clearly be limited to the current tab. Cross-tab, and certainly, cross-application is just clearly wrong.



agreed, which is why Microsoft should be held to account for not prioritising fixing this problem. However, I felt that the portrayal of this particular hole in the linked article made it out to be more than it is.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: