Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is more dangerous than it sounds. As the blog post points out you can only get account balance and last transactions. Here's what's really dangerous: the last transactions.

Say you have one more piece of information: account # and routing #. This can be obtained from any check the person has written. Now you can link their account to your account from your bank's website. Your bank will make some small deposits into their account that you will have to verify. Now you use the security hole discussed in this post and you can find out what the amount of those small deposits was. You have now successfully linked their account to your account and you can withdraw their entire account balance into your account from your bank's website.

Now go to your local bank branch and withdraw your entire account in cash and walk away. So yes, this security hole is bad.



That is very bad. The small deposit + verification is exactly how Paypal used to do account linking - I don't know if they've since added extra steps.


It's how everything I've ever used for ACH transfers does account linking, from Paypal to other banks. They assume, and mostly rightfully so, that if you can view an account's recent transactions, you control the account.


Google also does this method of verification for their Adsense payments -- just type in the amount deposited and your account can now receive payments from Google.


I had once a check stolen. No money was taken, since the bank got suspicious and called me and I told it's not authorized, so they did not pay anything. But I had to close that account and open a new one, because having the check the thief has account # and routing # (the latter is public anyway) so he can initiate electronic transactions from my account without asking anybody. I myself did so on many billing sites - you just given them account number and payment is processed, my bank has no idea if I authorized it or not (in those cases I did, but the bank has no way to verify it).

Security of this system doesn't even deserve the name, the only resort it to catch it after the fact and rely on the bank rolling back the transaction.


...and then prepare for the FBI to show up at your door. You can't open a bank account without producing several pieces of ID bearing you current address. Not discounting the apparent stupidity of BofA relying on caller ID for auhthentication, but it's not quite that easy. Moving money from one account to another leaves a trail.

Still a really bad situation though.


Current address can change. The only reason my bank knows my current address is because I've repeatedly informed them, and it took about half a year and some effort from my side to have them update all accounts and records with the correct address. So the FBI has a good chance of scaring some innocent men living in a rental apartment that was used by some bad guy two years ago. In one place I lived, I regularly got payment demands from various credit companies to the name of somebody that (I suspect) lived there 2 years ago at least (I knew who lived there before me, and that wasn't the bad credit person). So address doesn't give much.


You can easily open up a bank account without ever interacting with a person- some banks, like ING Direct, are almost completely online.


It isn't too difficult to set up a bank account in someone else's name without them knowing. It happens with credit cards all the time.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: