Skip to content

Comment on AmEx: "We discourage the use of special characters because..."parent

Comments

They could block whatever location the fake account was accessed from, but the attacker could try one account each from lots of different locations (perhaps through a botnet). For this to be useful the bank would have to lock all account access from everywhere when a fake one was accessed.

at which point the only thing to say is "denial of service"

Additionally, the mined usernames / passwords could still be used to brute force other banking / credit card web sites.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.