Amex's lack of security is no less interesting if it's discovered by a competitor. It's a pretty serious mistake by an organization you would expect to be more careful and knowledgeable about these things.
True, but read the comments. The organization reporting this is little better. ("Encrypted on the client" - which means they would be horribly exposed to man-in-the-middle attacks...)
What's wrong with it is that it is about as relevant as Microsoft analyzing security problems in OS/X and posting them on their website or Apple evaluating Windows.
It's just an attack on a competitor and a veiled ad.
As for the butthurt, and this comment: http://news.ycombinator.com/reply?id=1379577 I think you're missing the tone of the conversation around you and it makes you stand out in a negative way.
Comments
That's just an ad for 'homerun'.
Find insecurity in competitors service, make loud blog noises, drop payload.
Really, just an ad?
Amex's lack of security is no less interesting if it's discovered by a competitor. It's a pretty serious mistake by an organization you would expect to be more careful and knowledgeable about these things.
True, but read the comments. The organization reporting this is little better. ("Encrypted on the client" - which means they would be horribly exposed to man-in-the-middle attacks...)
By that token, all security advisories are just advertisements for the security researchers' services.
what's wrong with that? i removed that part from the conclusion to help fix your butthurt.
What's wrong with it is that it is about as relevant as Microsoft analyzing security problems in OS/X and posting them on their website or Apple evaluating Windows.
It's just an attack on a competitor and a veiled ad.
As for the butthurt, and this comment: http://news.ycombinator.com/reply?id=1379577 I think you're missing the tone of the conversation around you and it makes you stand out in a negative way.