Skip to content

Comment on Bank harrasses user because he tweeted screenshot of their SSL certificateparent

Comments

I used to write trading software - had test FIX accounts on live cbot, cme, xetra, Liffe, lme, etc.

Decided to see if I could still log in to any of them about a year ago. Still could on half of them. I left that gig a decade ago.

Oh, and a few of them have no trade limits or risk management.

Boggle.

20+ years I had some security discussions with a major exchange in the USA. In the same building were offices of Goldman Sachs and another bank (Morgan or Merril, don't remember). Anyway there was a single thinnet (10base2 ethernet) that connected them to the exchange. Yep, a quick sniff showed that everyone could see everyone else's traffic.

My contacts were genuinely surprised that this was even possible. But also I was told there would be no contract if I mentioned this to upper management in my report.

There was no contract.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.