Visit John Ratcliffe-Lee's column >>

JOHN RATCLIFFE-LEEHome Page

New Media & Interactive Design Specialist
Add To Watchlist
Articles Posted: 4; Links Seeded: 140
Member Since: 3/2006Last Seen: 11/03/2009

Huge Security Hole in Citibank's Online Account Center

advertisement

I discovered a huge security hole in Citibank's online Account center that lets coComment publish any messages you send to Citibank.

Published to:

What's this?
Who's leading the conversation?
This visualization below allows you to see the impact that each user has on the current conversation. The top row contains the group of users who have had the most impact, the 2nd row the group of users who have had the 2nd most impact (et cetera). Users with similar impact are grouped together, and the average score of the group is shown to the left of the group. The author of the article is also shown on the left, in their corresponding group. Each user's score is based on the number of comments the user has made plus the number of votes their comments have received. The scores are calculated relative one another, so while their absolute value is not particularly important, their relative difference does indicate a larger difference in impact on the conversation.
0.5
{"commentId":594670,"authorDomain":"ageing-hippie"}

Interesting, when I clicked on the image of the letter it took me to a Flickr account

{"commentId":594670,"threadId":"86244","contentId":"618409","authorDomain":"ageing-hippie"}
    Reply#1 - Mon Mar 19, 2007 5:30 PM EDT
    {"commentId":595333,"authorDomain":"jratlee"}

    Correct. That's my flickr account where I have the screen shots stored. Citibank has since been minimally responsive and coComment has posted about it in their official blog. Read more about it here:

    http://blog.cocomment.com/2007/03/19/cocomment-security-and-privacy/

    http://www.openthedialogue.com/2007/03/insecure_messaging_at_citibank.html

    {"commentId":595333,"threadId":"86244","contentId":"618409","authorDomain":"jratlee"}
      #1.1 - Mon Mar 19, 2007 11:53 PM EDT
      Reply
      {"canLink":false,"threadId":"86244","isPrivate":false}
      Leave a Comment:
      You're in Easy Mode. If you prefer, you can use XHTML Mode instead.
      As a new user, you may notice a few temporary content restrictions. Click here for more info.
      {"threadId":"86244","contentId":"618409"}
      Start TrackingStart Tracking
      Stop TrackingStop Tracking