Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Big respect for you usually, but I think you're completely wrong here. See my comment a bit upstream - having that sort of access to mortgage/credit card systems would a great way to steal money, or at the very least fudge things up left and right.

Internal access would also include access to low latency markets and internal risk management systems. Being able to see what kinds of trades - particularly in FX - are made across many, many international counterparties would go very, VERY far to make large amounts of cash.

At that same bank, many green engineers had the ability to do trades on behalf of many large counterparties. Lots of room for monetization there - or more.



I helped start a specialty practice at Matasano focused on trading firms and exchanges. That doesn't make me right or anything, but I'm pretty familiar with the attack surface we're discussing. I think the kind of attack you're contemplating is a lot harder to pull off than you think it is. (Not from a technical perspective.)

I have no trouble believing that you can make money from PII stolen from a bank breach. The issue is that the same PII exists in all sorts of other firms that are lower-hanging fruit, both from a technical perspective and from a "degree to which law enforcement will be invested in tracking you down" perspective.

In any case: banks staff decent-sized security groups, but they're generally nothing like the force Google can bring to bear on the same problems. There's a reason Chris Evans works at Google and not at some random bank.


Yep - I was actually hoping to see your talk on Starfighter last week, but work kept me in a different state. :)

My experience has been in finance for the past ten years at an ops/sysad level and can frankly say that security at these places may be a lot worse than you think. Much of it just seems to be out of laziness/not understanding best practice. Attacks would by no means be trivial, but they're certainly possible with (edit: relatively) low risk.

Keep in mind that the finance field is largely based on very, very old legacy systems that only upgrade as a last resort, including patching. Managing legacy systems on top of improper management of organizational complexity leads to some very, very poorly implemented security. It's pretty frightening.

Things I've seen in finance -

(edit: deleted long list that probably shouldn't stay within easy internet accessible reach)


Technical security at financials, especially in application code and especially in application code that is closer to infrastructure than to line-of-business or retail, is very bad.

But the business processes that are driven by that infrastructure tends to be surprisingly manual and/or reversible, and, for reasons having little to do with technical security, is heavily audited.

I think unless you're the online equivalent of the robbery crew from Heat, if you SQLI your way into a bank (or trading firm or exchange) and try to move large volumes of cash directly, what's really going to happen is you're going to end up in prison before you get a spendable dollar.

This is a better conversation over beer than on HN. There's definitely stuff you can do! But I don't think financial firms are low-hanging fruit.


Fair enough - I can definitely see how auditing on a non-technical level would "do the trick".

I'll definitely take you up on that beer ;). hubblefisher at gee mayl.


Isn’t Evans working for Tesla these days?


Yup. Forgot. Thanks!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: