A Norwegian bank leaked the balance of other customers' bank accounts
blog.roysolberg.com
blog.roysolberg.com
That this went unnoticed suggests that:
- the API architect (assuming this web site obtained data via an API, not directly from the database) forgot to validate that requested account belonged to the provided cookie
- the web developer didn't think to test this
- there was either no penetration testing (the author mentioned that this feature was likely released in a rush), or it was not properly performed
Changing it to: Tell me your Sbanken bank account no. and I'll tell you how rich you are
Would be enough.
Although I would prefer: Tell me your Sbanken bank account no. and I'll tell you your account balance
Submitters: the HN guidelines ask you to change a title when it is misleading or baity (https://news.ycombinator.com/newsguidelines.html). This one was both. When changing a title, please look for representative language from the article itself. Usually there's a subtitle or a first sentence that says what the article actually is.
Now you've got data moving off of the server that would have normally been selectively parsed/rendered server-side. It's also easy to use marshalling tools/framework features that serialize entire domain objects, which contain sensitive IDs/data that is then inadvertently leaked. You really have two views to think about; one not as visible.
Not to mention, it can take a lot of additional effort and forethought to expose what you need on the client, so that the UI is robust and responsive, but you're not exposing too much.
And, frankly, some devs naively have in mind the common user, 90% of whom couldn't go beyond what's rendered. So, they are falsely comforted by the idea that the data isn't being shown explicitly in the browser.
Ironically, of course, it's exactly the other 10% they need to be thinking about.
> It's also easy to use marshalling tools/framework features that serialize entire domain objects, which contain sensitive IDs/data that is then inadvertently leaked.
This is just poor code quality. Sensitive data can be hidden in HTML attributes and inline scripts too.
"Not as visible" depends on who is looking.