3 ms·
> when someone finds and exploits a weakness in your library to take my money, I'm screwed. I'm not sure what kind of exploit or weakness you are thinking abou
by javiercr 10y ago
> when someone finds and exploits a weakness in your library to take my money, I'm screwed.
I'm not sure what kind of exploit or weakness you are thinking about. But the risk of using Bankscrap's gem from your computer is similar to using your bank's mobile app. Bankscrap itself doesn't store any data nor send your credentials to any place other than your bank's API (the same that your mobile app does).
In other words, if you use Bankscrap's gem to build a web app to fetch and store your bank transactions (or someone else's), and your webapp or server gets hacked, obviously the responsibility is yours.
- adrianN 10y agoWho pays when the open source library triggers a bug in the bank's computer and takes the whole system offline?
- javiercr 10y agoIf you had your own API exposed to the internet and someone made an HTTP call that "triggers a bug" in your server "and takes the whole system offline", would you sue the guy who made the HTTP call or would you assume it was a bug in your server / app? And we're not talking about HTTP calls with SQL injection or things like that. We're talking about identical HTTP calls to the ones that the banks' mobile apps do. Same headers, same body.
- adrianN 10y agoIf they're identical to the official app, they likely won't trigger an unexpected case. If they're not identical (maybe your open source lib has a bug, or the API changed) I could see lawyers trying to sell it as a deliberate hacking attempt to a court.
- dandermotj 10y agoThe open source library simply helps a programmer put together HTTP requests. If an API crashes because it receives an unexpected HTTP request its certainly not the requesters fault.
- drvdevd 10y agoAlso, if it's their public API used by their mobile/web apps, it would likely be crashing all the time anyway from normal user interaction (if some OSS were able to crash it via HTTP).
- rhizome 10y agoNah, you can totally walk a tightrope where one's app is never crashes the API, but only because it has no input fields that allow you to try to transfer currency in the amount of "spaghetti" from one account to another.
- dfox 10y agoThat is reasonable technical approach to the problem, but not how the courts work. On the other hand in court also should ask and answer the question of whether you triggered such behavior intentionally or not.
- synctext 10y agoAt Delft University of Technology we're working on this also for about 2 years. Currently 8 (big) banks reverse-engineered, the smartphone way (no scraping). Besides universities there are not many non-profits that will have the legal and financial means to publish an open source lib. The legal landscape for managing a complete library with numerous banks is complex. As we see in this discussion thread, there are some fragmented solutions with limited coverage. https://github.com/Internet-of-Money https://github.com/Internet-of-Money (empty placeholder)
- javiercr 10y agoWhat's the best way to contact you guys? :)
- xorcist 10y agoYou make it sound silly. But the "unexpected HTTP request" may in fact be a SYN flood (yes, that has happened), or looping some non-trivial request for an ad-hoc DoS. That is indeed the requesters "fault", even if there is clearly no intent and hopefully no legal ramifications.