10 ms·
0day vulnerability full disclosure: American Express
- ch0wn 15y agoOh wow, unprotected admin tools and an XSS vulnerability on their main homepage that is used for customer logins. That's pretty bad.
- JoshTriplett 15y agoThe utter lack of a mechanism to report bugs, particularly security bugs, seems far worse. I've encountered this problem frequently when interacting with various organizations. The pervasive availability of bug-tracking systems and/or bug-reporting email addresses makes the absence of one quite conspicuous.
- michiel3 15y agoI've many seen organizations applying spam filtering on their security@org.org address, leading to tons of reports ending up in spam boxes without being noticed by the company. The researcher doesn't receive any feedback on his responsible disclosure and multiple reminders, and finally submits the vulnerability to a full disclosure list.
- JoshTriplett 15y agoEven worse: some businesses apply spam filtering to their abuse@ address, which thus rejects reports of spam as...spam.
- deleted 15y ago[deleted]
- avree 15y agoIt's amazing that such a huge oversight can be made. I hope American Express doesn't try to sue this guy.
- wgx 15y agoFinancial services are, of course, among the most cautious of organisations - which makes this kind of glaring mistake all the more worrying. Astonishing.
- alfiejohn_ 15y agoSurely this is just a honeypot?
- asto 15y agoIt could have been. Except, you can't leave your valuables on the street and then arrest someone for breaking and entering when they're stolen!
- mootothemax 15y agoExcept, you can't leave your valuables on the street and then arrest someone for breaking and entering when they're stolen! Agreed, that would be theft: Theft by finding occurs when someone who chances upon an object which seems abandoned takes possession of the object but fails to take steps to establish whether the object is abandoned and not merely lost or unattended http://en.wikipedia.org/wiki/Theft_by_finding http://en.wikipedia.org/wiki/Theft_by_finding
- toyg 15y agoThe admin page is completely unprotected, you don't even get a notice about the system being private. They can't sue him, they wouldn't have a leg to stand on. To me it looks like somebody left a "DEBUG = True" somewhere on the site and went to the beach :)
- mootothemax 15y agoThey can't sue him, they wouldn't have a leg to stand on. Why not? I've been clicking around various US laws and have yet to see any mention about a login screen or "Go away, private!" messages being required before it counts as unauthorized access: http://www.irongeek.com/i.php?page=computerlaws/state-hacking-laws http://www.irongeek.com/i.php?page=computerlaws/state-hackin...
- deleted 15y ago[deleted]
- JoshTriplett 15y agoHence the bug report. :) Misconfiguration, most likely.
- asto 15y ago"Hence the bug report." The story was posted an HOUR ago! They're a bank! Imagine the number of criminals swarming over their website by now. You'd think they'd react quicker. Or maybe the bosses there aren't aware of the implications of this disclosure.
- 9ec4c12949a4f3 15y agoThey've had similar password stupidities in the past as well, 6char alphanumeric is secure according to amex. I'm presently having an issue with one of their internal departments who doesn't know how to set up SSH keys rather than some third-party FTPS over HTTPS software using passwords. The password's nothing amazing but at least they have SSL going on. I'm trying to figure out how to teach them SSH without teaching them how to hurt themselves at the same time.
- jcromartie 15y agoThe admin page is still there. Amazing.
- gulbrandr 15y agoIt seems to be fixed: https://www.americanexpress.com/us/admin/ https://www.americanexpress.com/us/admin/
- epenn 15y agoWhen a major company, especially a financial services company, is subject to public security vulnerability disclosures like this, it should really make other companies stand up and take notice. There is absolutely no excuse for these kinds of vulnerabilities to exist on a production system. When Citibank was recently hacked by simply changing the account number in URLs, that should have been enough for other financial institutions to do an internal security audit to make sure they weren't susceptible to anything similar. Don't wait until it's too late. For the sake of their customers I hope this is resolved swiftly.
- joelhaasnoot 15y agoNot to mention that that's a trivial security mistake. ActiveRecord makes it very easy to just "read" the id, and ignore whether or not the user actually has access to it, or just guessed the id. Any operation using an id needs to be checking if you actually have rights to the object. Yes it requires an extra SELECT before you UPDATE or an extra condition (my ORM doesn't do that), but it's secure.
- viraptor 15y agoIt seems the bigger the company is the more irresponsible they become. In UK in the bank I use, you can activate protection of your debit card / current account (usage analysis, higher insurance), but to do that you need to register with Experian (credit rating company). The process for that is: put your recent bill, bank statement and photocopy of ID in an envelope and post it to them via normal mail. I decided to ignore that great offer and keep my account secure in traditional way. Apparently ignorance with regards to the internet sites is not what causes big companies to act in stupid ways. It's the whole mindset...
- sliverstorm 15y agoI'm pretty sure normal mail is generally quite secure. Sure, there's very little barrier to someone opening your envelope, but perhaps because the ratio of sensitive stuff vs. letters to grandma is so low, I'm not aware of it ever happening much.
- Robin_Message 15y agoSurely a DM message to the AskAmex account, with some actual details written in clear English, not jargon or "hacker lingo stuff" would have been more suitable? Or asking someone on here like Thomas to make a phone call? I understand the argument between full disclosure and responsible disclosure, but if the author could have DM'd it on Twitter. Or posted it on Twitter wholesale, since its now public anyway.
- redthrowaway 15y agoThe operator of the AskAmex account seemed completely clueless on security-related matters. I doubt saying, "visit this URL: https://www.americanexpress.com/?debug=true&heroOverride=%3c%73%63%72%69%70%74%3e%61%6c%65%72%74%28%27%68%61%78%27%29%3c%2f%73%63%72%69%70%74%3e https://www.americanexpress.com/?debug=true&heroOverride... would have registered as a problem for her. AMEX made it incredibly difficult for this guy to report the issue to anyone who had the slightest clue as to its severity. Banging his head against the wall until someone finally clued in would not have fixed that communication issue. Full disclosure just might.
- Robin_Message 15y agoAll the more reason to make as clear and straightforward a declaration as possible. Not "I have vulnerabilities", but a DM saying "American Express is leaking customer information at this URL and it is imperative this is reported to your security department." It's their problem to escalate if they don't understand, but you have to give enough information to make escalation possible.
- danvideo 15y agoAgreed Robin - it's likely that the person operating the twitter account for most huge companies has minimal, if any, interaction with IT/security and its lingo. Speak plainly people.
- redthrowaway 15y ago
- jgrahamc 15y agoWow. All you need to do to activate this is append ?debug to the main American Express URL: https://www.americanexpress.com/?debug https://www.americanexpress.com/?debug
- deleted 15y ago[deleted]
- nyellin 15y agoI empathize with the developer, but this disclosure is wildly irresponsible. It's a pain contacting live representatives at any large corporation. When you're dealing with the financial industry, you should grit your teeth and find a way to do it anyway. If you have no choice, publish a warning about the exploit, but don't release all the details without a long warning period.
- cookiecaper 15y agoFYI, this is one of the few good uses for LinkedIn. If you need to access the engineering department, the ordinary external avenues are usually going to fall flat, and that only becomes increasingly true as the target organization expands. However, hopping on LinkedIn you can find an engineer or someone who at least has engineering buddies within AmEx and similarly monolithic corporations in seconds.
- nhangen 15y agoAs an Amex cardholder, I can attest to the fact that getting in touch with their service reps, should you happen to not have your card on hand, is a pain in the ass. They have many obstacles in place to prevent talking to non-members.
- dhimes 15y agoI agree, but this is a complete fail by AmEx. They don't even have a way to report or check on phishing emails from their contact page. THAT would have been the way I would have tried to get in contact with them to help them out. Hopefully, if nothing else, they'll get some sort of scam alert response. Note to self: It's really hard to automate good customer service.
- mustpax 15y agoNo. It's about time we stop letting the financial industry get away with incompetence. Every other software vendor would be raked over coals for not having a publicly available security disclosure email address and utterly failing to properly route a request via Twitter. Responsible disclosure exists so that vendors have an incentive to respond to vulnerability reports in a timely manner. In fact, it is the responsible thing to publicly disclose vulnerabilities so that AmEx learns to implement a proper security reporting process.
- viraptor 15y agoThis is crazy... when you go to the admin panel https://www.americanexpress.com/us/admin/ https://www.americanexpress.com/us/admin/ you actually get access to user cookies (session ids) which probably allow you to hijack their session (haven't tried it in case it's going to be traced back...)
- uptown 15y agoHere's something I learned from AMEX last week ... if one of your cards gets compromised and you cancel the card, AMEX will continue to allow charges to flow through that old "canceled" number to your newly issued number if those charges are coming from a "trusted recurring entity". I discovered that charges were continuing to flow through a number that I'd canceled due to it being compromised even though I thought it'd been nullified. AMEX explained that their policy is to allow these charges to continue, and it took a number of months before I caught the problem because the charge was coming from a business I continued to have business with. Apparently the person that stole my number had setup a recurring charge with this business as well. To their credit, AMEX removed all of these charges even though they spanned a number of months ... but it caught me completely by surprise that a number I though was canceled was still allowing charges to flow through it.
- pwaring 15y agoThat's standard practice for all cards, it's not just AMEX (I believe the authority is based on the account rather than the card). In the UK, there's no easy way to cancel a recurring payment on a card other than contacting the entity taking the payments. If they refuse, you can complain to the card provider and they will eventually sort it out, but payments will still go through in the meantime. Moral of the story: Don't let anyone have a recurring payment authorisation on your card.
- felipemnoa 15y agoYou can always close the CC account completely. Not ideal but it will work hard and fast.
- pwaring 15y agoEven if you do, you're still liable for any charges which hit the account after it's been closed, at least according to every closed account letter I've received (in the UK, not sure what the process is in other countries). Plus you can't close an account until the balance is clear.
- Nitramp 15y agoThe author should have contacted the email addresses given in the DNS WHOIS (amexdns@aexp.com, gtld@aexp.com) and the obvious aliases (security@...). However I can understand and sympathize, it's enraging how hard it is to get into contact with a person of any kind at certain companies (KLM/Air France, I'm looking at you). I understand they want to save money, but if you run a business, you have to be contactable in one way or another. And snail mail as the last option really doesn't cut it in the 21st century.
- asto 15y agoExtremely hard to get in touch with Google as well. And you only tend to realise it when something goes horribly wrong - like when your adsense account gets suspended.
- eli 15y agoYeah, but it's not hard to report a security problem: https://www.google.com/appserve/security-bugs/new?rl=usrwf3z65ebo2rey87mtsxmr https://www.google.com/appserve/security-bugs/new?rl=usrwf3z...
- joelhaasnoot 15y agoKLM has a very good social media service department and should respond to most if not all question...
- Nitramp 15y agoI did get contacted by a Twitter account after venting there, but after DM'ing (160 characters?!) my request, they couldn't help me either. Really, why not just provide an email address? If you have someone listening and responding at @KLM in any case, why not also accept emails instead of the crippled communication possible through Twitter?
- diziet 15y agoIndeed, checking the whois for emails and other things could easily work.
- jgrahamc 15y agoSome years ago when I was doing more stuff in spam and phishing I came across a phishing site for a small US bank. The list of phished card details was available through the interface and it was clear that there were some real people local to the bank who had given their name, address, card number, PIN, SSN, ... everything. I decided to contact the bank. After filling in the form for contact on their web site giving all the details of the site, I did get an email back and eventually I got someone on the phone. This person (who said they were in charge of bank computer security) thanked me and said that they were going to try to deal with it (I had also contacted the school district whose computer was hosting the site to get it shut down). I then told this person that there were real account details on the phisher site and would they like the list of people's account numbers so they could inform their customer/shut down their debit card etc. The bank officer replied, "No." As far as they were concerned the people who were that stupid got what they deserved. I was flabbergasted, but couldn't do much to make the bank do something. So, using the names and addresses of the people from the phishing site I managed to track a couple of them down (they were small businesses whose business addresses were available on the web) and phoned them up so they would be alerted. They took it pretty well considering that some weird British guy was calling them from France to tell them their US bank account details were at risk.
- aw3c2 15y agoIn my opinion that would have justified alerting the local press.
- click170 15y agoLocal? Just local? I'd be as noisy about it as I could, and I would have informed the people who's info had been compromised as to just what the bank said when you offered them a list of compromised accounts. Wouldn't you want to be informed if your bank was intentionally leaving your personal info and financial well-being at risk?
- toyg 15y agoSounds like they were trying to avoid liability. If you know person X has had his account hijacked, and you do nothing, you're probably liable under some law or another. If you don't know the exact identities involved, you can feign ignorance and probably get away with it.
- clistctrl 15y agoWow. This is a huge vulnerability. I hope they fix this very soon. The cognitive dissonance going on with that twitter conversation makes me think he was talking to a bot. Also I love the "These cookies are secure" bit on the admin interface.
- deleted 15y ago[deleted]
- aiham 15y ago// don't ask me how exactly, but this gets the main domain froma hostname; This explains a lot. What I don't understand though, is why this guy, who doesn't understand basic regular expressions (the expression is also wrong), is working on the American Express website.
- danso 15y agoThe regex: // don't ask me how exactly, but this gets the main domain froma hostname; var hostArray = /([^.]+(.com))$/ LOL.
- mml 15y agoTarget.com had an almost identical problem on their newly designed site (years in the making).
- rgarcia 15y agoCan someone explain the origin or meaning of the word "hero" to describe primary marketing/call to action sections? I saw it first in the twitter bootstrap code [1], and now here. [1] view-source: http://twitter.github.com/bootstrap/examples/hero.html http://twitter.github.com/bootstrap/examples/hero.html
- seclorum 15y agoHero;- An entity which is idealized for possessing superior qualities in any field. It is someone / something that is promoting your company or product, and is a 'hero of the product X' being promoted. Kind of like how, if we mention it to our friends, we become 'heroes of hacker news' ..
- showerst 15y agoI'm not so sure about the origin, but it's commonly used in design/UX to showcase one primary or "Hero" product, and refers to a large space front-and-center above the fold on a page. Think apple's site putting up a huge iPhone image on release day (http://www.sprint.com http://www.sprint.com is another good example). I think this likely started in physical product sites and the lingo just stuck.
- danso 15y agoFor the longest time, American Express had a password system that only allowed 8 alphanumeric characters and was case-INSENSITIVE. Moreover, sometimes the AJAX used to submit your payments did not activate, and often, no feedback at all was given if a payment did go through. This kind of vulnerability seems par for course for their tech team.
- john_b 15y agoSince AMEX caters to wealthier customers you would think that they would be on top of this kind of thing...
- gcp 15y agoFWIW, on his homepage there's also a nice small vulnerability in reCAPTCHA. The Google developer who wrote the buggy code actually had to do a hack to shut up PHP warnings about it. Duuuh...
- 9ec4c12949a4f3 15y agoIf this gets taken down, here's a mirror, making any such legal threats pointless: http://pastebin.com/d9npXm5A http://pastebin.com/d9npXm5A
- fred10 15y agoI don't think this is anything dangerous. All the data is static, its just some sort of demo. It doesn't matter who goes to the page, they will always get the same data, it never changes. I'm not a customer so can't try once logged in. If I was to wildly speculate, I'd say honeypot.
- djwelch666 15y agoThis is dangerous! Someone has left the debug=true in the config somewhere. Anything could be possible on the site, not just the script injection in the url and the debug page, but a lot of other stuff as well. When the debug flag is true on our sites, we have a link which will authenticate us as an admin without any credentials for example!
- rufibarbatus 15y ago> When the debug flag is true on our sites, we have a link which will authenticate us as an admin without any credentials for example! Well, get rid of that and push for a change in your company's workflow. This kind of control shouldn't be deployable to the main servers at all. Have separate, staging servers and run your tests and debugging interfaces on it, but as much as possible, don't deploy administrator interfaces to the servers that talk to the customer. [1] [1] I'm undecided which kinds of heisenbugs would justify breaking that lemma.
- phpnode 15y agohuge glaring XSS vulnerability on a credit card company's homepage is not serious? This kind of stuff is a phisher's dream
- demetris 15y agoThe first three Twitter messages by the vulnerability reporter are: “@AmericanExpress Who can I contact regarding security vulnerabilities in your system? I'm not available through phone, physical mail or fax” “@AmericanExpress Just to clarify: I have vulnerabilities. This should be "urgent", so no technical support jungle please :-)” “@AmericanExpress I've been trying to get in touch with AMEX regarding security vulnerabilities in your system for a while. Who do I speak to?” I think this is not ideally expressive language when you talk to a lay-person representative on Twitter. I believe a better result could be achieved with simpler and clearer language: “@AmericanExpress I have discovered a serious security issue in your web system (money can be stolen). Please help me report it to someone responsible.”
- danvideo 15y agoyep, credit that the guy partially tried - but prefacing your first interaction about a serious issue by "I'm not available [to contact through most of the usual communication methods]" is sort of self-defeating.
- nknight 15y agoHe's reporting a vulnerability on a website. It is absolutely reasonable to expect to be able to report it through email, and utterly ridiculous of AMEX to refuse. That's where the conversation ends, not with "well, you should spend your time fighting through these costly and obsolete mechanisms so you can do us a favor".
- deleted 15y ago[deleted]
- sudonim 15y agoDoes going to the url https://www.americanexpress.com/us/admin/ https://www.americanexpress.com/us/admin/ constitute "computer hacking"? It's not protected in any way, shape or form.
- deleted 15y ago[deleted]
- mootothemax 15y agoDoes going to the url https://www.americanexpress.com/us/admin/ https://www.americanexpress.com/us/admin/ constitute "computer hacking"? It's not protected in any way, shape or form. I believe that the level of hacking/cracking required is irrelevant to most laws around the world; if you're not meant to be there, you're guilty of an offence. I'm sure lawyers could argue intent all day long, but whether or not a logic screen appears is irrelevant.
- Evgeny 15y agoif you're not meant to be there, you're guilty of an offence. But how would I know? If someone's private property is not marked as such in any way, would I be a trespasser if I wander into it? Let's say it's part of a field or a forest, not a building with doors ...
- mootothemax 15y agoBut how would I know? If someone's private property is not marked as such in any way, would I be a trespasser if I wander into it? According to this page (the first result I found in Google - there may be more reliable information out there), it's not an easy question to answer: http://www.ucc.ie/law/odg/messages/060222b.htm http://www.ucc.ie/law/odg/messages/060222b.htm Can trespass to land be committed without fault? The answer should be obvious but I have found it surprisingly difficult to track down. I am referring, not to cases of involuntary entry onto land (there are clear cases saying no liability if you get pushed or fall unconscious), but to the sort of case where you (without carelessness) cross over someone's boundary in the bush (maybe more likely in Australia than the UK!) without knowing it
- maxniederhofer 15y agoThey knew this was open. They even took it out of their robots.txt :) https://www.americanexpress.com/robots.txt https://www.americanexpress.com/robots.txt User-agent: * Disallow: /us/admin/ Disallow: /us/heroes/ Allow:
- spdy 15y agoThen there is more behind as we think. Actually we can be pretty sure someone on the web team will have pointed out that this is not good and insecure. After seeing this i kind of get the idea why this url is in the wild.
- coenhyde 15y agoI apologise in advance for a lack luster comment, but seeing incompetence on so many levels like this on a monthly basis from financial institutions makes me want to be sick. This is like putting a sign out the front of your house saying please do not enter though the back window, it's open.
- jrockway 15y agoI look at this as a good thing. I know that if I am ever injured in such a way as to receive severe brain damage, I'll still be able to get a high-paying programming job.
- gulbrandr 15y agohere is another robots.txt file: https://home.americanexpress.com/robots.txt https://home.americanexpress.com/robots.txt
- JonnieCache 15y agoCrawling robots.txt files is a great way to find fun stuff in general.
- pbz 15y agoWhen you go through the regular PCI compliance scan they actually warn you about this...
- duncan_bayne 15y agoTyping this up in real time ... I called American Express Australia to report the defect & I was transferred through to the American call centre. The CSR to whom I spoke transferred me through to a different department, after I explained that I didn't have an account. She did ask whether "I received an email" which I assume was some sort of inquiry as to whether I had been phished. I then spoke to an online services rep., who after asking for my card number, listened to my report. She then put me on hold. (The call had taken 10 minutes by this time). After a few more minutes on hold, the CSR came back on the line, asked me to repeat the information, and confirmed for the umpteenth time that I don't have an American Express card. I explained that it wasn't my find, but that it had been published online & so was by now _very_ public. (15 minutes by this time, most of that on hold listening to advertising for American Express, including some ironic praise for their website). CSR comes back on the line. She's spoken to her 'technical team' who assure me that there's nothing insecure going on because it's all over HTTPS. So I politely walked her through the process - visit the page, add ?debug to the URL, click the admin link & behold: lots of should-be-secure stuff. At this point she thanks me profusely, & asks that I hold while she speaks to her supervisor. Back to the American Express ads ... (20 minutes at this point). The CSR came back on the line, thanked me again, & said that her supervisor had taken a screenshot of the issue & escalated it. Job done. So, yeah, I can totally understand the frustration experienced by the guy who discovered the vulnerability. But it certainly wasn't impossible for me to report the issue, & I'm in Australia.
- duncan_bayne 15y ago(I didn't mention that there was a pregnant pause after she clicked the Admin Home link & saw the admin page in all its glory. I think the only sound was, as Scott Adams put it, the sound of eyeballs getting really big.)
- rufibarbatus 15y agoFunny thing is: he didn't even try that, because he didn't accept under any circumstances to communicate by phone, fax or snail mail. He made this big, boldface disclaimer with twitter screenshots and all trying to claim "best effort is good enough" and "they won't listen", but all I saw was them listening and him refusing to speak.
- gospelwut 15y agogoogle + "Amex security response team" = eirp@aexp.com also http://www.reddit.com/r/netsec/comments/l2uzj/0day_full_disclosure_american_express/c2pbt39 http://www.reddit.com/r/netsec/comments/l2uzj/0day_full_disc...
- pbhjpbhj 15y agoDon't you think then that if you asked their customer services via twitter for a way to report a security issue that the customer service rep should have sent that address?
- gospelwut 15y agoShould have? Maybe. But, with corporations that size it's unlikely. I'm not saying this fall entirely on him, but I feel he didn't exactly do his fullest before puling the trigger on the full disclosure.
- yahelc 15y agoThis is kind of a cool debug interface. Anyone feel like forking it and putting it on Github?
- slpollack 15y agoI work at AXP and have escalated internally
- 0x12 15y agoI'll bet you that reporting this on HN is a more effective way than going through channels.
- simon_weber 15y agoUnfortunately, I've had this kind of difficulty far too often when reaching out to large companies with disclosures. Most recently, the only thing that worked was blasting off an email to all the internal people I could find through google: the CTO, vp of engineering, and head of support were on the list, as were a few lower level employees. The lower level got back to me right away, eager to cc the CTO on their response =)
- chaz 15y agoNext time, I would try reaching their Public Relations group for help. PR people are almost always accessible by name, phone, and email -- they're usually on the bottom of every press release that goes out. They also have good internal channels to every part of the company and know who to contact. Googling for "american express public relations" turns up a page with three NY-based vice presidents, with direct lines and email addresses listed: http://about.americanexpress.com/news/media_contacts.aspx http://about.americanexpress.com/news/media_contacts.aspx
- InclinedPlane 15y agoUnrelated, it looks like someone at AmEx finally improved their crazy, broken password system at least, this used to be the password requirement: "Your Password should contain 6 to 8 characters . at least one letter and one number (not case sensitive), contain no spaces or special characters (e.g. &, >, , $, @) and be different from your User ID."* Now it's this: "Your Password must be different from your User ID, must contain 8 to 20 characters, including one letter and number, may include the following characters: %,&, _, ?, #, =, -, cannot have any spaces and will not be case sensitive."
- desigooner 15y agoIs the "will not be case sensitive" just a typo or do they enforce case insensitivity?! If they do, that's horrendous.
- InclinedPlane 15y agoI assume it means that case insensitivity is a "feature" of the password system.
- aidenn0 15y agoTry logging into various sights with a case-flipped version of your password, you'd be surprised(horrified?) how often it works
- jrockway 15y agoSo 90 comments and no mention of "didn't he try emailing security@americanexpress.com". That would be my first step, not harassing a marketing account on Twitter. Marketing campaigns are often run by third-party companies. Whoever gets security@ emails, not so much. If you want to inflate your ego, post to full-disclosure; don't annoy people on Twitter and blog about it.
- eric-hu 15y ago08:39 PST: the page says it's removed for me. https://www.americanexpress.com/us/admin/ https://www.americanexpress.com/us/admin/
- funkah 15y agoUgh, it would just be easier to sell the vuln than try to inform one of these clueless dinosaur companies about it. I know why companies like Amex build these giant fortresses around their communications, but they should be more cognizant of the damage that can cause.
- eykanal 15y agoCheck out the site now, it looks like this has been fixed. At the very least, not bad response time on their part once they got wind of it.
- mkramlich 15y agoprotip: if you're a bank or credit card company you need top security folks and procedures. just a thought.
- rdl 15y agoI don't consider telephone contact for security vulnerabilities to be that unreasonable. They should support PGP encrypted email, yes, and have a page about how to report incidents, issue tracking numbers, etc., but it took me ~3 minutes on the phone to get the right info for Amex corporate security.