FNB small security bug

bar1

Expert Member
Joined
Sep 15, 2008
Messages
4,342
Reaction score
497
Hi, does anyone know if FNB offer a reward if you find security issues?
I think i found a small bug, probably not a big deal....(not log4j....)
 
One would be forgiven for thinking that a prominent consumer focused bank would have a RFC2350 compliant CERT or CSIRT, together with publicly available contact details and (at least) public PGP keys, but sadly FNB seems to believe that putting the SAPS's contact details up will suffice under Important Numbers :mad:

I honestly believe that your finding/s, and subsequent messages would be treated with complete disdain. With SA's banks, this would also be somewhat due to millions of wannabee crackers who have "discovered HUGE security holes" (like scoring a B minus on an SSLLABS test), but without having a reasonably adept, efficient and competent team to evaluate such claims, FNB clearly does not want to know about genuine security issues.

I say fuggem.
 
Hi, does anyone know if FNB offer a reward if you find security issues?
I think i found a small bug, probably not a big deal....(not log4j....)
images
 
What i found will not allow hackers into your accounts, but if it's exploited further...who know?
 
I normally just email it to a few email addresses and then its their baby. Most I ever got over the years was a thanks reply and typically nothing allthough they do tend to fix the reported issues.
 
Top
Sign up to the MyBroadband newsletter
X