It’s almost as if Monzo know what they’re doing and people just spout rubbish making issues out of nothing.
Good job nobody made an official complaint or drafted a letter to ICO.
If no one did anything then there be rather more data breaches…
Also for reference, ISO material on responsible disclosure: http://standards.iso.org/ittf/PubliclyAvailableStandards/c045170_ISO_IEC_29147_2014.zip
Not necessarily, you can put quite a lot of sensitive information on an invoice…
Yup. Monzo currently do not implement signed URLs so once you publish that URL (or someone works it out…) it’s there for life.
If you want an example of nothing turning to something, look at Tesco. Mixed content alerts lead to insecure passwords turning into Clubcard voucher fraud.
It’s some fun(?) reading: https://www.troyhunt.com/the-tesco-hack-heres-how-it-probably/
I agree, exposed receipts is making something of nothing (unless one of the security questions on your account is how much did you spend recently). But that doesn’t mean you shouldn’t question why Monzo are doing something (and just assume they know what they’re doing).
I’ll all for questioning, especially when it’s a company I like. I want to know they’re doing things correctly. I take issue when forthright claims are made that something is a big issue and that an exploit could be knocked up in no time.
Especially when, even I, can see that that’s not going to be the case.
Apologies for any offence caused
These ‘public’ images are most likely a lot more secure than most people’s password.
True.
Passwords are notoriously weak and actually, password rules (fixed length, containing these chars) make them worse!