Don't trust the client
Citigroup Hacked I was recently came across this article about a successful hacking attempt made on Citigroup. In a nutshell the hackers logged into a Citigroup related website and simply changed the query string to access other user’s account data. For example let’s say I just logged into my citicard account and I see this ...