The attack surface on software the size and complexity of a bank's is like the Death Star, except any single rivet being out of place will eventually result in this headline.
I agree that banking software is probably complicated. But really, this bug is a beginners mistake and it shoul dhave never happened.
It is something that the original developers should have known about and also something that the company auditing this code should have seen.
I've been doing software security since 1994, but spent 10 of those years as a dev, and so didn't do my first web pentest until '05. On my first ever web gig, I scored a login prompt with 'OR''=' SQLI in the password field. It's like the White Whale for me now; I haven't seen it again, but I know it's out there. Arrrrrhh.
I can understand and even respect a good pw SQL inject, but they MUST HAVE sat there with pins and needs, giddy, saying to themselves: "It CANT be THIS easy!".
I agree that banking software is probably complicated. But really, this bug is a beginners mistake and it shoul dhave never happened.
It is something that the original developers should have known about and also something that the company auditing this code should have seen.
There is really no excuse for this.