David Eade is a web developer and web security consultant, based in Billingshurst, West Sussex, UK. Most security vulnerabilities are privately reported to the respective vendor. This blog includes only resolved issues not subject to a non-disclosure agreement.
David Eade exposed a security loophole allowing Cahoot customers to access other peoples' accounts without a password. Customers could log in to other people's accounts using just a username and bypassing any security information. The Cahoot website, run by Abbey Bank, was closed down for 10 hours to carry out urgent repairs. Tim Sawyer, head of Cahoot bank, said it needed to learn lessons from the security breach.
David Eade was interviewed for BBC Breakfast regarding the Cahoot security loophole.
Several newspapers reported the Cahoot security loophole. David Eade is not responsible for the content of these articles or external sites.