Comment by megous
14 hours ago
I really doubt there's anything interesting in there, judging from experience of looking at implementations of mobile banking apps and websites. Horrendous API, some intrusive scanning/probing/fingerprinting code and usually pretty weird ass ad-hoc cryptography protocols + some mechanism to try to lock API use to OS vendor giving a blessing for its use, so usually Google has to say, "ok, you can call API of your bank to access your money" or whatever on every single use of the app. (which is one of their ways to increase moat around their walled OS gardens) Otherwise you're out of luck using a mobile app. Websites don't have this issue, yet. Mozilla doesn't gate my access to bank APIs.
Backend will have some shuffling of data around some ledgers + a lot of ceremony around auditing + shit ton of CRUD mess and arcane connections to other systems/institutions. Probably the nightmare of nightmares codebase, if frontends are any indication. :D
Same with healthcare ime. I'm more on the human services side, but I was reversing their apis since pre llm days when I was a relative novice. Many don't even minify, so you can step thru the frontend src in devtools.
And yes, if frontends are any indication, just seeing tip of the shit-berg
There are some days I just hit a raw debugger in AuthForRealThisTime() under a three-paragraph jsdoc written by bot which is itself under the commented-out Auth() function. So many questions arise, and I can burn hours rabbit-holing the stack