Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

51–60 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#51

Earlier quoted context omitted.

I believe the idea is nobody would willingly sign a contract that does nothing to benefit themselves so they must have been mislead into the agreement thus it is invalid. Sort of a rational actor theory of law.

Isn't the benefit for William that he was provided some confidential information in addition to what he already knew?

Possibly. But the contract doesn't say so. This is exactly why the consideration has to be explicit, so the judge adjudicating disputes doesn't have to guess about such things.

Re: What Happens When You Send a Zero-Day to a Bank?

#52

On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…

Tell us what bank so we can avoid them.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service.

I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

Re: What Happens When You Send a Zero-Day to a Bank?

#53

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

Better yet: Short their stock, then write a scary blog post about the problem.

Re: What Happens When You Send a Zero-Day to a Bank?

#54

I think they're regarding these things as weapons, because that's how they or others are using them. It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN.

I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more concerned with threatening me, and trying to find out what kind of criminal angle I was playing, and what my ulterior motive was, etc etc. I honestly expected to hear "Oh dang, that sucks, we'll close the accounts and contact the victims", and was depressed at the hostility I encountered.

Re: What Happens When You Send a Zero-Day to a Bank?

#55

Earlier quoted context omitted.

You need damages to have a class action lawsuit. What are your damages? I am not saying no one has damages, but if 100s of people had damages, I expect something would have happened...

Couldn't anyone who lost money on a stock be able to claim damages? How would the bank prove the purchase order was legitimate seeing as there's basically no security around the endpoint and the bank knew it?

The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.

Re: What Happens When You Send a Zero-Day to a Bank?

#59
post #34

Earlier quoted context omitted.

Consideration is a common law concept as far as I can tell. As someone unfamiliar with how it came to be: Why was consideration introduced? What's the rationale, the goal behind it?

Is this a test? Are we allowed to use Wikipedia? Because Wikipedia has a lot on it.

This was a test for understanding that a person not familiar with a particular field (e.g. GP and common law) will not be easily able to find a source on a particular aspect of that field and at the same time verify the information are more-less complete. Therefore, it's much easier for someone familiar with the field to provide a link to appropriate source.

You, sir, have unfortunately failed that test.

Post reply on HN