Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

71–80 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#71

Were cookies shared across sites in 2008? It seems pretty odd..

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

Where do I type it ?

Re: What Happens When You Send a Zero-Day to a Bank?

#72
post #42
post #10

Would he not have a case of gross negligence against Zecco if he were a customer? Is there something preventing a lawsuit, outside of the possibly non-binding NDA?

No damages, assuming no unauthorized trades were executed in his account as a result of the unpatched vulnerability.

Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.

Re: What Happens When You Send a Zero-Day to a Bank?

#73
post #34

Earlier quoted context omitted.

Is this a test? Are we allowed to use Wikipedia? Because Wikipedia has a lot on it.

This was a test for understanding that a person not familiar with a particular field (e.g. GP and common law) will not be easily able to find a source on a particular aspect of that field and at the same time verify the information are more-less complete. Therefore, it's much easier for someone familiar with the field to provide a link to appropriate source. You, sir, have unfortunately failed that test.

I thought it was significant that they were able to distinguish it as a common-law concept. Are you implying this was something like a lucky guess on their part?

Re: What Happens When You Send a Zero-Day to a Bank?

#74

Earlier quoted context omitted.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this?

Although I guess it could help align customer and business goals, since no one wants to lose money

Re: What Happens When You Send a Zero-Day to a Bank?

#75
post #46

Earlier quoted context omitted.

No. But I can read.

Are you a heart surgeon? No but I can read. I'll stick to advice from subject matter experts, not self appointed experts.

As you wish. My legal advice comes with a free double-your-money-back guarantee if not completely satisfied.

Re: What Happens When You Send a Zero-Day to a Bank?

#77

Earlier quoted context omitted.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

Better yet: Short their stock, then write a scary blog post about the problem.

This has been done!

http://www.pcworld.com/article/3155990/security/stock-tankin...

A company discovered vulnerabilities in some medical devices, then shorted the stock of the company before disclosing them.

Re: What Happens When You Send a Zero-Day to a Bank?

#78
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

This was my question: is this NDA even enforceable and why would the author have signed it?

Re: What Happens When You Send a Zero-Day to a Bank?

#79

Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

I think it may be enough to play a beep every few seconds to indicate that the call is recorded. At least that's what a bank I used to work for would do when I called offices in a two-party state.

Re: What Happens When You Send a Zero-Day to a Bank?

#80

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

Do they have direct debits yet?
Post reply on HN