Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

81–90 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#81

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

The Lumber Liquidators short-seller is quite a famous example of this strategy being executed.

Before writing his blog-post, he short-sold a bunch of Lumber Liquidator stock and made tons of money during the fallout.

Re: What Happens When You Send a Zero-Day to a Bank?

#82
post #71

Earlier quoted context omitted.

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

Where do I type it ?

In Firefox, Ctrl+Shift+K opens the web console.

Re: What Happens When You Send a Zero-Day to a Bank?

#83
post #55

Earlier quoted context omitted.

Couldn't anyone who lost money on a stock be able to claim damages? How would the bank prove the purchase order was legitimate seeing as there's basically no security around the endpoint and the bank knew it?

The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.

Maybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.

Re: What Happens When You Send a Zero-Day to a Bank?

#85

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

Re: What Happens When You Send a Zero-Day to a Bank?

#86

I think they're regarding these things as weapons, because that's how they or others are using them. It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…

Suppose they granted your plan to "cancel the credit card accounts" and "potential fraud source" note on each account.

That's pretty much trying to shut down business with their customers. You don't see how they'd interpret that as hostile? Future actors would know how to apply similar techniques if the outcome was in their favor (e.g. Anonymous suddenly produces a large file of cc#'s and threatens bank!)

> The only thing I asked..

In fact, why were you making demands about how they handle their customer relationships, instead of simply presenting what you'd found?

Re: What Happens When You Send a Zero-Day to a Bank?

#87

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

Attempted stock manipulation, probably

Re: What Happens When You Send a Zero-Day to a Bank?

#88

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

What I love most about n26 is the lack of foreign currency transaction fees.

Re: What Happens When You Send a Zero-Day to a Bank?

#89

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

I posted this downstream, but it's happened and there weren't charges filed.

http://www.pcworld.com/article/3155990/security/stock-tankin...

Re: What Happens When You Send a Zero-Day to a Bank?

#90

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

Not at all. You're making bets based on public information only you have realized is meaningful before informing the rest of the public to make money off that discovery. Quite a few folks make a lot of money this way and (nearly) everyone benefits: https://www.bloomberg.com/news/articles/2015-03-04/how-a-25-...
Post reply on HN