Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

91–100 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#91
post #73

Earlier quoted context omitted.

This was a test for understanding that a person not familiar with a particular field (e.g. GP and common law) will not be easily able to find a source on a particular aspect of that field and at the same time verify the information are more-less complete. Therefore, it's much easier for someone familiar with the field to provide a link to appropriate source. You, sir, have unfortunately failed that test.

I thought it was significant that they were able to distinguish it as a common-law concept. Are you implying this was something like a lucky guess on their part?

My guess is that 'beefhash is not from a common law country and was only able to figure out for sure that the topic is a part of common law.

Re: What Happens When You Send a Zero-Day to a Bank?

#92

Were cookies shared across sites in 2008? It seems pretty odd..

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

This is how FB & others track everyone on the web through ad frames, like buttons, etc.

Re: What Happens When You Send a Zero-Day to a Bank?

#93
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

This was my question: is this NDA even enforceable and why would the author have signed it?

My reading is that he signed it because he was falsely made to believe he may have done something illegal and this would protect him from the FBI. I.e. he was coerced.

Re: What Happens When You Send a Zero-Day to a Bank?

#94
post #48

Earlier quoted context omitted.

What about NDAs for interviews? What am I gaining (a chance at getting a job doesn't seem like a gain)?

> a chance at getting a job Yes, that is exactly right. > doesn't seem like a gain Why not? If you don't think that's a gain, why are you wasting your time doing the interview in the first place?

OTOH, I've heard that you can't be forced into an NDA with the consideration of only continued employment.

Re: What Happens When You Send a Zero-Day to a Bank?

#95
post #90

Earlier quoted context omitted.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

Not at all. You're making bets based on public information only you have realized is meaningful before informing the rest of the public to make money off that discovery. Quite a few folks make a lot of money this way and (nearly) everyone benefits: https://www.bloomberg.com/news/articles/2015-03-04/how-a-25-...

Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.

Re: What Happens When You Send a Zero-Day to a Bank?

#96

Earlier quoted context omitted.

He was afraid that he was bound by the NDA not to disclose it. Now, in 2017, he flouts the NDA and acts in the public interest.

But why now? What changed?

Perhaps author gained some age and wits.

Re: What Happens When You Send a Zero-Day to a Bank?

#97
post #71

Earlier quoted context omitted.

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

Where do I type it ?

Ctrl + Shift + J

in chrome

Re: What Happens When You Send a Zero-Day to a Bank?

#98

I think they're regarding these things as weapons, because that's how they or others are using them. It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…

Sad part is that if you just posted that link somewhere very public anonymously, it'd have been fixed in minutes and everyone on fraud alert.

Re: What Happens When You Send a Zero-Day to a Bank?

#99

Earlier quoted context omitted.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

The Lumber Liquidators short-seller is quite a famous example of this strategy being executed. Before writing his blog-post, he short-sold a bunch of Lumber Liquidator stock and made tons of money during the fallout.

Martin Shkreli claims to have made a lot of money by shorting pharma companies ahead of their FDA results - he would read their studies and make reasonably accurate predictions as to the outcome.
Post reply on HN