Heh.
What Happens When You Send a Zero-Day to a Bank?
111–120 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#112The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.
Worth noting that just because it doesn't stand up as a contract doesn't necessarily mean a claim can't be made under breach of confidence (I doubt it would be applicable here, but just pointing out that contracts aren't the only form of legal protection provided to confidential information).
Re: What Happens When You Send a Zero-Day to a Bank?
#113https://jeremytunnell.com/2014/12/22/swab-password-policies-...
Re: What Happens When You Send a Zero-Day to a Bank?
#114Re: What Happens When You Send a Zero-Day to a Bank?
#115Nitpick: was this disclosed to a bank or a broker? Not sure it matters tbf
Re: What Happens When You Send a Zero-Day to a Bank?
#116About a month ago I noticed that my bank had a vulnerability - I could access the details and photos of every remotely deposited check. I sent them an email, they took the feature offline in about 2 hours. No bug bounty but oh well.
Re: What Happens When You Send a Zero-Day to a Bank?
#117Earlier quoted context omitted.
No damages, assuming no unauthorized trades were executed in his account as a result of the unpatched vulnerability.
Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.
Re: What Happens When You Send a Zero-Day to a Bank?
#118Earlier quoted context omitted.
Better yet: Short their stock, then write a scary blog post about the problem.
Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money
Re: What Happens When You Send a Zero-Day to a Bank?
#119That's a lot of errors for one document.
I'm also kinda curious why the author didn't run through a simple spell checker before posting. I'm grateful for the article, it was an interesting read, but really why not just paste into google docs real quick or something?
Re: What Happens When You Send a Zero-Day to a Bank?
#120The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.
I agree. There's plenty of "Tester agrees"/"Tester shall (not)", but the document provides nothing of value/benefit in return. Worth noting that just because it doesn't stand up as a contract doesn't necessarily mean a claim can't be made under breach of confidence (I doubt it would be applicable here, but just pointing out that contracts aren't the only form of legal protection provided to confidential information).
Definitely not. The bank did not disclose the vulnerability to him, he discovered it on his own. He had absolutely no obligation to the bank.