Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

111–120 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#112
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

I agree. There's plenty of "Tester agrees"/"Tester shall (not)", but the document provides nothing of value/benefit in return.

Worth noting that just because it doesn't stand up as a contract doesn't necessarily mean a claim can't be made under breach of confidence (I doubt it would be applicable here, but just pointing out that contracts aren't the only form of legal protection provided to confidential information).

Re: What Happens When You Send a Zero-Day to a Bank?

#115

Nitpick: was this disclosed to a bank or a broker? Not sure it matters tbf

I believe you have picked an actual nit. He reported to Zecco (his actual broker) and Penson (Zecco's clearing firm). Both were SEC-registered broker-dealers at the time, neither were banks.

Re: What Happens When You Send a Zero-Day to a Bank?

#117
post #42

Earlier quoted context omitted.

No damages, assuming no unauthorized trades were executed in his account as a result of the unpatched vulnerability.

Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.

Yeah, but presumably he'd claim it on an asset in the red, and for a large enough amount of money to be worth risking lying about under oath. Zecco could have the court subpoena the ISP to prove the IP was in use at the time by the defendant.

Re: What Happens When You Send a Zero-Day to a Bank?

#118

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

https://www.quora.com/Is-it-legal-to-short-a-companys-stock-...

Re: What Happens When You Send a Zero-Day to a Bank?

#119
post #20
post #2

That's a lot of errors for one document.

I'm also kinda curious why the author didn't run through a simple spell checker before posting. I'm grateful for the article, it was an interesting read, but really why not just paste into google docs real quick or something?

Maybe his editor is on leave.

Re: What Happens When You Send a Zero-Day to a Bank?

#120
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

I agree. There's plenty of "Tester agrees"/"Tester shall (not)", but the document provides nothing of value/benefit in return. Worth noting that just because it doesn't stand up as a contract doesn't necessarily mean a claim can't be made under breach of confidence (I doubt it would be applicable here, but just pointing out that contracts aren't the only form of legal protection provided to confidential information).

> I doubt it would be applicable here

Definitely not. The bank did not disclose the vulnerability to him, he discovered it on his own. He had absolutely no obligation to the bank.

Post reply on HN