Kudos for the balls to come public despite NDA.
What Happens When You Send a Zero-Day to a Bank?
131–140 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#132Earlier quoted context omitted.
No damages, assuming no unauthorized trades were executed in his account as a result of the unpatched vulnerability.
Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.
With sufficient preparation it's likely, that the bank (and prosecutors) wouldn't be able to prove that crime beyond all reasonable doubt, and he wouldn't be convicted for it, but it still carries a risk that they could prove that (e.g. by forensic analysis of his computer) and he'd go to jail.
Furthermore, even if he manages to prevail in the criminal case, in the civil case (where the criteria is less strict) it is quite likely that after reviewing all possible evidence they'll manage to get to the correct judgement that the "unauthorised trades" claim was false, thus not getting him anything anyway.
Re: What Happens When You Send a Zero-Day to a Bank?
#133On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…
Re: What Happens When You Send a Zero-Day to a Bank?
#134Earlier quoted context omitted.
Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money
Not at all. You're making bets based on public information only you have realized is meaningful before informing the rest of the public to make money off that discovery. Quite a few folks make a lot of money this way and (nearly) everyone benefits: https://www.bloomberg.com/news/articles/2015-03-04/how-a-25-...
But would this case with the bank be different because the vulnerability, unlike formaledehyde, could be actively exploited? Encouraging a stock price to fall because of bad practices seems alright (like the LUmber Liquidators example), but if in the process you become an accessory to smaller-scale fraud against individual account owners, is it still "alright"?
Re: What Happens When You Send a Zero-Day to a Bank?
#135Earlier quoted context omitted.
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
As someone who lives in Texas, I can confirm that Texas is a one-party state. I specifically do not need to inform people of recording devices if I am a party to the conversation . It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring.
Re: What Happens When You Send a Zero-Day to a Bank?
#136I think they're regarding these things as weapons, because that's how they or others are using them. It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.
That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…
Why should we be strictly ethical in the face of behavior that is unethical? We deserve protection, too.
Re: What Happens When You Send a Zero-Day to a Bank?
#137Earlier quoted context omitted.
"We won't sue you", however, is not consideration.
I wouldn't be so sure - for example, out of court settlements pretty much amount to "We'll pay you $x without admitting that we ever did something wrong, and you agree not to sue us over that thing that we totally did not do.", and these definitely are valid contracts.
Re: What Happens When You Send a Zero-Day to a Bank?
#138On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…
Tell us what bank so we can avoid them.
Re: What Happens When You Send a Zero-Day to a Bank?
#139Earlier quoted context omitted.
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
As someone who lives in Texas, I can confirm that Texas is a one-party state. I specifically do not need to inform people of recording devices if I am a party to the conversation . It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring.
Google is based in California. There is a good probability that the act of recording occurs there. California is an all-party consent state. Also, even if the recording isn't happening in California, it's potentially tricky to be sure that no party to the call is in California (even numbers assigned to landlines don't assure that the person ultimately connecting is in a particular place.)
Re: What Happens When You Send a Zero-Day to a Bank?
#140Earlier quoted context omitted.
Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.
Yeah, but presumably he'd claim it on an asset in the red, and for a large enough amount of money to be worth risking lying about under oath. Zecco could have the court subpoena the ISP to prove the IP was in use at the time by the defendant.