Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

141–150 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#141

Earlier quoted context omitted.

Better yet: Short their stock, then write a scary blog post about the problem.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

There are law firms working with hedge funds that specialize in doing exactly this when they are about to file a class-action suit. It's possible to be criminally charged if you know that the information you are spreading is false. But other than that limited circumstance, you are free to trade on any information you have about a company that you did not illegally obtain from an insider. Even in the case that the information was obtained from an insider, to convict you, the government must be able to prove that you knew that the insider both a) received a benefit (usually money) in exchange for the information, and b) breached their fiduciary duty by disclosing the information.

That said, technical glitches tend to not affect the fortunes of companies nearly as much as we (the HN crowd) think. Tradeking had the glaring vulnerability outlined in this article for years, and they are doing just fine.

Re: What Happens When You Send a Zero-Day to a Bank?

#142

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

So far, I count three separate replies to this article along the lines of "I also found my bank doing so-and-so thing insecurely, but LA LA I'm not going to tell you which bank it is!" These kinds of comments don't help anyone--you might as well not post them.

Yeah I genuinely don't understand the point here. Who is protecting what?

Re: What Happens When You Send a Zero-Day to a Bank?

#143
post #90

Earlier quoted context omitted.

Not at all. You're making bets based on public information only you have realized is meaningful before informing the rest of the public to make money off that discovery. Quite a few folks make a lot of money this way and (nearly) everyone benefits: https://www.bloomberg.com/news/articles/2015-03-04/how-a-25-...

Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.

Nothing can protect you from the lawsuit being brought, but it will likely be thrown out. That's the same with anything, and whether you short a stock or not.

If you short it, at least you might make some money to offset any pending lawsuit. There's plenty of examples of people doing the same thing to fall back on, such as the guy who found out a newly listed company wasn't actually real[1].

1: http://www.npr.org/2015/01/30/382587945/winning-at-short-sel...

Re: What Happens When You Send a Zero-Day to a Bank?

#144

On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…

Who logs into their bank from a public computer? Genuinely curious.

[deleted]

Re: What Happens When You Send a Zero-Day to a Bank?

#145
There was no value in discussing this over the phone. Clearly their only motivation was to trick him into signing the NDA or foolishly becoming an employee to keep him silenced. Just send in the bug report and empty your account. If the bug persists after 6 months then close the account and go to public disclosure.

Re: What Happens When You Send a Zero-Day to a Bank?

#146

Earlier quoted context omitted.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

I posted this downstream, but it's happened and there weren't charges filed. http://www.pcworld.com/article/3155990/security/stock-tankin...

Great link, thanks for sharing. The quote that stood out to me was “My issue was that patient safety wasn’t front and center.”

I don't have a problem with MedSec making money by shorting St. Jude's stock (that seems to align incentives to take care of security issues as early as possible). But if MedSec publicly disclosed specific, exploitable vulnerabilities (I'm not sure about specifics from the article), they shouldn't be able to hide behind the "doing what is best for the consumer" argument. It's definitely a clever business hack, and that's alright, but the fake sense of moral superiority isn't.

Re: What Happens When You Send a Zero-Day to a Bank?

#147

On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…

Who logs into their bank from a public computer? Genuinely curious.

There's plenty of laggards who don't have home internet and only browse through e.g. a library computer. Some of them are probably doing banking too, given the recent trend of preferring online transactions

Re: What Happens When You Send a Zero-Day to a Bank?

#149

Earlier quoted context omitted.

Maybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.

Is it proven anywhere that it wasn't?

They may have not been logging referrers.

Re: What Happens When You Send a Zero-Day to a Bank?

#150

Earlier quoted context omitted.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

N26 had some of the worst security until a researcher came along. See https://media.ccc.de/v/33c3-7969-shut_up_and_take_my_money

People often confuse lack of published security issues with the existence of strong security. It was the rally cry all along of techies opposing Apple's security-based advertisements.
Post reply on HN