Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

151–160 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#151

Earlier quoted context omitted.

The Lumber Liquidators short-seller is quite a famous example of this strategy being executed. Before writing his blog-post, he short-sold a bunch of Lumber Liquidator stock and made tons of money during the fallout.

Martin Shkreli claims to have made a lot of money by shorting pharma companies ahead of their FDA results - he would read their studies and make reasonably accurate predictions as to the outcome.

Shkrelli has shuttered two hedge funds (Elea Capital Management & MSMB Capital Management) when he was unable to cover shorts and put options when the stock price moved away from him. He is also currently awaiting trial for securities fraud. So I would take his comments with a grain of salt.

Re: What Happens When You Send a Zero-Day to a Bank?

#152

Earlier quoted context omitted.

Couldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.

In order to do so, he would have to actually declare a claim that a particular trade was unauthorised. Assuming that he actually did execute all his trades himself (which, frankly, is quite likely), making that claim in court would be a crime (perjury + fraud), a much serious issue than the security vulnerability. With sufficient preparation it's likely, that the bank (and prosecutors) wouldn't be able to prove that…

How is the bank able to get to get the correct judgement in the civil case? There's proof the bank knew about the security hole, there is proof that at least one person outside of the employment of the bank had discovered this vulnerability (meaning there were likely more), and there is no way for the bank to prove that the transactions were legitimate. The article mentions that unauthorized transactions were indistinguishable from legit ones:

> Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitimate transactions.

Re: What Happens When You Send a Zero-Day to a Bank?

#153

Earlier quoted context omitted.

Just curious, what would the legal implications of something like that be? It seems like you're still benefitting from criminal activity that you enable, but what would the specific charge (if any) be? And any examples where people have tried this? Although I guess it could help align customer and business goals, since no one wants to lose money

There are law firms working with hedge funds that specialize in doing exactly this when they are about to file a class-action suit. It's possible to be criminally charged if you know that the information you are spreading is false. But other than that limited circumstance, you are free to trade on any information you have about a company that you did not illegally obtain from an insider. Even in the case that the inf…

Great point, I think the tech crowd may overestimate the cost of glitches, relative to everything else at play in a business.

I think the point I'm getting hung up on is that the bank's stock price could drop for two reasons: bad PR due to the glitch, and/or falling financials due to fraud perpetrated as part of the glitch. I can completely understand a hedge fund trading and making money off the bad PR. But if (hypothetically) the bank lost a ton of money by hackers liquidating user accounts or, worse, making leveraged bets [before everyone checked for that sort of thing ;)], and the hedge fund knew there was a reasonable chance that the malicious activity would occur based on the newly disclosed information, would they have liability there? (from the theft/fraud perpetrated against the bank, not the drop in stock price)

Re: What Happens When You Send a Zero-Day to a Bank?

#154
post #79

Earlier quoted context omitted.

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

I think it may be enough to play a beep every few seconds to indicate that the call is recorded. At least that's what a bank I used to work for would do when I called offices in a two-party state.

First, IANAL but I would be very surprised if beeps alone would be considered a legal notification of recording.

Second, those beeps probably exist to reinforce that the audio is unmolested. A beep every 5 seconds means you would have to cut audio in five-second increments, which is not likely to be convenient to whatever segment of audio you actually want to cut.

Re: What Happens When You Send a Zero-Day to a Bank?

#155
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

Consideration is a common law concept as far as I can tell. As someone unfamiliar with how it came to be: Why was consideration introduced? What's the rationale, the goal behind it?

It's what distinguishes a contract from a promise.

If I say, "I'm going to give you some apples in six months, after the harvest" and then there's a blight and I don't actually end up with any apples, society (at least in America) decided that I should be able to just say, "Oops, sorry, I'm not going to be able to give you those apples after all" and be done with it.

On the other hand, if I say, "I am going to sell you some apples in six months, in return for $100", American society collectively decided that I'm on the hook to get you those apples, regardless of whatever difficulties should ensue.

Re: What Happens When You Send a Zero-Day to a Bank?

#156
There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy would be a lawyer.

This is for cases where you want the credit but still want the protections afforded by being somewhat anonymous. Similar to WikiLeaks but more focused on allowing the company or entity to solve their problems and representing fairness on all sides.

Re: What Happens When You Send a Zero-Day to a Bank?

#158
post #49

Earlier quoted context omitted.

IANAL A contract is what lets you sue someone over a private transaction. That's what it does, that's all it does. If for whatever reason you're not willing to bring a contract dispute to court, then your contract doesn't do anything and you wasted your time writing it. Contract = right to sue for breach of contract. In order to sue someone, you need to be able to describe what damages have been done to you. The goal…

"the 'damages' of breaking the contract is equal to the 'consideration' of fulfilling the contract" This is categorically incorrect. Damages for breach of contract are supposed to put you back in the position you'd have been in had the contract been performed. It's not related to the value of the consideration. Consideration is one of the things needed to make a contract binding in English law (along with offer & acc…

> In a "mutual NDA", consideration is easy to find; each party agrees not to disclose confidential information disclosed by the counterparty.

I don't think mutual NDAs are typical. Typically, you sign an NDA prior to receiving information. So the consideration for signing the NDA is receiving the information that you agreed to not disclose. If you already have that information, then that's no longer valid consideration.

In this case, the reporter already knew the security vulnerability, so that knowledge could not be considered consideration. The bank would have needed to offer something else.

Re: What Happens When You Send a Zero-Day to a Bank?

#159

Earlier quoted context omitted.

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

I sent feedback about the WF interface and it was actually addressed with 2 weeks. I was floored.

I clicked the transfer money button from chrome and it logged me out for months if not years. I called them and it still took them forever

Re: What Happens When You Send a Zero-Day to a Bank?

#160
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

I definitely think you're correct. In the future you could probably save yourself the hassle of the "Are you a lawyer?" questions by dropping the phrase "almost certainly" right before "not a valid contract". Most attorneys I know are super reluctant to call a contract invalid without some sort of qualifying language.

This contract might actually be egregious enough to warrant an unqualified declaration of invalidity, in which case you should go the other direction and overstate your case with conclusory statement and some word like "clearly" or "patently". "This contract is patently invalid!" and then explain why.

Post reply on HN