Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

161–170 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#161

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency).

I wonder if an org like the EFF could add this to their scope.

Re: What Happens When You Send a Zero-Day to a Bank?

#162

On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…

Who logs into their bank from a public computer? Genuinely curious.

And the kind of people that don't have access to anything else.

My bank (arguably) condones use from public computers by asking me if they should "trust" the computer I'm on.

Re: What Happens When You Send a Zero-Day to a Bank?

#163

Earlier quoted context omitted.

So far, I count three separate replies to this article along the lines of "I also found my bank doing so-and-so thing insecurely, but LA LA I'm not going to tell you which bank it is!" These kinds of comments don't help anyone--you might as well not post them.

Yeah I genuinely don't understand the point here. Who is protecting what?

So the article mentions the threat of retaliation against the security researcher, and you are surprised people are afraid to come out publicly?

Re: What Happens When You Send a Zero-Day to a Bank?

#164

Earlier quoted context omitted.

I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

It was discovered today that Wells Fargo passwords are case-insensitive:

https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

Re: What Happens When You Send a Zero-Day to a Bank?

#165

I think they're regarding these things as weapons, because that's how they or others are using them. It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…

You could always send an anonymous, or not, tip to KrebsOnSecurity.com. Brian has the skill to handle this kind of disclosure and the street cred to avoid pitfalls.

Re: What Happens When You Send a Zero-Day to a Bank?

#166

Earlier quoted context omitted.

I believe the idea is nobody would willingly sign a contract that does nothing to benefit themselves so they must have been mislead into the agreement thus it is invalid. Sort of a rational actor theory of law.

Isn't the benefit for William that he was provided some confidential information in addition to what he already knew?

Typically yes, access to the information is the proper consideration for agreeing not to further disclose the information. But as lisper says [0], that will also typically be spelled out in the contract.

If a contract doesn't outline consideration, and the jurisdiction requires consideration, then the lawyer writing the contract was not very good at their job...

[0] https://news.ycombinator.com/item?id=14167805

Re: What Happens When You Send a Zero-Day to a Bank?

#167

Earlier quoted context omitted.

Yeah I genuinely don't understand the point here. Who is protecting what?

So the article mentions the threat of retaliation against the security researcher, and you are surprised people are afraid to come out publicly?

I read more in the article so I am updating my comment - the FBI's involvement is surprising and alarming.

When in doubt, people, call your attorney.

Re: What Happens When You Send a Zero-Day to a Bank?

#168
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

I definitely think you're correct. In the future you could probably save yourself the hassle of the "Are you a lawyer?" questions by dropping the phrase "almost certainly" right before "not a valid contract". Most attorneys I know are super reluctant to call a contract invalid without some sort of qualifying language. This contract might actually be egregious enough to warrant an unqualified declaration of invalidity…

Despite the fact that I'm not a lawyer, I happen to know quite a lot about contract law because I was once involved in a contract dispute. That provided quite a good education on this particular topic.

Re: What Happens When You Send a Zero-Day to a Bank?

#169

Earlier quoted context omitted.

Are you a heart surgeon? No but I can read. I'll stick to advice from subject matter experts, not self appointed experts.

There's a helicopter crashed in a house. I don't need to be a pilot to know it's not supposed to do that.

This is actually pretty close to how I personally define a "professional": A professional is someone whose work can only be judged by other professionals of the same domain.

Obvious failure modes are exempted. Anyone can tell you about a bad bridge after it has failed. But it would take a bridge engineer to tell you that before it fails.

https://news.ycombinator.com/item?id=8960822#8963307

Re: What Happens When You Send a Zero-Day to a Bank?

#170
post #124

Earlier quoted context omitted.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

> let the market do what she does best: work. Hm, I recall the Comodo hack. I think it Comodo was hacked twice or more times that year. It won many rewards and continued leading the CA space. The market did not work apparently...

Well, in a way, it did: people voted and said "we don't care la la la what did you just say?".
Post reply on HN