Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

171–180 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#171

I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...

FYI,

Password + token is a common pattern in systems where hardware/software/OTP tokens were bolted on after the fact.

Not just that, but on certain systems (think a Windows login screen, or a POP3/IMAP login for your e-mail client), you can't have a 3rd "token" field -- they're hardcoded to ask for just a username and password.

So vendors came up with the idea of appending the token value onto the password, and their middleware (say, a PAM module) splits the provided value into password and token and validates both.

EDIT: That's not to say that Schwab is doing it right (in the front-end, seriously???), but just pointing it it's not as uncommon as you think.

Re: What Happens When You Send a Zero-Day to a Bank?

#172
post #79

Earlier quoted context omitted.

I think it may be enough to play a beep every few seconds to indicate that the call is recorded. At least that's what a bank I used to work for would do when I called offices in a two-party state.

First, IANAL but I would be very surprised if beeps alone would be considered a legal notification of recording. Second, those beeps probably exist to reinforce that the audio is unmolested. A beep every 5 seconds means you would have to cut audio in five-second increments, which is not likely to be convenient to whatever segment of audio you actually want to cut.

Apparently the legalese is "recorder warning tone" and it should be a 1400 Hz beep every 15 seconds. https://en.wikipedia.org/wiki/Recorder_warning_tone

I mentioned it because someone working for a big organization and making a lot of interstate calls probably hears these beeps all day and would be less likely to protest than if someone verbally announced that they're recording the call.

Re: What Happens When You Send a Zero-Day to a Bank?

#173
post #147

Earlier quoted context omitted.

Who logs into their bank from a public computer? Genuinely curious.

There's plenty of laggards who don't have home internet and only browse through e.g. a library computer. Some of them are probably doing banking too, given the recent trend of preferring online transactions

> laggards

Or, you know, poor people.

Re: What Happens When You Send a Zero-Day to a Bank?

#174

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There's no analogy - what you're describing is literally a lawyer.

Re: What Happens When You Send a Zero-Day to a Bank?

#175

Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

Obligatory disclaimer: IANAL

It's completely legal to record a phone call in Canada as long as you are a party to that conversation. However I still cannot find an app for my Android phone to do this.

Re: What Happens When You Send a Zero-Day to a Bank?

#176
post #168

Earlier quoted context omitted.

I definitely think you're correct. In the future you could probably save yourself the hassle of the "Are you a lawyer?" questions by dropping the phrase "almost certainly" right before "not a valid contract". Most attorneys I know are super reluctant to call a contract invalid without some sort of qualifying language. This contract might actually be egregious enough to warrant an unqualified declaration of invalidity…

Despite the fact that I'm not a lawyer, I happen to know quite a lot about contract law because I was once involved in a contract dispute. That provided quite a good education on this particular topic.

What really made me laugh was "Are you an IP lawyer?"

This isn't even an IP question!

Re: What Happens When You Send a Zero-Day to a Bank?

#177

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Or you can just post your findings to full disclosure and call it a day.

Re: What Happens When You Send a Zero-Day to a Bank?

#178

Earlier quoted context omitted.

There are law firms working with hedge funds that specialize in doing exactly this when they are about to file a class-action suit. It's possible to be criminally charged if you know that the information you are spreading is false. But other than that limited circumstance, you are free to trade on any information you have about a company that you did not illegally obtain from an insider. Even in the case that the inf…

Great point, I think the tech crowd may overestimate the cost of glitches, relative to everything else at play in a business. I think the point I'm getting hung up on is that the bank's stock price could drop for two reasons: bad PR due to the glitch, and/or falling financials due to fraud perpetrated as part of the glitch. I can completely understand a hedge fund trading and making money off the bad PR. But if (hypo…

I believe that responsible disclosure is a courtesy to the vendor and its customers. Afaik, there is nothing in the law that requires it. Exploiting vulnerabilities like the one you are discussing here yourself certainly would be illegal, and you could possibly be implicated in a conspiracy if you disclosed the vulnerability solely to one person or group that you knew would exploit it (so "I told my Russian hacker friend about this..let's short the stock before he nails them with it!" would probably be a conspiracy case, whereas a press release or HN posting would not be).

But general public disclosure of a vulnerability, and/or trading on the anticipated effects of public disclosure, is not illegal. It likely won't win you friends in the IT community, but it falls short of an indictable offense.

Re: What Happens When You Send a Zero-Day to a Bank?

#179
post #164

Earlier quoted context omitted.

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

To be fair, until sometime in the last ~2 years, Schwab PWs were alphanum case-insensitive 6-8 characters only.

Re: What Happens When You Send a Zero-Day to a Bank?

#180

Earlier quoted context omitted.

He was afraid that he was bound by the NDA not to disclose it. Now, in 2017, he flouts the NDA and acts in the public interest.

But why now? What changed?

I like to think that the world's view on network security has changed, even in just the past few years. Companies seem more educated on proper disclosure, network security is now seen as a part of national security and/or common good, and society seems to be shifting the blame for insecurity away from the exploiter and more toward the exploited.

For example, if you'd stolen millions of credit cards in 1983 you'd have a special session of Congress dedicated to going after you, whereas now we (rightly) blame Target.

Post reply on HN