Earlier quoted context omitted.
Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.
IANAL but there is no risk that you may have to defend that proposition in court as long as you don't actually exploit the vulnerability and simply point it out. It's public information. Now if someone who works at the bank had told you about it, you'd be in a lot of trouble.
What Happens When You Send a Zero-Day to a Bank?
181–190 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#182I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...
Re: What Happens When You Send a Zero-Day to a Bank?
#183There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda.
There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
Re: What Happens When You Send a Zero-Day to a Bank?
#184Earlier quoted context omitted.
Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!
It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...
C-mp-t-rsh-r-: your website's trash and you should be embarrassed with yourselves.
Re: What Happens When You Send a Zero-Day to a Bank?
#185Earlier quoted context omitted.
Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!
It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...
Re: What Happens When You Send a Zero-Day to a Bank?
#186Earlier quoted context omitted.
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
Re: What Happens When You Send a Zero-Day to a Bank?
#187Re: What Happens When You Send a Zero-Day to a Bank?
#188TLS1.2 and proper crypto schemes should be mandatory at this point.
Re: What Happens When You Send a Zero-Day to a Bank?
#189Earlier quoted context omitted.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
So what happens if you find a zero day vulnerability in a Russian bank? Not everyone on the internet is from the US.
Re: What Happens When You Send a Zero-Day to a Bank?
#190Earlier quoted context omitted.
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.