Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

181–190 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#181

Earlier quoted context omitted.

Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.

IANAL but there is no risk that you may have to defend that proposition in court as long as you don't actually exploit the vulnerability and simply point it out. It's public information. Now if someone who works at the bank had told you about it, you'd be in a lot of trouble.

That's not really true; anybody can sue you if they want, whether or not you're in the right.

Re: What Happens When You Send a Zero-Day to a Bank?

#183

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

> However, there is a risk they would sit on zero days

Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda.

There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

Re: What Happens When You Send a Zero-Day to a Bank?

#184
post #164

Earlier quoted context omitted.

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

It's 2017, and I still have online financial accounts that are "secured" by short numeric PIN, so count yourself lucky that you can at least use some letters in your password.

C-mp-t-rsh-r-: your website's trash and you should be embarrassed with yourselves.

Re: What Happens When You Send a Zero-Day to a Bank?

#185
post #164

Earlier quoted context omitted.

Wells Fargo and Schwab seem ok in my experience. Wells Fargo even updated their site with slick new UI and menu options are actually findable. Amazing!

It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

Just today...? Chase Bank has been case-insensitive for several years now. I even contacted them about it when I found out and they outright told me they had no plans to fix it.

Re: What Happens When You Send a Zero-Day to a Bank?

#186

Earlier quoted context omitted.

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

So what happens if you find a zero day vulnerability in a Russian bank? Not everyone on the internet is from the US.

Re: What Happens When You Send a Zero-Day to a Bank?

#189
post #186

Earlier quoted context omitted.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

So what happens if you find a zero day vulnerability in a Russian bank? Not everyone on the internet is from the US.

It'd be tough to form an international legal entity anyways.

Re: What Happens When You Send a Zero-Day to a Bank?

#190

Earlier quoted context omitted.

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

What makes you say that? Plenty of evidence points to upper management at the FBI and other 3 letter agencies being more interested in power brokering than honesty and serving the public.
Post reply on HN