Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
What Happens When You Send a Zero-Day to a Bank?
191–200 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#192Earlier quoted context omitted.
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
Obligatory disclaimer: IANAL It's completely legal to record a phone call in Canada as long as you are a party to that conversation. However I still cannot find an app for my Android phone to do this.
Re: What Happens When You Send a Zero-Day to a Bank?
#193There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
There's no analogy - what you're describing is literally a lawyer.
Re: What Happens When You Send a Zero-Day to a Bank?
#194Re: What Happens When You Send a Zero-Day to a Bank?
#195Wow. Going on with your life as a C-level executive with this knowledge, as if it's just all good, is just insane. I'm sure they're in the clear personally now, but I can certainly see why they would wanna sell their company fast after gaining this knowledge in 2010.
> I'm sure they're in the clear personally now Don't be so sure. If they didn't disclose this to their buyers they are guilty of fraud. The statute of limitations has probably run out (I don't know which state has jurisdiction here), but delayed discovery rules may apply.
If I were a betting man, I'd bet the buyer knew about the issue and basically didn't care.
Re: What Happens When You Send a Zero-Day to a Bank?
#196There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Re: What Happens When You Send a Zero-Day to a Bank?
#197Earlier quoted context omitted.
> I'm sure they're in the clear personally now Don't be so sure. If they didn't disclose this to their buyers they are guilty of fraud. The statute of limitations has probably run out (I don't know which state has jurisdiction here), but delayed discovery rules may apply.
I'm not so sure it's fraud for 2 reasons: 1) how easy it would/should be for the buyer to discover the issue; 2) these transactions generally have very detailed disclaimers / disclosure -- basically making them 'as-is' transactions. If I were a betting man, I'd bet the buyer knew about the issue and basically didn't care.
This is negligent. If they are running banking ecommerce infrastructure and are unable to deal with 101 security risks then it is absolutely negligent. The "it is too complex for the average person" isn't an adequate defense.
The only thing is that there has to be someone who lost something of real value for it to go to court as negligence does it not?
Re: What Happens When You Send a Zero-Day to a Bank?
#198Earlier quoted context omitted.
Martin Shkreli claims to have made a lot of money by shorting pharma companies ahead of their FDA results - he would read their studies and make reasonably accurate predictions as to the outcome.
Shkrelli has shuttered two hedge funds (Elea Capital Management & MSMB Capital Management) when he was unable to cover shorts and put options when the stock price moved away from him. He is also currently awaiting trial for securities fraud. So I would take his comments with a grain of salt.
Re: What Happens When You Send a Zero-Day to a Bank?
#199Earlier quoted context omitted.
First, IANAL but I would be very surprised if beeps alone would be considered a legal notification of recording. Second, those beeps probably exist to reinforce that the audio is unmolested. A beep every 5 seconds means you would have to cut audio in five-second increments, which is not likely to be convenient to whatever segment of audio you actually want to cut.
Apparently the legalese is "recorder warning tone" and it should be a 1400 Hz beep every 15 seconds. https://en.wikipedia.org/wiki/Recorder_warning_tone I mentioned it because someone working for a big organization and making a lot of interstate calls probably hears these beeps all day and would be less likely to protest than if someone verbally announced that they're recording the call.
If so, as you point out it seems like an interesting way to avoid having to announce the recording to those not knowledgeable.
EDIT: I don't know how reliable this site is, but it seems to indicate the recording beep is sufficient for notification, but not sufficient for consent, which makes sense.
http://www.justanswer.com/criminal-law/5dj81-question-record...
Re: What Happens When You Send a Zero-Day to a Bank?
#200Earlier quoted context omitted.
Yeah, but presumably he'd claim it on an asset in the red, and for a large enough amount of money to be worth risking lying about under oath. Zecco could have the court subpoena the ISP to prove the IP was in use at the time by the defendant.
Of course it was from his IP, the only way the transaction works is if your browser has the proper cookies. The whole vulerability is that all someone has to do is put that into ANY webpage you visit and so long as your browser still had the cookies, the transaction would go though without you needing to do anything.