Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

211–220 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#211

Earlier quoted context omitted.

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

This is how FB & others track everyone on the web through ad frames, like buttons, etc.

Do they get info about from which page they got requested when one includes just an image?

Re: What Happens When You Send a Zero-Day to a Bank?

#212

Earlier quoted context omitted.

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

> They are still here to protect americans

That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".

Re: What Happens When You Send a Zero-Day to a Bank?

#213

Earlier quoted context omitted.

In order to do so, he would have to actually declare a claim that a particular trade was unauthorised. Assuming that he actually did execute all his trades himself (which, frankly, is quite likely), making that claim in court would be a crime (perjury + fraud), a much serious issue than the security vulnerability. With sufficient preparation it's likely, that the bank (and prosecutors) wouldn't be able to prove that…

How is the bank able to get to get the correct judgement in the civil case? There's proof the bank knew about the security hole, there is proof that at least one person outside of the employment of the bank had discovered this vulnerability (meaning there were likely more), and there is no way for the bank to prove that the transactions were legitimate. The article mentions that unauthorized transactions were indisti…

For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP.

They don't have to prove that it couldn't have been someone else, they have to convince the court that it's more likely than not. Motive matters a lot - if there's some way how that transaction would have been useful for a fraudster (i.e. if it was a money transfer to them), then it's one thing; but if there's no indication of why someone else would want to make the fraudulent trade (which is the case for most stock purchases/sells) and a clear motive why the claimant would want the trade to be reversed (i.e. the stock buy seemed good on that day but turned out to be bad afterwards) then if there's any technical evidence whatsoever pointing towards the claimant, it's hard to be convinced.

If data shows that the transaction is e.g. done from some Starbucks and local security cameras show the claimant near that Starbucks at that time, it's probably not enough to get a conviction but likely enough to make them lose the civil claim.

The criminal case would be expected to get much more evidence than an ordinary civil claim, so they'd likely wait for its results and use everything that the police/prosecutors gathered to dismiss their civil claim.

Re: What Happens When You Send a Zero-Day to a Bank?

#215

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Or you can just post your findings to full disclosure and call it a day.

What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?

Re: What Happens When You Send a Zero-Day to a Bank?

#216

Earlier quoted context omitted.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

> They are still here to protect americans That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".

They were perfectly happy to use the vulnerabilities exploited by Stingray after all.

Re: What Happens When You Send a Zero-Day to a Bank?

#217
post #90

Earlier quoted context omitted.

Not at all. You're making bets based on public information only you have realized is meaningful before informing the rest of the public to make money off that discovery. Quite a few folks make a lot of money this way and (nearly) everyone benefits: https://www.bloomberg.com/news/articles/2015-03-04/how-a-25-...

I agree that making bets by noticing public information earlier is 100% okay (and in the case of Lumber Liquidators, a better outcome for almost everyone). But would this case with the bank be different because the vulnerability, unlike formaledehyde, could be actively exploited? Encouraging a stock price to fall because of bad practices seems alright (like the LUmber Liquidators example), but if in the process you b…

That question has nothing to do with shorting stocks and everything to do with vulnerability disclosure: http://www.blackhat.com/presentations/win-usa-04/bh-win-04-g...

Re: What Happens When You Send a Zero-Day to a Bank?

#218

Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

Just because evidence was not lawfully obtained (ie. call recorded without other the other party's consent where that is requirement of state statute), doesn't necessarily mean that evidence can't be used to protect yourself against a more wide-ranging claim. The various precedents against the use of tainted evidence are mostly used in favor of a defendant and against the state.

A $50 misdemeanor fine for unlawfully recording a phone conversation, may well be a small price to pay - if the content of that recording can successfully protect you from a potentially bankrupting civil case.

And you always have the option of not disclosing the recording if that is your lawyer's recommended advice.

Re: What Happens When You Send a Zero-Day to a Bank?

#220
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

Your statement is 100% incorrect. P.S. It might be of limited correctness, only in some states, in the USA. I'd suggest you don't talk people into signing perfectly valid contracts hoping for an unlikely loophole.

Care to explain why he's wrong, or are we to assume your expertise, random internet person?
Post reply on HN