Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

221–230 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#222
post #55

Earlier quoted context omitted.

The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.

The article covers this: >Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitemate transactions.

That doesn't really matter that much. The customer would have to show they were harmed. So if you were playing around with certain stocks, decided you didn't like the outcome and are now going to sue, you'll need to provide some proof that you didn't make that transaction.

If you kept buying and selling on that account, including with the supposedly-hacked-purchased shares, you'd need to explain why you didn't bring it up until now.

Re: What Happens When You Send a Zero-Day to a Bank?

#224

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043...

This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185

HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the vulnerability with the organization so it can be resolved.

Seems like it address most of the problems of educating the organization so they don't threaten you.

Re: What Happens When You Send a Zero-Day to a Bank?

#225

Earlier quoted context omitted.

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

While it may be true that in this particular instance the FBI might act benevolently, the idea was that it would be nice if there was an organization you could go to with any zero day bug. Even if the FBI is not mismanaged and always tries to protect Americans, you could easily imagine a scenario where someone reports an exploit to an OS where anyone can remotely install a key logger. The FBI wouldn't be a good organization to report this to because they may want to use this to track down criminals which, they would no doubt feel, would greatly outweigh the cost to Americans that the zero day represents.

The EFF seems like a good choice. In general you would need to pick an organization that does not have a vested interest in using exploits.

Re: What Happens When You Send a Zero-Day to a Bank?

#226
post #221

>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts Pardon my ignorance, but how would this work?

I felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says:

"But this only affects people that are logged in, right? Yes ..."

So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser.

If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with the IMG tag in a webmail client), the browser will enclose the cookie in the header of the request. This makes the request automatically authenticated.

Re: What Happens When You Send a Zero-Day to a Bank?

#228
post #224

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…

Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.

Re: What Happens When You Send a Zero-Day to a Bank?

#229

Earlier quoted context omitted.

Or you can just post your findings to full disclosure and call it a day.

What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?

It's "broken window" community policing.

The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community.

It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visible broken window indicates a higher incidence of other exploitable vulnerabilities.

It's also important to pursue the very easily exploited vulnerabilities, because when you get rid of all the low-hanging fruit, the people who can't already climb the tree won't survive long enough to learn how. You're cutting a lot of bootstraps so that immature criminals can't pull themselves up by them.

Re: What Happens When You Send a Zero-Day to a Bank?

#230

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There's a service called Synack that does something similar to what you describe
Post reply on HN