Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

241–250 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#241

Earlier quoted context omitted.

Tell us what bank so we can avoid them.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

The idea of the banking system being subject to market forces is nice.

Re: What Happens When You Send a Zero-Day to a Bank?

#242

Earlier quoted context omitted.

Care to explain why he's wrong, or are we to assume your expertise, random internet person?

Assume the expertise. A whole semester of university dedicated to contract law: Consumer contracts and B2B contracts in the national law, then the specifics when dealing with a party in another European country and internationally. You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.

We certainly don't have all the facts surrounding this case, but we definitely have enough to move forward under the assumption that this would be resolved with American and probably Californian law. I'll leave you to research whether California requires consideration for valid contract.

Re: What Happens When You Send a Zero-Day to a Bank?

#243
post #182

I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...

Wow, how has this not gotten more attention?

It has. It's just been like that for years.

Re: What Happens When You Send a Zero-Day to a Bank?

#244
post #235

Earlier quoted context omitted.

You should demand your tuition money back. http://www.nolo.com/legal-encyclopedia/consideration-every-c...

Too bad, the best schools are free where I come from. A few ones actually pay you. The point stands. Your link doesn't infirm what I said.

> Your link doesn't infirm what I said.

LOL. Res ipsa loquitur.

Re: What Happens When You Send a Zero-Day to a Bank?

#245

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

You're thinking CIA and NSA.

Re: What Happens When You Send a Zero-Day to a Bank?

#246

Earlier quoted context omitted.

Care to explain why he's wrong, or are we to assume your expertise, random internet person?

I have no idea since I haven't reviewed the contract. But consideration can be more than just cash money. In some areas and circumstance continued employment can be enough consideration. Or getting access to more information might be enough. There isn't a bright line rule.

We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise.

But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at all, which in my experience, is unheard of for these types of agreements.

Re: What Happens When You Send a Zero-Day to a Bank?

#247

Earlier quoted context omitted.

This is how FB & others track everyone on the web through ad frames, like buttons, etc.

Do they get info about from which page they got requested when one includes just an image?

Yes, it is passed along through the Referer (sic) header.

Re: What Happens When You Send a Zero-Day to a Bank?

#248
post #226
post #221

>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts Pardon my ignorance, but how would this work?

I felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says: "But this only affects people that are logged in, right? Yes ..." So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser. If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with…

>eg viewing a malicous email with the IMG tag in a webmail client

The article mentions it would occur even without opening the email.

Re: What Happens When You Send a Zero-Day to a Bank?

#249

Earlier quoted context omitted.

How is the bank able to get to get the correct judgement in the civil case? There's proof the bank knew about the security hole, there is proof that at least one person outside of the employment of the bank had discovered this vulnerability (meaning there were likely more), and there is no way for the bank to prove that the transactions were legitimate. The article mentions that unauthorized transactions were indisti…

For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. They don't have to prove that it couldn't have been someone else, they have to convince the court that it's more likely than not. Motive matters a lot - if there's some wa…

> For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP.

Again, the IP address would obviously be associated with him and the browser because that's how the vulnerability works. The attacker just has to get the victim to visit any website with a browser which has the cookies for the bank. So proving that the user's browser/machine/IP made the request does nothing to show that the user did so intentionally.

> Motive matters a lot - if there's some way how that transaction would have been useful for a fraudster (i.e. if it was a money transfer to them), then it's one thing; but if there's no indication of why someone else would want to make the fraudulent trade (which is the case for most stock purchases/sells) and a clear motive why the claimant would want the trade to be reversed (i.e. the stock buy seemed good on that day but turned out to be bad afterwards) then if there's any technical evidence whatsoever pointing towards the claimant, it's hard to be convinced.

It doesn't have to be done by a fraudster. The motive for the attacker could simply be to fuck with people. They don't gain anything but satisfaction from the fact that they were able to successfully exploit this vulnerability.

Re: What Happens When You Send a Zero-Day to a Bank?

#250
post #224

Earlier quoted context omitted.

It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…

Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.

OK, let the lawyers handle it. You don't make progress by catering to other people's ignorance and insecurities.
Post reply on HN