Earlier quoted context omitted.
Tell us what bank so we can avoid them.
This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.
What Happens When You Send a Zero-Day to a Bank?
241–250 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#242Earlier quoted context omitted.
Care to explain why he's wrong, or are we to assume your expertise, random internet person?
Assume the expertise. A whole semester of university dedicated to contract law: Consumer contracts and B2B contracts in the national law, then the specifics when dealing with a party in another European country and internationally. You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.
Re: What Happens When You Send a Zero-Day to a Bank?
#243Re: What Happens When You Send a Zero-Day to a Bank?
#244Earlier quoted context omitted.
You should demand your tuition money back. http://www.nolo.com/legal-encyclopedia/consideration-every-c...
Too bad, the best schools are free where I come from. A few ones actually pay you. The point stands. Your link doesn't infirm what I said.
LOL. Res ipsa loquitur.
Re: What Happens When You Send a Zero-Day to a Bank?
#245There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
Re: What Happens When You Send a Zero-Day to a Bank?
#246Earlier quoted context omitted.
Care to explain why he's wrong, or are we to assume your expertise, random internet person?
I have no idea since I haven't reviewed the contract. But consideration can be more than just cash money. In some areas and circumstance continued employment can be enough consideration. Or getting access to more information might be enough. There isn't a bright line rule.
But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at all, which in my experience, is unheard of for these types of agreements.
Re: What Happens When You Send a Zero-Day to a Bank?
#247Re: What Happens When You Send a Zero-Day to a Bank?
#248>if somebody sent you an email with that code (even if you never open the email) then you would be the unwitting owner of one share of Krispy Kreme Donuts Pardon my ignorance, but how would this work?
I felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says: "But this only affects people that are logged in, right? Yes ..." So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser. If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with…
The article mentions it would occur even without opening the email.
Re: What Happens When You Send a Zero-Day to a Bank?
#249Earlier quoted context omitted.
How is the bank able to get to get the correct judgement in the civil case? There's proof the bank knew about the security hole, there is proof that at least one person outside of the employment of the bank had discovered this vulnerability (meaning there were likely more), and there is no way for the bank to prove that the transactions were legitimate. The article mentions that unauthorized transactions were indisti…
For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. They don't have to prove that it couldn't have been someone else, they have to convince the court that it's more likely than not. Motive matters a lot - if there's some wa…
Again, the IP address would obviously be associated with him and the browser because that's how the vulnerability works. The attacker just has to get the victim to visit any website with a browser which has the cookies for the bank. So proving that the user's browser/machine/IP made the request does nothing to show that the user did so intentionally.
> Motive matters a lot - if there's some way how that transaction would have been useful for a fraudster (i.e. if it was a money transfer to them), then it's one thing; but if there's no indication of why someone else would want to make the fraudulent trade (which is the case for most stock purchases/sells) and a clear motive why the claimant would want the trade to be reversed (i.e. the stock buy seemed good on that day but turned out to be bad afterwards) then if there's any technical evidence whatsoever pointing towards the claimant, it's hard to be convinced.
It doesn't have to be done by a fraudster. The motive for the attacker could simply be to fuck with people. They don't gain anything but satisfaction from the fact that they were able to successfully exploit this vulnerability.
Re: What Happens When You Send a Zero-Day to a Bank?
#250Earlier quoted context omitted.
It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.