Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

251–260 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#251
post #164

Earlier quoted context omitted.

It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

To be fair, until sometime in the last ~2 years, Schwab PWs were alphanum case-insensitive 6-8 characters only.

So I know this also :) I am a techie that made a bit of money and it was kept at Schwab. I made a big enough issues of it that they arranged a call with their security team. The call was good and they explained the reason why (legacy system) and their plans to update / fix it. They also address my questions about password storage (hashing/salt) - they did it correctly. They showed a great deal of knowledge and competence in their job, such that I was willing to leave my money. I applaud their willingness to have the call. My dealings with them have always been pleasant.

Re: What Happens When You Send a Zero-Day to a Bank?

#252

Earlier quoted context omitted.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

> They are still here to protect americans That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".

Don't mix up the existence of incentives with the idea that you have insight into what people's goals are.

Re: What Happens When You Send a Zero-Day to a Bank?

#253

Earlier quoted context omitted.

I have no idea since I haven't reviewed the contract. But consideration can be more than just cash money. In some areas and circumstance continued employment can be enough consideration. Or getting access to more information might be enough. There isn't a bright line rule.

We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise. But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at…

Well, the contract has been published, we could get more facts. (except it's midnight now and I'm not gonna read it carefully now)

Without going into the extreme details of this case. Being "considerate" in legal jargon is much more subtle than "both parties have to gain something" in engineering talk. Determining the consideration can be as hard as a NP problem, to speak in engineer :D

Back to my original point: Let's not talk people into signing perfectly valid contracts, hoping for a loophole because it didn't look nice enough to them!

Re: What Happens When You Send a Zero-Day to a Bank?

#254

Earlier quoted context omitted.

This is how FB & others track everyone on the web through ad frames, like buttons, etc.

Do they get info about from which page they got requested when one includes just an image?

Yes, via the HTTP Referer header.

Re: What Happens When You Send a Zero-Day to a Bank?

#255

Earlier quoted context omitted.

Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.

IANAL but there is no risk that you may have to defend that proposition in court as long as you don't actually exploit the vulnerability and simply point it out. It's public information. Now if someone who works at the bank had told you about it, you'd be in a lot of trouble.

IANAL either but my understanding is that you can be prosecuted under U.S. law for poking around on servers in any unconventional way. The text of the CFAA forbids "unauthorized access" or "exceeding authorized access".

I'll admit that viewing the source code and noticing this link would be a stretch, but I wouldn't necessarily expect it to be a slam dunk for the researcher, especially if he had assented to the site's ToS (and since he had an account, it seems that he had).

At this point, I imagine he could be in all sorts of (primarily civil) trouble for the disclosure that he just made. He may be protected under some type of financial whistleblower law, but I wouldn't hold my breath.

Re: What Happens When You Send a Zero-Day to a Bank?

#256
post #244

Earlier quoted context omitted.

Too bad, the best schools are free where I come from. A few ones actually pay you. The point stands. Your link doesn't infirm what I said.

> Your link doesn't infirm what I said. LOL. Res ipsa loquitur.

Dura lex sed lex.

Re: What Happens When You Send a Zero-Day to a Bank?

#258
post #196

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Why didn't they just give him $10K to shut up and then go fix the issue? It would be cheaper than all the lawyer fees.

Because if the vulnerability turns into a problem down the line and ends up in court, the record of the payment could come out during discovery, which could be made to look bad for the defendant firm.

Have you heard of Elizabeth Kubler-Ross's '5 stages of grief' model that summarizes people's typical responses to bereavement? EKR argued that people generally go through a cycle of denial, anger, bargaining, depression and acceptance. IME this is a good rule of thumb for how people typically handle any kind of unwelcome news.

In this case:

  o There is no such problem
  o Grr why did you hack us I'll call the police
  o How about you take this pittance and STFU
  o We're just trying to run a business and you ruined everything
  o OK we'll fix it and alert our customers

Re: What Happens When You Send a Zero-Day to a Bank?

#259
post #164

Earlier quoted context omitted.

It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...

Just today...? Chase Bank has been case-insensitive for several years now. I even contacted them about it when I found out and they outright told me they had no plans to fix it.

Tons of companies do this because it substantially diminishes the number of support calls/complaints that they get related to unsuccessful logins.

Re: What Happens When You Send a Zero-Day to a Bank?

#260

Earlier quoted context omitted.

What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?

It's "broken window" community policing. The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community. It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visib…

This is correct, and the morally sound right thing to do if you're interested in cutting down on cyber-crime, but it unfortunately falls under the incorporeal "good-boy points."

Perhaps there's a breakdown of definitions here. I've lumped bug-bounty hunters and grey hat hackers, along with actual researchers, under "researchers." Stop me now if this isn't who you're referring to.

Now if it is, this route of action goes against the reseachers' monetary incentives. It is in their wallets' interests to have criminals validating the existence of their work. As well as selling the direct findings of one's research, including even minor exploitabilities, which is a given.

If researchers were to constantly give away their work (on even little issues) it would directly lower the cumulative value of cuber-security research, i.e their more expensive projects now sell for less.

Post reply on HN