Earlier quoted context omitted.
It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...
To be fair, until sometime in the last ~2 years, Schwab PWs were alphanum case-insensitive 6-8 characters only.
What Happens When You Send a Zero-Day to a Bank?
251–260 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#252Earlier quoted context omitted.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
> They are still here to protect americans That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".
Re: What Happens When You Send a Zero-Day to a Bank?
#253Earlier quoted context omitted.
I have no idea since I haven't reviewed the contract. But consideration can be more than just cash money. In some areas and circumstance continued employment can be enough consideration. Or getting access to more information might be enough. There isn't a bright line rule.
We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise. But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at…
Without going into the extreme details of this case. Being "considerate" in legal jargon is much more subtle than "both parties have to gain something" in engineering talk. Determining the consideration can be as hard as a NP problem, to speak in engineer :D
Back to my original point: Let's not talk people into signing perfectly valid contracts, hoping for a loophole because it didn't look nice enough to them!
Re: What Happens When You Send a Zero-Day to a Bank?
#254Re: What Happens When You Send a Zero-Day to a Bank?
#255Earlier quoted context omitted.
Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.
IANAL but there is no risk that you may have to defend that proposition in court as long as you don't actually exploit the vulnerability and simply point it out. It's public information. Now if someone who works at the bank had told you about it, you'd be in a lot of trouble.
I'll admit that viewing the source code and noticing this link would be a stretch, but I wouldn't necessarily expect it to be a slam dunk for the researcher, especially if he had assented to the site's ToS (and since he had an account, it seems that he had).
At this point, I imagine he could be in all sorts of (primarily civil) trouble for the disclosure that he just made. He may be protected under some type of financial whistleblower law, but I wouldn't hold my breath.
Re: What Happens When You Send a Zero-Day to a Bank?
#256Re: What Happens When You Send a Zero-Day to a Bank?
#257https://www.paloaltoonline.com/news/2017/04/20/pausd-student...
Re: What Happens When You Send a Zero-Day to a Bank?
#258There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Why didn't they just give him $10K to shut up and then go fix the issue? It would be cheaper than all the lawyer fees.
Have you heard of Elizabeth Kubler-Ross's '5 stages of grief' model that summarizes people's typical responses to bereavement? EKR argued that people generally go through a cycle of denial, anger, bargaining, depression and acceptance. IME this is a good rule of thumb for how people typically handle any kind of unwelcome news.
In this case:
o There is no such problem
o Grr why did you hack us I'll call the police
o How about you take this pittance and STFU
o We're just trying to run a business and you ruined everything
o OK we'll fix it and alert our customersRe: What Happens When You Send a Zero-Day to a Bank?
#259Earlier quoted context omitted.
It was discovered today that Wells Fargo passwords are case-insensitive: https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...
Just today...? Chase Bank has been case-insensitive for several years now. I even contacted them about it when I found out and they outright told me they had no plans to fix it.
Re: What Happens When You Send a Zero-Day to a Bank?
#260Earlier quoted context omitted.
What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?
It's "broken window" community policing. The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community. It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visib…
Perhaps there's a breakdown of definitions here. I've lumped bug-bounty hunters and grey hat hackers, along with actual researchers, under "researchers." Stop me now if this isn't who you're referring to.
Now if it is, this route of action goes against the reseachers' monetary incentives. It is in their wallets' interests to have criminals validating the existence of their work. As well as selling the direct findings of one's research, including even minor exploitabilities, which is a given.
If researchers were to constantly give away their work (on even little issues) it would directly lower the cumulative value of cuber-security research, i.e their more expensive projects now sell for less.