Earlier quoted context omitted.
Tell us what bank so we can avoid them.
So far, I count three separate replies to this article along the lines of "I also found my bank doing so-and-so thing insecurely, but LA LA I'm not going to tell you which bank it is!" These kinds of comments don't help anyone--you might as well not post them.
What Happens When You Send a Zero-Day to a Bank?
261–270 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#262Earlier quoted context omitted.
For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. They don't have to prove that it couldn't have been someone else, they have to convince the court that it's more likely than not. Motive matters a lot - if there's some wa…
> For starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. Again, the IP address would obviously be associated with him and the browser because that's how the vulnerability works. The attacker just has to get the victim to visit…
In general, you make good points, they are believable and likely would be made if such a court case happened. In the absence of hard evidence, if they seem slightly more believable than whatever story the company presents, the claimant would win; if they seem slightly less believable, the claimant would lose. In a civil claim, the company needs to prove that it was authorised only just as much as the claimant needs to prove that it was not, it's a somewhat symmetric contest - simply claiming "I didn't authorise it" is effectively countered by claiming "Yes you did", and simply moves the discussion on to further investigation.
The motive could be just a prankster messing with people, but it's a lot less convincing motive than an obvious benefit. If the transaction is one where you clearly lose money and someone (possibly anonymous) gains it, it's easy to make the case that you were hacked. But, for example, if the claimant had previously unsuccessfully complained to the company about the theoretical possibility of such vulnerability, and then complained that a seemingly random transaction is unauthorized, I'm fairly sure that any decent lawyer would successfully convince the court that "a prankster did it" is comparable to "the dog ate my homework" and it's a bit more likely that they orchestrated the claim themselves to mess with the company. Getting 51% of belief is preponderance of evidence, and sufficient in a civil trial.
And in any case, all this wouldn't be "simply claim" - seriously making such a claim would require a significant investment of time and money from the claimant. It's not something most people would do for fun. Some would do it to make a point, but that's quite a niche hobby.
Re: What Happens When You Send a Zero-Day to a Bank?
#263Earlier quoted context omitted.
It's "broken window" community policing. The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community. It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visib…
This was fascinating. Can I read more somewhere?
New York City based their increased focus on petty crimes on it. I don't think it is useful as the basis for a model of policing, though.
In some ways, it is an embodiment of the slippery slope fallacy, where if security is not perfect, it's worthless, in the same sense that a roof with one leak in it is worthless, because that one leak becomes the beachhead for further damage to the roof.
Re: What Happens When You Send a Zero-Day to a Bank?
#264Re: What Happens When You Send a Zero-Day to a Bank?
#265Earlier quoted context omitted.
It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.
But any person looking at their homepage would be a lot less concerned. Impressive logo's and a clear story for an enterprise audience.
Re: What Happens When You Send a Zero-Day to a Bank?
#266There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
https://vulcoord.cert.org/VulReport/ http://www.zerodayinitiative.com/about/
Re: What Happens When You Send a Zero-Day to a Bank?
#267Were cookies shared across sites in 2008? It seems pretty odd..
Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.
var i = document.createElement('img');
i.src= "https://news.ycombinator.com/y18.gif";
document.body.insertBefore(i, document.body.firstChild);
The image appeared in the upper left of the Google home page.So, I clicked over to the Network tab and viewed the headers. The request headers do not include any cookies. If Hacker News were a broker using GET requests to buy shares, and the image URL was such a request, HN would not have known whose account to buy the shares for, even though I'm logged in in another tab.
So, presumably, the hack does not work in Chrome 57.
Edit: Never mind. It's because I have third-party cookies blocked. If I unblock third-party cookies, my HN cookie does get sent.
Re: What Happens When You Send a Zero-Day to a Bank?
#268Were cookies shared across sites in 2008? It seems pretty odd..
Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.
Re: What Happens When You Send a Zero-Day to a Bank?
#269Earlier quoted context omitted.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
While it may be true that in this particular instance the FBI might act benevolently, the idea was that it would be nice if there was an organization you could go to with any zero day bug. Even if the FBI is not mismanaged and always tries to protect Americans, you could easily imagine a scenario where someone reports an exploit to an OS where anyone can remotely install a key logger. The FBI wouldn't be a good organ…
Indeed. Didn't the FBI effectively purchase a zero day to break into the iPhone of the San Bernardino shooter? Didn't they also then not disclose said zero day to Apple?
There's no way that any LE agency can be trusted with this responsibility; I'm not convinced that it can be done by the federal government at all. EFF seems like a reasonable choice, but even non-profits have the potential to be corrupted/subverted (and operating as a dump for zero days has the power to corrupt, for sure, regardless of how moral your organization claims to be on its website).
This definitely falls under the umbrella of hard-problems-in-politics-that-will-not-be-solved-any-time-soon
Re: What Happens When You Send a Zero-Day to a Bank?
#270I recently dropped a credit union because they can't be bothered to secure their mobile app (in the official google play store!) to use anything better than TLS1.0. TLS1.2 and proper crypto schemes should be mandatory at this point.
https://cdn2.hubspot.net/hubfs/281302/Resources/Migrating_fr...