Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

271–280 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#271

Earlier quoted context omitted.

Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.

OK, let the lawyers handle it. You don't make progress by catering to other people's ignorance and insecurities.

You are right, that isn't how you make progress: it's how you make money.

Re: What Happens When You Send a Zero-Day to a Bank?

#272
post #21

Kudos to the author, and hopefully they don't get sued as a result. This bullshit with corporations trying to cover up security vulnerabilities (rather than fix them) needs to stop. "Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.

No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law.

The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume it is, it would still seriously damage the researcher's life.

Here's how it goes when you get sued by a big company. Their lawyers essentially have a heyday doing everything possible to obstruct and delay the process so that they can maximize their time on the corporate teat. It will go on for years; they won't mind because it's business as usual for them, and they're getting paid big bucks to torment you. Your life will be ruined: assets seized pre-emptively, reputation and credit destroyed, inordinate quantities of time consumed by legal research and tedious paperwork, struggling (if not immediately blatantly failing) to keep your incompetent counsel paid at $250/hr and meet the retainer, and eventually failing to file some document or pay some fee that will cause the court to enter a default judgment against you and permanently confiscate everything you own, leaving you with the albatross of a massive outstanding judgment waiting to be enforced, bank accounts garnished any time you get any money, etc. And that's the short version!

And then guess what -- if, by some miracle, you don't lose in the first round, this whole process will repeat as they file appeal after appeal. Hunker down because the proceedings will last at least 5 years.

The corporate lawyers will be able to justify all of it to their clients without blinking an eye, who probably forgot that they even asked them to sue you. Everyone at the company and the law firm will go home and sleep soundly on their piles of money, and you'll have learnt your lesson that trying to stop the subterfuge of an online trading platform is a terrible offense.

Good reading: http://www.nissan.com/Lawsuit/The_Story.php

IANAL.

Re: What Happens When You Send a Zero-Day to a Bank?

#273
I think that an important point in this vulnerability is that it does not violate the CFAA. From my, albeit limited, understanding of the CFAA, it requires access breach.

Imagine this conversation were the user to have discovered a parameter which let the user execute trades on behalf of another user.

Re: What Happens When You Send a Zero-Day to a Bank?

#274
post #172

Earlier quoted context omitted.

Apparently the legalese is "recorder warning tone" and it should be a 1400 Hz beep every 15 seconds. https://en.wikipedia.org/wiki/Recorder_warning_tone I mentioned it because someone working for a big organization and making a lot of interstate calls probably hears these beeps all day and would be less likely to protest than if someone verbally announced that they're recording the call.

Interesting... So seeing that it's a federal standard, now I wonder whether it is sufficient notification of recording... If so, as you point out it seems like an interesting way to avoid having to announce the recording to those not knowledgeable. EDIT: I don't know how reliable this site is, but it seems to indicate the recording beep is sufficient for notification , but not sufficient for consent , which makes sen…

It looks like the beep is sufficient for recording from a one-party state calling a two-party state, since federal law supercedes the other state's law. Actual consent would be required if the recorder is in a two-party state, even if the other party is in a one-party state. But even if the recording is "technically legal" without consent, using it as evidence in the two-party state could still be problematic. So I guess it wouldn't be a good idea to rely on the beep alone.

Re: What Happens When You Send a Zero-Day to a Bank?

#275

I think that an important point in this vulnerability is that it does not violate the CFAA. From my, albeit limited, understanding of the CFAA, it requires access breach. Imagine this conversation were the user to have discovered a parameter which let the user execute trades on behalf of another user.

This vulnerability does allow to execute trades on behalf of another user.

For example, a realistic exploit would be to slowly buy up a bunch of a random penny stock; and then post an image link to some forum frequented by users of that software with the order "buy 10000 units of stock_x, okthxbye". The order will be executed by users viewing that forum and will bump up the price as you dump it.

Re: What Happens When You Send a Zero-Day to a Bank?

#276

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There is. Carnegie-Mellon University's CERT. Here's the form for reporting a vulnerability.[1] For this kind of problem, select "Request Vulnerability Coordination Assistance". You can even do this anonymously.

The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact the bank themselves. If you do, you can cite the CVE vulnerability number they give you. This gives you some advantages when talking to a bank. "Have your technical people contact Homeland Security's US-CERT at (888) 282-0870 regarding CVE-NNNN" will usually deal with a bank's people. They can't make the problem disappear.

[1] https://vulcoord.cert.org/VulReport/ [2] http://www.cert.org/vulnerability-analysis/vul-disclosure.cf...

Re: What Happens When You Send a Zero-Day to a Bank?

#277

Earlier quoted context omitted.

Are you a heart surgeon? No but I can read. I'll stick to advice from subject matter experts, not self appointed experts.

There's a helicopter crashed in a house. I don't need to be a pilot to know it's not supposed to do that.

And the validity of an NDA is blatantly obvious to any person who can read?

Re: What Happens When You Send a Zero-Day to a Bank?

#278
post #235

Earlier quoted context omitted.

You should demand your tuition money back. http://www.nolo.com/legal-encyclopedia/consideration-every-c...

Too bad, the best schools are free where I come from. A few ones actually pay you. The point stands. Your link doesn't infirm what I said.

"the best schools are free where I come from" generally implies living in one of civil law jurisdictions, where many legal principles are quite opposite from USA.

A good bunch of things taught in a contract law class are subtly wrong even for a very similar neighbouring country (in EU it's now getting a bit better because of harmonization efforts) but common vs civil law changes pretty much everything.

And a semester in contract law is not really much expertise - any MBA with a semester in USA contract law would have much more relevant expertise than us Europeans talking.

Re: What Happens When You Send a Zero-Day to a Bank?

#279

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.

How about the National Institute of Standards and Technology? My impression is that they are less interested in offense compared to the NSA, and more serious than possible private entities like PCI.

Re: What Happens When You Send a Zero-Day to a Bank?

#280

I'm not quite following the timeline: why did he end up under an NDA and the too-long wait to get it fixed? Why not say "I'm publishing this on my blog in 30 days so it better be fixed by then"? Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?

> Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?

Of course you would. The bank would call the FBI and tell them you're hacking the bank, and the FBI would then knock down your door, tear up your house and drag you away. The system would then do everything it could to represent what you did as a crime, and if you are lucky you get away with only a year in court, many thousands in debt and your name dragged through the mud.

tl;dr The actual legality of an action is only tangentially related to how the legal system will be used against you in response to it.

Post reply on HN