Earlier quoted context omitted.
Just that they have a name that will immediately be without any trust at any non -tech company. Basically mentioning "hacking" will make any non-technical CEO shiver and call the lawyers.
OK, let the lawyers handle it. You don't make progress by catering to other people's ignorance and insecurities.
What Happens When You Send a Zero-Day to a Bank?
271–280 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#272Kudos to the author, and hopefully they don't get sued as a result. This bullshit with corporations trying to cover up security vulnerabilities (rather than fix them) needs to stop. "Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.
The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume it is, it would still seriously damage the researcher's life.
Here's how it goes when you get sued by a big company. Their lawyers essentially have a heyday doing everything possible to obstruct and delay the process so that they can maximize their time on the corporate teat. It will go on for years; they won't mind because it's business as usual for them, and they're getting paid big bucks to torment you. Your life will be ruined: assets seized pre-emptively, reputation and credit destroyed, inordinate quantities of time consumed by legal research and tedious paperwork, struggling (if not immediately blatantly failing) to keep your incompetent counsel paid at $250/hr and meet the retainer, and eventually failing to file some document or pay some fee that will cause the court to enter a default judgment against you and permanently confiscate everything you own, leaving you with the albatross of a massive outstanding judgment waiting to be enforced, bank accounts garnished any time you get any money, etc. And that's the short version!
And then guess what -- if, by some miracle, you don't lose in the first round, this whole process will repeat as they file appeal after appeal. Hunker down because the proceedings will last at least 5 years.
The corporate lawyers will be able to justify all of it to their clients without blinking an eye, who probably forgot that they even asked them to sue you. Everyone at the company and the law firm will go home and sleep soundly on their piles of money, and you'll have learnt your lesson that trying to stop the subterfuge of an online trading platform is a terrible offense.
Good reading: http://www.nissan.com/Lawsuit/The_Story.php
IANAL.
Re: What Happens When You Send a Zero-Day to a Bank?
#273Imagine this conversation were the user to have discovered a parameter which let the user execute trades on behalf of another user.
Re: What Happens When You Send a Zero-Day to a Bank?
#274Earlier quoted context omitted.
Apparently the legalese is "recorder warning tone" and it should be a 1400 Hz beep every 15 seconds. https://en.wikipedia.org/wiki/Recorder_warning_tone I mentioned it because someone working for a big organization and making a lot of interstate calls probably hears these beeps all day and would be less likely to protest than if someone verbally announced that they're recording the call.
Interesting... So seeing that it's a federal standard, now I wonder whether it is sufficient notification of recording... If so, as you point out it seems like an interesting way to avoid having to announce the recording to those not knowledgeable. EDIT: I don't know how reliable this site is, but it seems to indicate the recording beep is sufficient for notification , but not sufficient for consent , which makes sen…
Re: What Happens When You Send a Zero-Day to a Bank?
#275I think that an important point in this vulnerability is that it does not violate the CFAA. From my, albeit limited, understanding of the CFAA, it requires access breach. Imagine this conversation were the user to have discovered a parameter which let the user execute trades on behalf of another user.
For example, a realistic exploit would be to slowly buy up a bunch of a random penny stock; and then post an image link to some forum frequented by users of that software with the order "buy 10000 units of stock_x, okthxbye". The order will be executed by users viewing that forum and will bump up the price as you dump it.
Re: What Happens When You Send a Zero-Day to a Bank?
#276There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact the bank themselves. If you do, you can cite the CVE vulnerability number they give you. This gives you some advantages when talking to a bank. "Have your technical people contact Homeland Security's US-CERT at (888) 282-0870 regarding CVE-NNNN" will usually deal with a bank's people. They can't make the problem disappear.
[1] https://vulcoord.cert.org/VulReport/ [2] http://www.cert.org/vulnerability-analysis/vul-disclosure.cf...
Re: What Happens When You Send a Zero-Day to a Bank?
#277Earlier quoted context omitted.
Are you a heart surgeon? No but I can read. I'll stick to advice from subject matter experts, not self appointed experts.
There's a helicopter crashed in a house. I don't need to be a pilot to know it's not supposed to do that.
Re: What Happens When You Send a Zero-Day to a Bank?
#278Earlier quoted context omitted.
You should demand your tuition money back. http://www.nolo.com/legal-encyclopedia/consideration-every-c...
Too bad, the best schools are free where I come from. A few ones actually pay you. The point stands. Your link doesn't infirm what I said.
A good bunch of things taught in a contract law class are subtly wrong even for a very similar neighbouring country (in EU it's now getting a bit better because of harmonization efforts) but common vs civil law changes pretty much everything.
And a semester in contract law is not really much expertise - any MBA with a semester in USA contract law would have much more relevant expertise than us Europeans talking.
Re: What Happens When You Send a Zero-Day to a Bank?
#279There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Personally I think this is a function the the FBI should fill. However, there is a risk they would sit on zero days and weaponize them (or give them to another three letter agency). I wonder if an org like the EFF could add this to their scope.
Re: What Happens When You Send a Zero-Day to a Bank?
#280I'm not quite following the timeline: why did he end up under an NDA and the too-long wait to get it fixed? Why not say "I'm publishing this on my blog in 30 days so it better be fixed by then"? Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?
Of course you would. The bank would call the FBI and tell them you're hacking the bank, and the FBI would then knock down your door, tear up your house and drag you away. The system would then do everything it could to represent what you did as a crime, and if you are lucky you get away with only a year in court, many thousands in debt and your name dragged through the mud.
tl;dr The actual legality of an action is only tangentially related to how the legal system will be used against you in response to it.