Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

321–330 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#321

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

How about Google? If you discover a big vulnerability, perhaps? Someone ought to have some connection somewhere. Ask your colleagues around.

Re: What Happens When You Send a Zero-Day to a Bank?

#322

Earlier quoted context omitted.

I don't recommend submitting to CERT unless you genuinely don't care about the outcome of reporting. Yes, reporting to CERT is "safe"; you almost certainly aren't going to get sued for doing it. But don't count on CERT coordinating a fix or even figuring out how to report flaws to. It's unlikely that anyone at CERT knows who "Zecco" is. CERT themselves ask you not to submit to CERT unless your vulnerability fits some…

Who is Zecco?

[deleted]

Re: What Happens When You Send a Zero-Day to a Bank?

#323

Earlier quoted context omitted.

> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.

> They are still here to protect americans That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".

Have you ever interacted with law enforcement on any professional basis?

They aren't like that at all.

Re: What Happens When You Send a Zero-Day to a Bank?

#324

Earlier quoted context omitted.

Someone in another forum commented recently that there should be a new top-line federal agency whose mission is to promote the security of America's information infrastructure. They suggested it should be established as an adversarial check/balance against e.g., the CIA and NSA. https://twitter.com/Snowden/status/839168025517522944 Maybe if they were required by statute to accept anonymous submissions and make FOIA-s…

The already exists an agency with this mission: the NSA. The problem is that they have two often-conflicting mission statements, WTH the other being to spy on foreign adversaries. Really what this would entail is splitting the NSA into two bureaucracies, with the information-security one then being able to wholeheartedly pursue vulnerabilities that affect American infrastructure. The offensive organization wold proba…

"The already exists an agency with this mission: the NSA."

It's a myth far as I know. I've studied them a long time seeing much conflicting info about this. A declassified, historical document I found at one point about them said their job was SIGINT and COMSEC (just communications security!) for U.S. government. A later provision extended this to protecting COMSEC of defense contractors. The IAD seems to have policy-driven stuff about helping protect INFOSEC in general. There could've been a COTS mandate of some sort at some point but it was clearly toothless.

The NSA is mandated to protect communication security of defense sector. That's it. Even then, the defense sector keeps asking them to downgrade the security to let in more quick-moving products from commercial sector that are hacker fodder. They've since started on a program that lets them in after a 90-day evaluation against the lowest standards from Common Criteria. The NSA is the last group that should be responsible for INFOSEC given all this w/ market an utter failure, too.

The groups that have done the most are probably NSF and DARPA for funding strong security with NIST and DISA (esp STIGS) at least trying to do something with hardening guides and crypto recommendations. I prefer reputation-driven nonprofits that are funded with combo of donations, licensing of quality software, and consulting fees. They can't get acquired or be destroyed by changes in government policy.

Re: What Happens When You Send a Zero-Day to a Bank?

#325

Earlier quoted context omitted.

Who just has an attorney sitting around who is competent to handle such things? I wouldn't know who the fuck to call if I found something on my bank's website.

I am one such attorney.

Can I get your number?

Re: What Happens When You Send a Zero-Day to a Bank?

#326

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There is. Carnegie-Mellon University's CERT. Here's the form for reporting a vulnerability.[1] For this kind of problem, select "Request Vulnerability Coordination Assistance". You can even do this anonymously. The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact th…

You're suggesting we send our exploits to the company that hacked Tor for the FBI? How much do they pay you?

Re: What Happens When You Send a Zero-Day to a Bank?

#327
post #124

Earlier quoted context omitted.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

> let the market do what she does best: work. Hm, I recall the Comodo hack. I think it Comodo was hacked twice or more times that year. It won many rewards and continued leading the CA space. The market did not work apparently...

The security market is working exactly as it was designed and evolved to. Far as when high-assurance started, the Black Forrest Group of execs of big companies convening on INFOSEC told one of INFOSEC founders they thought companies would refuse to sell them highly-assured software. The reason was they suspected they intended to make extra profit two ways: cutting QA for immediate profit; selling the fixes for later profit. This proved true with lock-in strategy combining for what was essentially checkmate to lots of companies.

The other end are buyers. Most of them don't know what to expect for security or how to evaluate it. Most attempts to solve this failed. They've been conditioned to expect constant hacks, crashes, or data loss. So, they see Comodo etc get hacked and shrug. They'll usually stay if their end of whatever they bought works. The sector that will pay for highly reliable or secure software is probably under 1% of the market or projects. It's enough companies keep forming to do real thing but tiny, tiny few struggling to justify the extra costs or less features necessary for higher security.

Re: What Happens When You Send a Zero-Day to a Bank?

#328

Were cookies shared across sites in 2008? It seems pretty odd..

Because most people don't have 3rd party cookies disabled. It's one of the first things you should do when you install a browser. It doesn't break anything worthwhile and protects your privacy (and security).

Re: What Happens When You Send a Zero-Day to a Bank?

#329

Earlier quoted context omitted.

This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.

Better yet: Short their stock, then write a scary blog post about the problem.

Alternatively, publish it in an obscure place online, get proof you published it in archived medium (eg Gmail or Archive.org), short the stock based on that now-public information, and then reveal it again in a way that will get stock-smashing attention. That's my hypothetical model I came up with when trying to figure out how to incentivize apathetic, but public companies, to care about security a bit. You can even follow up offering them security consulting but don't expect a yes haha.

Re: What Happens When You Send a Zero-Day to a Bank?

#330
post #318

Earlier quoted context omitted.

The attack would leave traces. Timestamps would show when exactly the request was made, ISP logs or data from the claimants computer would show other requests in the same seconds (i.e. wherever the victim got served the malicious link); Sending the img link by email would be visible in that email; getting the user to view a malicious post on some webpage/forum/etc is likely to leave evidence there. In general, you ma…

Do ISP's keep detailed logs as far back as 2005?

Nope, but if you reported that you just noticed a fake stock deal made 12 years ago on an account that you actively use, you'd have an uphill battle proving that it really was unauthorised, and the lack of logs would only make it harder for you.
Post reply on HN