There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
What Happens When You Send a Zero-Day to a Bank?
321–330 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#322Earlier quoted context omitted.
I don't recommend submitting to CERT unless you genuinely don't care about the outcome of reporting. Yes, reporting to CERT is "safe"; you almost certainly aren't going to get sued for doing it. But don't count on CERT coordinating a fix or even figuring out how to report flaws to. It's unlikely that anyone at CERT knows who "Zecco" is. CERT themselves ask you not to submit to CERT unless your vulnerability fits some…
Who is Zecco?
Re: What Happens When You Send a Zero-Day to a Bank?
#323Earlier quoted context omitted.
> However, there is a risk they would sit on zero days Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda. There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
> They are still here to protect americans That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".
They aren't like that at all.
Re: What Happens When You Send a Zero-Day to a Bank?
#324Earlier quoted context omitted.
Someone in another forum commented recently that there should be a new top-line federal agency whose mission is to promote the security of America's information infrastructure. They suggested it should be established as an adversarial check/balance against e.g., the CIA and NSA. https://twitter.com/Snowden/status/839168025517522944 Maybe if they were required by statute to accept anonymous submissions and make FOIA-s…
The already exists an agency with this mission: the NSA. The problem is that they have two often-conflicting mission statements, WTH the other being to spy on foreign adversaries. Really what this would entail is splitting the NSA into two bureaucracies, with the information-security one then being able to wholeheartedly pursue vulnerabilities that affect American infrastructure. The offensive organization wold proba…
It's a myth far as I know. I've studied them a long time seeing much conflicting info about this. A declassified, historical document I found at one point about them said their job was SIGINT and COMSEC (just communications security!) for U.S. government. A later provision extended this to protecting COMSEC of defense contractors. The IAD seems to have policy-driven stuff about helping protect INFOSEC in general. There could've been a COTS mandate of some sort at some point but it was clearly toothless.
The NSA is mandated to protect communication security of defense sector. That's it. Even then, the defense sector keeps asking them to downgrade the security to let in more quick-moving products from commercial sector that are hacker fodder. They've since started on a program that lets them in after a 90-day evaluation against the lowest standards from Common Criteria. The NSA is the last group that should be responsible for INFOSEC given all this w/ market an utter failure, too.
The groups that have done the most are probably NSF and DARPA for funding strong security with NIST and DISA (esp STIGS) at least trying to do something with hardening guides and crypto recommendations. I prefer reputation-driven nonprofits that are funded with combo of donations, licensing of quality software, and consulting fees. They can't get acquired or be destroyed by changes in government policy.
Re: What Happens When You Send a Zero-Day to a Bank?
#325Re: What Happens When You Send a Zero-Day to a Bank?
#326There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
There is. Carnegie-Mellon University's CERT. Here's the form for reporting a vulnerability.[1] For this kind of problem, select "Request Vulnerability Coordination Assistance". You can even do this anonymously. The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact th…
Re: What Happens When You Send a Zero-Day to a Bank?
#327Earlier quoted context omitted.
This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.
> let the market do what she does best: work. Hm, I recall the Comodo hack. I think it Comodo was hacked twice or more times that year. It won many rewards and continued leading the CA space. The market did not work apparently...
The other end are buyers. Most of them don't know what to expect for security or how to evaluate it. Most attempts to solve this failed. They've been conditioned to expect constant hacks, crashes, or data loss. So, they see Comodo etc get hacked and shrug. They'll usually stay if their end of whatever they bought works. The sector that will pay for highly reliable or secure software is probably under 1% of the market or projects. It's enough companies keep forming to do real thing but tiny, tiny few struggling to justify the extra costs or less features necessary for higher security.
Re: What Happens When You Send a Zero-Day to a Bank?
#328Were cookies shared across sites in 2008? It seems pretty odd..
Re: What Happens When You Send a Zero-Day to a Bank?
#329Earlier quoted context omitted.
This deserves more than an upvote. This is exactly the right attitude. It puts the incentives in the right place and will let the market do what she does best: work.
Better yet: Short their stock, then write a scary blog post about the problem.
Re: What Happens When You Send a Zero-Day to a Bank?
#330Earlier quoted context omitted.
The attack would leave traces. Timestamps would show when exactly the request was made, ISP logs or data from the claimants computer would show other requests in the same seconds (i.e. wherever the victim got served the malicious link); Sending the img link by email would be visible in that email; getting the user to view a malicious post on some webpage/forum/etc is likely to leave evidence there. In general, you ma…
Do ISP's keep detailed logs as far back as 2005?