Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

331–340 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#331

Earlier quoted context omitted.

IANAL but there is no risk that you may have to defend that proposition in court as long as you don't actually exploit the vulnerability and simply point it out. It's public information. Now if someone who works at the bank had told you about it, you'd be in a lot of trouble.

IANAL either but my understanding is that you can be prosecuted under U.S. law for poking around on servers in any unconventional way. The text of the CFAA forbids "unauthorized access" or "exceeding authorized access". I'll admit that viewing the source code and noticing this link would be a stretch, but I wouldn't necessarily expect it to be a slam dunk for the researcher, especially if he had assented to the site'…

"The text of the CFAA forbids "unauthorized access" or "exceeding authorized access"."

BOOM! And they've been harsh on hackers for a long time. So, the vulnerability must not require violating access controls or system integrity to be safest. Hackers should be in the clear if it was simply noticing something in HTML/HTTP or whatever that indicated insecurity. An example might be a breakable cipher-suite or handling sessions improperly.

Re: What Happens When You Send a Zero-Day to a Bank?

#333

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

> the analogy would be a lawyer.

You can use a lawyer for this, this is a standard piece of advice for other kinds of bounties-- e.g. reporting criminal tax evasion.

Re: What Happens When You Send a Zero-Day to a Bank?

#334

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Professional association of security researchers? Come up with a good set of guiding principles for members. This would help avoid waiting 7 years and then sticking it online. Not criticising, I'm saying the situation here is pretty screwed up. Members pay dues, the association provides backing. Company threatens to call the FBI and the association is the one they can deal with. An organized group can help to provide…

> Professional association of security researchers

It's next door to the military intelligence folks.

(ba-da-bump)

Re: What Happens When You Send a Zero-Day to a Bank?

#335

Earlier quoted context omitted.

Sure banks can. Source: did software security for a number of banks. Big banks are chock full o' CSRFs, XSS, SSRFs, and SQLIs. They get found all the time. For every valid report they get, they get 3 that aren't valid. Nobody's hair achieves ignition over this stuff. There are two types of financial service organizations: the big banks, and random firms (like Zecco was, before Ally bought them). There's no point in c…

I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…

A lot of vulnerabilities are basically the same thing. From what I've seen, even legitimate researchers will have form reports. It's just an obvious optimization.

From there it's pretty easy to see that "vulnerability spam" would be a thing.

Re: What Happens When You Send a Zero-Day to a Bank?

#336

Earlier quoted context omitted.

That was my experience when I stumbled across a text file with several thousand credit card numbers, which included tons of details about each card holder, including SSN. I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more c…

You could always send an anonymous, or not, tip to KrebsOnSecurity.com. Brian has the skill to handle this kind of disclosure and the street cred to avoid pitfalls.

Has he said that he's willing to be a liaison like that? If not, you'd be putting an unfair burden on him by doing that.

Re: What Happens When You Send a Zero-Day to a Bank?

#337

Earlier quoted context omitted.

Someone in another forum commented recently that there should be a new top-line federal agency whose mission is to promote the security of America's information infrastructure. They suggested it should be established as an adversarial check/balance against e.g., the CIA and NSA. https://twitter.com/Snowden/status/839168025517522944 Maybe if they were required by statute to accept anonymous submissions and make FOIA-s…

The already exists an agency with this mission: the NSA. The problem is that they have two often-conflicting mission statements, WTH the other being to spy on foreign adversaries. Really what this would entail is splitting the NSA into two bureaucracies, with the information-security one then being able to wholeheartedly pursue vulnerabilities that affect American infrastructure. The offensive organization wold proba…

The NSA is part of the U.S. Dept of Defense, which generally can't operate domestically. I'm not sure how that applies in this case.

Re: What Happens When You Send a Zero-Day to a Bank?

#338

Earlier quoted context omitted.

I don't recommend submitting to CERT unless you genuinely don't care about the outcome of reporting. Yes, reporting to CERT is "safe"; you almost certainly aren't going to get sued for doing it. But don't count on CERT coordinating a fix or even figuring out how to report flaws to. It's unlikely that anyone at CERT knows who "Zecco" is. CERT themselves ask you not to submit to CERT unless your vulnerability fits some…

Who is Zecco?

The financial entity the article is written about.

Re: What Happens When You Send a Zero-Day to a Bank?

#339

Earlier quoted context omitted.

Sure banks can. Source: did software security for a number of banks. Big banks are chock full o' CSRFs, XSS, SSRFs, and SQLIs. They get found all the time. For every valid report they get, they get 3 that aren't valid. Nobody's hair achieves ignition over this stuff. There are two types of financial service organizations: the big banks, and random firms (like Zecco was, before Ally bought them). There's no point in c…

I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…

Whether you run a bug bounty or not, there are now hundreds of people in Asia and Eastern Europe who hope to make $500 every time they find a page without X-Frame-Options set. A lot of them have pirated Burp Suite and are hoping to simply cash in on the scanner output.

Re: What Happens When You Send a Zero-Day to a Bank?

#340

Earlier quoted context omitted.

Someone in another forum commented recently that there should be a new top-line federal agency whose mission is to promote the security of America's information infrastructure. They suggested it should be established as an adversarial check/balance against e.g., the CIA and NSA. https://twitter.com/Snowden/status/839168025517522944 Maybe if they were required by statute to accept anonymous submissions and make FOIA-s…

The already exists an agency with this mission: the NSA. The problem is that they have two often-conflicting mission statements, WTH the other being to spy on foreign adversaries. Really what this would entail is splitting the NSA into two bureaucracies, with the information-security one then being able to wholeheartedly pursue vulnerabilities that affect American infrastructure. The offensive organization wold proba…

NIST is another.
Post reply on HN