Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

341–350 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#341
post #21

Kudos to the author, and hopefully they don't get sued as a result. This bullshit with corporations trying to cover up security vulnerabilities (rather than fix them) needs to stop. "Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.

No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law. The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume…

My father is a (technically literate, he used to be a database architect) lawyer, and the general advice he gave me was that if you are in a situation where you have a critical vulnerability you should disclose it through a lawyer anonymously -- your identity is then protected under attorney-client privilege (assuming you haven't just asked your lawyer to commit a crime by disclosing it).

IANAL though.

Re: What Happens When You Send a Zero-Day to a Bank?

#342

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

What, more government spending and taxes and regulation? That's anti-American! Are you a traitor? Get the government out of our lives! Let the free market fix this. If you don't like it, just don't buy it. We don't need more acronyms! Just a bunch of bureaucrats! Drop more bombs!

/sarc

Re: What Happens When You Send a Zero-Day to a Bank?

#343
post #130

Earlier quoted context omitted.

When you come across a single credit card number (say, by finding someone's card on the ground), the response by most financial institutions is to invalidate that card and mail them a new one. Why shouldn't the response be the same if you come across a stack of 100 credit cards?

The response to invalidate is a choice by the bank, not the person who finds the card. Also, that is a single number. It's suspicious/threatening for a non-trivial amount of cards when the presenter also makes demands.

How is "someone has stolen your clients information and likely already sold it to nefarious actors, because otherwise it wouldn't be on the internet anywhere, so you should keep them safe by deactivating those accounts" threatening?

I'd be annoyed if my bank didn't do something.

Re: What Happens When You Send a Zero-Day to a Bank?

#344

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There was a guy who got thrown in prison for bringing a vulnerability to the attention of AT&T. He was thrown in solitary confinement for over a year. Then his sentence got vacated. What did he do as soon as he was released from prison?

He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRDdhVI

He seems to be of the opinion that this would be a less risky strategy than bringing those issues to the attention of many companies. He also believes that profit incentives for researchers will serve the public interest, because it creates economic disincentives against big companies having insecure software.

Re: What Happens When You Send a Zero-Day to a Bank?

#345

Earlier quoted context omitted.

When you come across a single credit card number (say, by finding someone's card on the ground), the response by most financial institutions is to invalidate that card and mail them a new one. Why shouldn't the response be the same if you come across a stack of 100 credit cards?

Because shutting down 100 credit cards has more reputation and monetary liability than shutting one down? You're basically saying "academics can derive your social security number using public information!" And wondering why they don't reissue all of the SSNs...

So? When a website has its passwords stolen (even just the hashed, salted ones) the immediate step is to invalidate every password potentially compromised and force users to reset them. Doesn't matter how or why the passwords were lost, you start by mitigating the damage someone can do. Why isn't the response for when credit card information (which is very often more valuable) is stolen similar?

>You're basically saying "academics can derive your social security number using public information!"

No, I'm saying that if my name, social, DoB, mother's maiden name, and credit card number appear online in a csv file with 200 other people's personal information, I'd really appreciate it if my credit card company would take proactive steps to keep my accounts secure.

Re: What Happens When You Send a Zero-Day to a Bank?

#346
post #269
post #225

Earlier quoted context omitted.

While it may be true that in this particular instance the FBI might act benevolently, the idea was that it would be nice if there was an organization you could go to with any zero day bug. Even if the FBI is not mismanaged and always tries to protect Americans, you could easily imagine a scenario where someone reports an exploit to an OS where anyone can remotely install a key logger. The FBI wouldn't be a good organ…

> While it may be true that in this particular instance the FBI might act benevolently Indeed. Didn't the FBI effectively purchase a zero day to break into the iPhone of the San Bernardino shooter? Didn't they also then not disclose said zero day to Apple? There's no way that any LE agency can be trusted with this responsibility; I'm not convinced that it can be done by the federal government at all. EFF seems like a…

What if there were multiple non-profits that can keep each other honest?

Re: What Happens When You Send a Zero-Day to a Bank?

#347

Earlier quoted context omitted.

You could always send an anonymous, or not, tip to KrebsOnSecurity.com. Brian has the skill to handle this kind of disclosure and the street cred to avoid pitfalls.

Has he said that he's willing to be a liaison like that? If not, you'd be putting an unfair burden on him by doing that.

Krebs writes articles based on tips [0] of this nature all the time. As a reporter I expect he would appreciate the opportunity to break the story.

[0] https://krebsonsecurity.com/about-this-blog/

Re: What Happens When You Send a Zero-Day to a Bank?

#349
post #7

The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.

Came here to say just this.

Re: What Happens When You Send a Zero-Day to a Bank?

#350

Earlier quoted context omitted.

Care to explain why he's wrong, or are we to assume your expertise, random internet person?

Assume the expertise. A whole semester of university dedicated to contract law: Consumer contracts and B2B contracts in the national law, then the specifics when dealing with a party in another European country and internationally. You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.

> European country and internationally.

You think you are qualified to determine ANYTHING about US contract law when you've taken a single semester in contract law related to an entirely different country?

By your logic I am basically a Astronomer. Except mine is more relevant since astronomy is the same regardless of where you take a "whole semester" of it.

Post reply on HN