Earlier quoted context omitted.
While it may be true that in this particular instance the FBI might act benevolently, the idea was that it would be nice if there was an organization you could go to with any zero day bug. Even if the FBI is not mismanaged and always tries to protect Americans, you could easily imagine a scenario where someone reports an exploit to an OS where anyone can remotely install a key logger. The FBI wouldn't be a good organ…
> While it may be true that in this particular instance the FBI might act benevolently Indeed. Didn't the FBI effectively purchase a zero day to break into the iPhone of the San Bernardino shooter? Didn't they also then not disclose said zero day to Apple? There's no way that any LE agency can be trusted with this responsibility; I'm not convinced that it can be done by the federal government at all. EFF seems like a…
What Happens When You Send a Zero-Day to a Bank?
351–360 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#352I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...
Re: What Happens When You Send a Zero-Day to a Bank?
#353Earlier quoted context omitted.
Consideration can be as minimal as "your continued employment with this company." It does not have to be any sort of additional dollar amount.
"We won't sue you", however, is not consideration.
[1] http://www.jstor.org/stable/1321438
[2] http://onlinelibrary.wiley.com/doi/10.1111/j.1468-2230.1964....
Re: What Happens When You Send a Zero-Day to a Bank?
#354Earlier quoted context omitted.
I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…
As someone who has been on the receiving end of a bug bounty's mailbox, 3-to-1 sounds about right. We got a ton of invalid "security vulnerabilities" that were essentially either people reporting OAuth as a vulnerability or not understanding how XSS actually worked. Most of these came from teenagers in southeast Asia.
Re: What Happens When You Send a Zero-Day to a Bank?
#355Earlier quoted context omitted.
The response to invalidate is a choice by the bank, not the person who finds the card. Also, that is a single number. It's suspicious/threatening for a non-trivial amount of cards when the presenter also makes demands.
How is "someone has stolen your clients information and likely already sold it to nefarious actors, because otherwise it wouldn't be on the internet anywhere, so you should keep them safe by deactivating those accounts" threatening? I'd be annoyed if my bank didn't do something.
Re: What Happens When You Send a Zero-Day to a Bank?
#356There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
There was a guy who got thrown in prison for bringing a vulnerability to the attention of AT&T. He was thrown in solitary confinement for over a year. Then his sentence got vacated. What did he do as soon as he was released from prison? He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRD…
Re: What Happens When You Send a Zero-Day to a Bank?
#357Re: What Happens When You Send a Zero-Day to a Bank?
#358I'm not quite following the timeline: why did he end up under an NDA and the too-long wait to get it fixed? Why not say "I'm publishing this on my blog in 30 days so it better be fixed by then"? Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?
> Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure? Of course you would. The bank would call the FBI and tell them you're hacking the bank, and the FBI would then knock down your door, tear up your house and drag you away. The system would then do everything it could to represent what you did as a crime, and if you…
I still hope this is not the case in most places outside the US - that is, I hope the responsible disclosure is complete proof you are in fact not hacking anyone.
Re: What Happens When You Send a Zero-Day to a Bank?
#359Note to self: The right thing to do, if you find a serious vulnerability, apparently, is consult an attorney. Geez, what a world.
*America
Re: What Happens When You Send a Zero-Day to a Bank?
#360There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
In a situation like this I'd probably directly ping taviso or someone else from the Google Project Zero team. Their contact information (email, G+, twitter (DM)) is not impossible to get at.
From there, I could get advice about next steps (the Project Zero team are going to know a few people) or maybe they could run with it themselves (depending on the bug; I don't know what the response would have been in this case).