Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

381–390 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#381

Earlier quoted context omitted.

Post them anonymously and see how fast they become too expensive to not fix.

Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…

Also a big issue here, as with many software vulnerabilities, is that the people the public disclosure would actually damage are the users, not the company making the vulnerable software. The bank would only start losing money if the users (personal customers, business customers using their APIs) would notice the hack and start demanding their money back.

Re: What Happens When You Send a Zero-Day to a Bank?

#382
post #344

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

There was a guy who got thrown in prison for bringing a vulnerability to the attention of AT&T. He was thrown in solitary confinement for over a year. Then his sentence got vacated. What did he do as soon as he was released from prison? He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRD…

He didn't "bring the vulnerability to the attention of AT&T" he fucking told Gawker first. Furthermore, he's part of a number of black hat hacker groups, including an anti-semitic one despite the fact that he's Jewish.

There are examples of honest people getting fucked over, but this isn't one of them.

Re: What Happens When You Send a Zero-Day to a Bank?

#383
post #73

Earlier quoted context omitted.

I thought it was significant that they were able to distinguish it as a common-law concept. Are you implying this was something like a lucky guess on their part?

My guess is that 'beefhash is not from a common law country and was only able to figure out for sure that the topic is a part of common law.

Their other comments cause me to guess differently.

Re: What Happens When You Send a Zero-Day to a Bank?

#384

this is a major bombshell. I'd hate to be those guys running zecco. The fact that they coerced an NDA to hide the millions of customer transactions that now have no way of proving were legitimate or not. I'm pretty sure the author wasn't the only guy looking for vulnerability. I'm pretty certain criminal minded folks would've already used it....with no way of finding out which are real or manipulated. Which further r…

Worst case (?) scenario, they were abusing the system themselves or were being pressured to allow others to do so.

It's unlikely, but my point is it's a hole in their system which would allow this to happen and it seems like they've deliberately let it continue. :(

Re: What Happens When You Send a Zero-Day to a Bank?

#385
post #55

Earlier quoted context omitted.

The bank may be able to demonstrate that the vulnerability was not exploited by, e.g., showing that the order preview page was first loaded with the same parameters, or showing a same domain referer.

Maybe the bank should've used this method to prevent the problem in the first place by just checking that the referer request header was from their domain.

You can spoof referrers, you just need some browser extension (or, if using python and requests, doing requests.get(url, headers={'referer': my_referer}) )

Re: What Happens When You Send a Zero-Day to a Bank?

#386
post #248
post #226

Earlier quoted context omitted.

I felt ignorant first when reading it as well. But looking at the "FAQ" at the bottom, it says: "But this only affects people that are logged in, right? Yes ..." So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser. If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with…

>eg viewing a malicous email with the IMG tag in a webmail client The article mentions it would occur even without opening the email.

Well, it is possible your email client is doing prefetching. I wouldn't rate it as probable, since you're unlikely to have a client with the same cookies than your web browser, but still.

You could also abuse Firefox and Chrome prefetching links. I'm not sure Gmail for example remove prefetching attributes in spam links. They do block images though.

Re: What Happens When You Send a Zero-Day to a Bank?

#387
post #374

Earlier quoted context omitted.

No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law. The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume…

...I'm worried of how much incentive there is to become a black hat. Either you risk prison... either earn a lot of bitcoin.

Yeah, the incentives are perverse. This is more of a symptom of the function of our legal apparatus than the law itself, because in theory, going through the legal process should be quick and if not affordable, at least reasonably doable for the individual or small business.

Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some goodwill, especially those that include payouts of five figures or more, but those companies have to be careful that they don't accidentally create an environment where bidding wars between exploiters and companies are legitimized.

Re: What Happens When You Send a Zero-Day to a Bank?

#388

I wrote this a couple years ago about Schwab's embarrasing security. Most of the issues are still there. https://jeremytunnell.com/2014/12/22/swab-password-policies-...

Are most of these actually still there? The password requirements have changed dramatically in the last 6 months.

Well if true, I stand corrected. I have received no communication from Schwab about any changes. I assume that if they had made stronger passwords available, for example, they would notify their customers.

I no longer hold any assets at Schwab, but I do poke around every now and then, and it's possible they changed things without me noticing.

Re: What Happens When You Send a Zero-Day to a Bank?

#389

Earlier quoted context omitted.

"The text of the CFAA forbids "unauthorized access" or "exceeding authorized access"." BOOM! And they've been harsh on hackers for a long time. So, the vulnerability must not require violating access controls or system integrity to be safest. Hackers should be in the clear if it was simply noticing something in HTML/HTTP or whatever that indicated insecurity. An example might be a breakable cipher-suite or handling s…

It sounds awfully close to what got weev sent to jail.

This is a good parallel and you're definitely right. However, weev was charged [0] on 2 counts:

1. conspiracy to access a computer without authorization

2. fraud in connection with personal information

This is because Goatse Security not only noticed the vulnerability itself, but because they wrote and executed a script called the "iPad 3G Account Slurper" to iterate over ICC-IDs, returning the associated email address for each one.

Executing the script against AT&T's servers probably is a bona fide violation of the CFAA, not just a conspiracy, but I would guess it's simpler to bring the conspiracy charge since you don't have to get into the nitty gritty of actual requests made, etc.

According to the complaint, they proceeded to email a handful of notable people whose emails had been harvested, including someone on the Board of Directors at News Corp. All of these contacts appear to be media outlets. The Gawker article also lists some of the people whose email addresses were extracted this way (without disclosing their emails).

I'm assuming this direct communication to journalists and/or execs at journalism outlets gives rise to the fraud with personal information charge.

Overall, I don't think that weev did anything that I wouldn't have necessarily have done if I were in that situation (trying to drum up attention and make a name for his consulting firm), but it's different from this disclosure because as far as we know, this researcher did not actually exploit the vulnerability and he has not obtained or disclosed any information from doing so.

Again, not a lawyer.

[0] https://www.eff.org/document/criminal-complaint

Re: What Happens When You Send a Zero-Day to a Bank?

#390
post #374

Earlier quoted context omitted.

...I'm worried of how much incentive there is to become a black hat. Either you risk prison... either earn a lot of bitcoin.

Yeah, the incentives are perverse. This is more of a symptom of the function of our legal apparatus than the law itself, because in theory, going through the legal process should be quick and if not affordable, at least reasonably doable for the individual or small business. Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some g…

> careful ... bidding wars

Why not? Yes prices can become high, but isn't that the work of the researcher? If the company doesn't want to have to purchase expensive bounties, they can either reduce the exposure (less legacy code, fewer APIs, more firewalls) or use more strict security rules.

I'd feel safer if LastPass' bounty was higher than the value of the assets I put in that vault. If the value of a single vault (mine, actually) is $10,000 and the bug bounty is $2500 (which it is), how can we persuade discoverers to sell to LastPass?

Post reply on HN