Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

391–400 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#391
post #355

Earlier quoted context omitted.

How is "someone has stolen your clients information and likely already sold it to nefarious actors, because otherwise it wouldn't be on the internet anywhere, so you should keep them safe by deactivating those accounts" threatening? I'd be annoyed if my bank didn't do something.

That is a different point. You are changing the party being considered by re-framing it under yourself, a customer, instead of considering it from the point of view of the bank.

That's ridiculous. If the bank is aware that my credentials are available online somewhere and are taking no action to protect me, they're being complicit in any harm that comes to be, because they have both the responsibility and ability to take action, and refuse to. They're being irresponsible and potentially harming their clients.

So again, how is saying "You should take action to protect your customers' data" a threat? How can it be interpreted as a threat? What is threatening about it?

Re: What Happens When You Send a Zero-Day to a Bank?

#392

In Finland, most online stores allow you to pay for your shopping directly using your online bank. The way it works is the online store calls the bank's e-payment API, which in turn lets the user authenticate using their normal online bank credentials and accept the payment. A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implem…

Post them anonymously and see how fast they become too expensive to not fix.

My credit card may be used for an online payement because it tells on a few information (number, cvv, etc.). This is obviously a security problem. Nobody cares: neither me as any payments which are not mine are immediately reverted (and then, maybe, the bank investigates), nor the bank for wom it is cheaper to write off this money then to fix the system.

So no, publicly exposing an issue does not always work if there are no incentives for anyone to fix it.

Re: What Happens When You Send a Zero-Day to a Bank?

#393

Earlier quoted context omitted.

I have no idea since I haven't reviewed the contract. But consideration can be more than just cash money. In some areas and circumstance continued employment can be enough consideration. Or getting access to more information might be enough. There isn't a bright line rule.

We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise. But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at…

Normally, you'd be allowed to look at the entire circumstance to determine consideration if it was unstated. however, this contract contains some pretty strong clauses about the document being the entire terms of the contract. So maybe that would be enough to invalid it.

But that would depend on the specific jurisdictions case law on contracts and then how the judges reading the contract.

If this were my client and he got some kind of consideration, I'd tell him to treat it like a valid contract. Though I'd trying to poke holes in it during litigation. But litigation is losing 9 out of 10 times, even if you win.

Re: What Happens When You Send a Zero-Day to a Bank?

#394
post #224

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

It sounds like you need HackerOne Disclosure Assistance https://support.hackerone.com/hc/en-us/articles/115001936043... This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185 HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the v…

I would be more supportive if HackerOne just gave me a form so I can do this myself. I do not need HackerOne to take credit for my work and and do not need them to represent me. I'm a big boy and can follow my own ethics and take my own consequences.

If other people feel the same way, I'll fork and make a repo. EFF is a great starting point but it is not nearly usable as a HOWTO.

I'm putting my balls on the line by publishing this blog post. Actually I started this blog 10 years ago just to make this page, here is the original page: https://privacylog.blogspot.com/2008/10/pre-announcement.htm...

Re: What Happens When You Send a Zero-Day to a Bank?

#395

Earlier quoted context omitted.

What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?

In this case, the researcher cared because they wanted the bug fixed. Posting the vulnerability publicly risks having it be exploited maliciously, but it also maximizes the likelihood that the bug will actually get fixed, because it's hard to ignore a public vulnerability in your service. If you don't care about your reputation, you post anonymously. An anonymous full disclosure post is a good way to report a bug wit…

I sat on this disclosure for ten years because family told me FBI would go after me. Good advice or bad advice, that was ten years of my life that could have been better spent.

One time I found a photo printing website made all photos public. They refused to fix, I fully disclosed, it made front page Slashdot. Then the company had to change its name. Maybe it was fun or maybe I get credit but most importantly it gets something from my TODO list to my DONE list. This is very important to me.

I have a 0-day on Apple, not very exciting. I reported in 2015 and they still did not fix. Having this in my inbox is a waste of my time thinking about it. I will FD it.

My experience is that security researchers do not make money unless you run script kiddy programs for stupid bounty programs. When I interviewed for a "security" job all they would ask me about is Microsoft certifications and user access testing. I asked if a TLA offer letter counted as sufficient reference and he said no. At that point I immediately switched from MS CS into MS Finance and MBA and my life has improved (while still being technically challenging and academic.)

So technically my disclosure policy is IJDGAF with two extra weeks as a gentleman's favor. Maybe I'm the bad guy, but that's why I'm here for the lovely discussion on YC. Thanks for sharing.

Re: What Happens When You Send a Zero-Day to a Bank?

#396

Earlier quoted context omitted.

What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?

It's "broken window" community policing. The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community. It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visib…

RE Broken Window.

The FBI / NCFTA invited me to speak about this vuln because it may have affected many banks at the time. (Please stop laughing.)

They called me to cancel. "Now we're all focused on this big DOS. Do you know anything about DOS that's happening today you can help us with?" I asked if the DOS is affecting the stability of the system or actually breaking anything. And they said yes it is bringing the banks down and affecting revenue.

You can read into this anecdote as you wish.

Re: What Happens When You Send a Zero-Day to a Bank?

#397
post #196

Earlier quoted context omitted.

Why didn't they just give him $10K to shut up and then go fix the issue? It would be cheaper than all the lawyer fees.

Vulnerabilities like these aren't likely to cost anything close to $10K, even if they stay open for years. But stipulate that there's some number here, and the answer is: because nobody in management at Zecco ever built a plan for how to handle incoming vulnerability reports, and so nobody who got the report was empowered to do anything but escalate the issue --- and halfheartedly, at that, because nobody in manageme…

The person I was in contact with was the CTO Michael Raneri and the General Council. And the CTO was promoted to CEO while the bug was still broken. And then he cashed out and sold the company.

Escalation enough?

Re: What Happens When You Send a Zero-Day to a Bank?

#398
post #196

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Why didn't they just give him $10K to shut up and then go fix the issue? It would be cheaper than all the lawyer fees.

On my phone call it was very awkward because I am spending lots of time helping them, sending multiple PoCs. But I think it improper to ask for money. Maybe if would count as blackmail. So I didn't. Also their ONLY goal, as per article, was to make me STFU. So this is why talks quickly got boring.

Re: What Happens When You Send a Zero-Day to a Bank?

#399

Earlier quoted context omitted.

Vulnerabilities like these aren't likely to cost anything close to $10K, even if they stay open for years. But stipulate that there's some number here, and the answer is: because nobody in management at Zecco ever built a plan for how to handle incoming vulnerability reports, and so nobody who got the report was empowered to do anything but escalate the issue --- and halfheartedly, at that, because nobody in manageme…

The person I was in contact with was the CTO Michael Raneri and the General Council. And the CTO was promoted to CEO while the bug was still broken. And then he cashed out and sold the company. Escalation enough?

What do you want me to tell you? I agree with you: they don't care. It didn't appear to matter for their outcome. They WONTFIXed a CSRF. Are you shocked?

Re: What Happens When You Send a Zero-Day to a Bank?

#400
post #266

Earlier quoted context omitted.

CERT and the Zero Day Initiative handle disclosure for you, in some cases. https://vulcoord.cert.org/VulReport/ http://www.zerodayinitiative.com/about/

Both of these organizations might be "helpful" if you have a new Internet Explorer vulnerability, but neither will likely help you with a CSRF bug in a bank website.

Still, thanks for sharing. Research ethics is always something I'm interested to read.
Post reply on HN