Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

401–410 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#401

Earlier quoted context omitted.

In this case, the researcher cared because they wanted the bug fixed. Posting the vulnerability publicly risks having it be exploited maliciously, but it also maximizes the likelihood that the bug will actually get fixed, because it's hard to ignore a public vulnerability in your service. If you don't care about your reputation, you post anonymously. An anonymous full disclosure post is a good way to report a bug wit…

I sat on this disclosure for ten years because family told me FBI would go after me. Good advice or bad advice, that was ten years of my life that could have been better spent. One time I found a photo printing website made all photos public. They refused to fix, I fully disclosed, it made front page Slashdot. Then the company had to change its name. Maybe it was fun or maybe I get credit but most importantly it gets…

You have never heard me say IDGAF is an unethical policy. If you've paid attention to me here (I don't know why you would), all you've seen me do is point out how Orwellian and coercive the term "responsible disclosure" is.

For a CSRF that you didn't use someone else's account to exploit and that you've told nobody about, and assuming you have no acquaintances who might screw you over by abusing the bug, 30 days and then Pastebin seems like a decent answer.

If any of your friends are shady, just forget about the bug.

Re: What Happens When You Send a Zero-Day to a Bank?

#402

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

Professional association of security researchers? Come up with a good set of guiding principles for members. This would help avoid waiting 7 years and then sticking it online. Not criticising, I'm saying the situation here is pretty screwed up. Members pay dues, the association provides backing. Company threatens to call the FBI and the association is the one they can deal with. An organized group can help to provide…

Thank you. This seems like a great idea. I would be more open about it. Rather than fees and membership, I would have a list of contributors and cross-checked publications. Basically like a resume. I.e. if you want to announce a vuln we would help you timestamp it, and optionally have a person you trust vouch for its authenticity. And if having that timestamp and cross check is valuable to you then you can brag about it when you contact the vendor.

I'd like to work in an organization like this. I'm not sure if anyone would want to join. It seems like everyone else is either completely independent like my own IDJGAF strategy or they are full corporate like HackerOne and other brokers.

Re: What Happens When You Send a Zero-Day to a Bank?

#403
post #360

There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…

I was thinking of exactly this as I read the article. In a situation like this I'd probably directly ping taviso or someone else from the Google Project Zero team. Their contact information (email, G+, twitter (DM)) is not impossible to get at. From there, I could get advice about next steps (the Project Zero team are going to know a few people) or maybe they could run with it themselves (depending on the bug; I don'…

Thank you, going forward this looks like a great start. And I have always had great experience reaching directly to Googlers when needing connections or technical advice.

Re: What Happens When You Send a Zero-Day to a Bank?

#404

Earlier quoted context omitted.

Maybe but I, personally, would not want to take the risk that I might need to defend that proposition in court.

Nothing can protect you from the lawsuit being brought, but it will likely be thrown out. That's the same with anything, and whether you short a stock or not. If you short it, at least you might make some money to offset any pending lawsuit. There's plenty of examples of people doing the same thing to fall back on, such as the guy who found out a newly listed company wasn't actually real[1]. 1: http://www.npr.org/201…

And even more general. Any form of profit will attract the possibility of defending yourself in court.

Re: What Happens When You Send a Zero-Day to a Bank?

#405
post #380

Earlier quoted context omitted.

I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…

Here is some context for what I'm about to write: I managed a bug bounty for a sizable arm of BBVA. I have temporarily managed bug bounties for many smaller tech companies. In 2014, I surveyed the the industry as BugCrowd and Hackerone were coming into prominence. Bug bounties, on average, have a signal:noise ratio that is horrible. I advocate for the programs completely, but they require a lot of planning in order t…

BBVA? I have been trying to get in touch with them regarding an app of theirs (Access Key Extranet by BBVA Bancomer, S.A. https://appsto.re/us/4QEKfb.i) which does not properly validate TLS certificates.

Re: What Happens When You Send a Zero-Day to a Bank?

#407
post #21

Kudos to the author, and hopefully they don't get sued as a result. This bullshit with corporations trying to cover up security vulnerabilities (rather than fix them) needs to stop. "Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.

Thanks for the support! So glad to see supportive people that recognize what is going on here.

Re: What Happens When You Send a Zero-Day to a Bank?

#408
post #21

Kudos to the author, and hopefully they don't get sued as a result. This bullshit with corporations trying to cover up security vulnerabilities (rather than fix them) needs to stop. "Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.

No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law. The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume…

Here's what really happened. I talked with my doctors and realized that I only have so much time left to live. Writing this article was of the items about putting my affairs in order. So short term this was a good decision.

Otherwise, in court I'll be happy to defend myself. If it is necessary to spend time to defend yourself then that is a blessing. I have successfully sued the government (the US Army and Veterans affairs, no less) http://www.gao.gov/docket/B-413723.2 when they do things wrong. Just be persistent and be right. Then we came out with a nice settlement. Sorry GAO used to publish fulltext docket outcomes but I don't see it here.

Fuck Nissan. (Can we curse here on HN?) Because their cars suck and because of this case that I am well aware of. The sad thing is that Mr. Nissan spent so much money in defense. I should hope that he would be able to be more effective with less money.

Re: What Happens When You Send a Zero-Day to a Bank?

#409
post #341

Earlier quoted context omitted.

No one should independently contact a company about this type of issue without first obtaining competent legal advice. And I do mean competent advice; most lawyers are very technically illiterate and will not be sympathetic, let alone familiar with the relevant areas of law. The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume…

My father is a (technically literate, he used to be a database architect) lawyer, and the general advice he gave me was that if you are in a situation where you have a critical vulnerability you should disclose it through a lawyer anonymously -- your identity is then protected under attorney-client privilege (assuming you haven't just asked your lawyer to commit a crime by disclosing it). IANAL though.

Interesting idea. Thank you for sharing. Is the goal just anonymity? Technically we already have solutions for anonymous disclosure of documents. Are there other benefits?

Re: What Happens When You Send a Zero-Day to a Bank?

#410
post #390

Earlier quoted context omitted.

Yeah, the incentives are perverse. This is more of a symptom of the function of our legal apparatus than the law itself, because in theory, going through the legal process should be quick and if not affordable, at least reasonably doable for the individual or small business. Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some g…

> careful ... bidding wars Why not? Yes prices can become high, but isn't that the work of the researcher? If the company doesn't want to have to purchase expensive bounties, they can either reduce the exposure (less legacy code, fewer APIs, more firewalls) or use more strict security rules. I'd feel safer if LastPass' bounty was higher than the value of the assets I put in that vault. If the value of a single vault…

Yes, this is why I don't use LastPass. As soon as I saw this I realized they must be a joke.
Post reply on HN