Earlier quoted context omitted.
Post them anonymously and see how fast they become too expensive to not fix.
Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…
What Happens When You Send a Zero-Day to a Bank?
411–420 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#412In Finland, most online stores allow you to pay for your shopping directly using your online bank. The way it works is the online store calls the bank's e-payment API, which in turn lets the user authenticate using their normal online bank credentials and accept the payment. A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implem…
The correct solution before this was to make an announcement:
"Here is the announcement I have made disclosing the problem. It is in both our best interest that it get fixed before publication. I have irrevocably given it to a blind drop that will publish it on DATE. And I believe that is a reasonable DATE that you could fix the problem. Let's work together to fix the problem."
What do you think about this type of approach? There is probably a name for it in Art of the Deal. (Whatever you think of the man, the book is worth reading.)
Re: What Happens When You Send a Zero-Day to a Bank?
#413Earlier quoted context omitted.
Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…
Also a big issue here, as with many software vulnerabilities, is that the people the public disclosure would actually damage are the users, not the company making the vulnerable software. The bank would only start losing money if the users (personal customers, business customers using their APIs) would notice the hack and start demanding their money back.
The wording you choose should be cognizant of your state's laws and the company's user agreement in such a way that the company is actually at risk if they ignore you.
When talking to people, "Reason is, and ought only to be the slave of the passions".
When talking to companies it is only necessary to discuss the impact on their profit.
Re: What Happens When You Send a Zero-Day to a Bank?
#414Earlier quoted context omitted.
I believe the idea is nobody would willingly sign a contract that does nothing to benefit themselves so they must have been mislead into the agreement thus it is invalid. Sort of a rational actor theory of law.
Isn't the benefit for William that he was provided some confidential information in addition to what he already knew?
Re: What Happens When You Send a Zero-Day to a Bank?
#415Earlier quoted context omitted.
I wouldn't be so sure - for example, out of court settlements pretty much amount to "We'll pay you $x without admitting that we ever did something wrong, and you agree not to sue us over that thing that we totally did not do.", and these definitely are valid contracts.
Not suing in that case is the terms of the contract. The consideration is $x for party A and for party B it's not having to admit wrongdoing. Had the NDA in question given William $x to not disclose the security hole then he would certainly would be in breach of contract. But the NDA gave him nothing.
Re: What Happens When You Send a Zero-Day to a Bank?
#416Earlier quoted context omitted.
This was my question: is this NDA even enforceable and why would the author have signed it?
My reading is that he signed it because he was falsely made to believe he may have done something illegal and this would protect him from the FBI. I.e. he was coerced.
Re: What Happens When You Send a Zero-Day to a Bank?
#417Earlier quoted context omitted.
We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise. But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at…
Normally, you'd be allowed to look at the entire circumstance to determine consideration if it was unstated. however, this contract contains some pretty strong clauses about the document being the entire terms of the contract. So maybe that would be enough to invalid it. But that would depend on the specific jurisdictions case law on contracts and then how the judges reading the contract. If this were my client and h…
Re: What Happens When You Send a Zero-Day to a Bank?
#418Earlier quoted context omitted.
There's a helicopter crashed in a house. I don't need to be a pilot to know it's not supposed to do that.
This is actually pretty close to how I personally define a "professional": A professional is someone whose work can only be judged by other professionals of the same domain. Obvious failure modes are exempted. Anyone can tell you about a bad bridge after it has failed. But it would take a bridge engineer to tell you that before it fails. https://news.ycombinator.com/item?id=8960822#8963307
Re: What Happens When You Send a Zero-Day to a Bank?
#419Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
Re: What Happens When You Send a Zero-Day to a Bank?
#420There was no value in discussing this over the phone. Clearly their only motivation was to trick him into signing the NDA or foolishly becoming an employee to keep him silenced. Just send in the bug report and empty your account. If the bug persists after 6 months then close the account and go to public disclosure.
However if the FBI and NCFTA were /genuinely/ interested in disclosing this in their forum for other banks then maybe my phone call with them may have been a win-win. But I think they were not genuinely interested.