Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

411–420 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#411

Earlier quoted context omitted.

Post them anonymously and see how fast they become too expensive to not fix.

Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…

This is not spite, please see full reply to parent.

Re: What Happens When You Send a Zero-Day to a Bank?

#412

In Finland, most online stores allow you to pay for your shopping directly using your online bank. The way it works is the online store calls the bank's e-payment API, which in turn lets the user authenticate using their normal online bank credentials and accept the payment. A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implem…

You have reached zugzwang in game theory parlance.

The correct solution before this was to make an announcement:

"Here is the announcement I have made disclosing the problem. It is in both our best interest that it get fixed before publication. I have irrevocably given it to a blind drop that will publish it on DATE. And I believe that is a reasonable DATE that you could fix the problem. Let's work together to fix the problem."

What do you think about this type of approach? There is probably a name for it in Art of the Deal. (Whatever you think of the man, the book is worth reading.)

Re: What Happens When You Send a Zero-Day to a Bank?

#413

Earlier quoted context omitted.

Unless you think this would actually lead to banks taking such vulnerabilities more seriously in general--which I don't believe is the case--taking an action like that is pure spite. Consider the possible outcomes for this particular vulnerability: [1] nothing happens, [2] it gets heavily exploited, customers lose money, and it doesn't get fixed, [3] the same thing happens and it does get fixed. In all three cases, t…

Also a big issue here, as with many software vulnerabilities, is that the people the public disclosure would actually damage are the users, not the company making the vulnerable software. The bank would only start losing money if the users (personal customers, business customers using their APIs) would notice the hack and start demanding their money back.

It would be very nice if your security disclosure report included a section about how you have provide good faith upfront notice to the vendor and that based on research and belief it would be negligent for the company to not fix the issue by X date.

The wording you choose should be cognizant of your state's laws and the company's user agreement in such a way that the company is actually at risk if they ignore you.

When talking to people, "Reason is, and ought only to be the slave of the passions".

When talking to companies it is only necessary to discuss the impact on their profit.

Re: What Happens When You Send a Zero-Day to a Bank?

#414

Earlier quoted context omitted.

I believe the idea is nobody would willingly sign a contract that does nothing to benefit themselves so they must have been mislead into the agreement thus it is invalid. Sort of a rational actor theory of law.

Isn't the benefit for William that he was provided some confidential information in addition to what he already knew?

Basically, per our phone call, my consideration was duress. As in "sign this or else..."

Re: What Happens When You Send a Zero-Day to a Bank?

#415

Earlier quoted context omitted.

I wouldn't be so sure - for example, out of court settlements pretty much amount to "We'll pay you $x without admitting that we ever did something wrong, and you agree not to sue us over that thing that we totally did not do.", and these definitely are valid contracts.

Not suing in that case is the terms of the contract. The consideration is $x for party A and for party B it's not having to admit wrongdoing. Had the NDA in question given William $x to not disclose the security hole then he would certainly would be in breach of contract. But the NDA gave him nothing.

When they were drafting the "contract", the concept of consideration was very interesting. I had considered that if I would receive cash for agreeing to not disclose then this would be blackmail which apparently is bad.

Re: What Happens When You Send a Zero-Day to a Bank?

#416
post #93

Earlier quoted context omitted.

This was my question: is this NDA even enforceable and why would the author have signed it?

My reading is that he signed it because he was falsely made to believe he may have done something illegal and this would protect him from the FBI. I.e. he was coerced.

Yes.

Re: What Happens When You Send a Zero-Day to a Bank?

#417

Earlier quoted context omitted.

We definitely don't have all the facts and learning new facts could definitely change the direction of the conversation. I hope that we all understand that this arm-chair lawyering is, at its core, a hypothetical exercise. But even if we are allowed to infer consideration, and I agree with you that we are, this contract isn't simply lacking the terms of consideration. It doesn't appear to contemplate consideration at…

Normally, you'd be allowed to look at the entire circumstance to determine consideration if it was unstated. however, this contract contains some pretty strong clauses about the document being the entire terms of the contract. So maybe that would be enough to invalid it. But that would depend on the specific jurisdictions case law on contracts and then how the judges reading the contract. If this were my client and h…

Thank you, and also parents. This discussion is very relieving for me.

Re: What Happens When You Send a Zero-Day to a Bank?

#418

Earlier quoted context omitted.

There's a helicopter crashed in a house. I don't need to be a pilot to know it's not supposed to do that.

This is actually pretty close to how I personally define a "professional": A professional is someone whose work can only be judged by other professionals of the same domain. Obvious failure modes are exempted. Anyone can tell you about a bad bridge after it has failed. But it would take a bridge engineer to tell you that before it fails. https://news.ycombinator.com/item?id=8960822#8963307

I like your definition better than "a trade that requires paying a fee to a local bureaucracy."

Re: What Happens When You Send a Zero-Day to a Bank?

#419

Lesson learned: when reporting a vulnerability, record all discussions from first contact with the vendor. At least in cases where the vendor doesn't have a clear, easy to find policy and/or bounty for disclosures. I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing…

I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...

Just asking for a friend, but Pennsylvania and California are two-party recording states. Is there a statute of limitations after when releasing an undisclosed recording between a Pennsylvanian and a Californian would not be considered an offense?

Re: What Happens When You Send a Zero-Day to a Bank?

#420

There was no value in discussing this over the phone. Clearly their only motivation was to trick him into signing the NDA or foolishly becoming an employee to keep him silenced. Just send in the bug report and empty your account. If the bug persists after 6 months then close the account and go to public disclosure.

Yes, this is my new IJDGAF policy. The phone call was a losing proposition from the beginning.

However if the FBI and NCFTA were /genuinely/ interested in disclosing this in their forum for other banks then maybe my phone call with them may have been a win-win. But I think they were not genuinely interested.

Post reply on HN