About a month ago I noticed that my bank had a vulnerability - I could access the details and photos of every remotely deposited check. I sent them an email, they took the feature offline in about 2 hours. No bug bounty but oh well.
My bank used to show deposited check photos in a popup with the URL viewable iirc, and sometime they switched to a modal window with base64 data as the source instead of a URL that might be manipulated. I wonder how many small banks still may have bugs like that
What Happens When You Send a Zero-Day to a Bank?
421–430 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#422Exactly what happened to me with Starbucks ( https://sakurity.com/blog/2015/05/21/starbucks.html ) - threats, signing NDA, they disappear.
Re: What Happens When You Send a Zero-Day to a Bank?
#423Earlier quoted context omitted.
I'm not so sure it's fraud for 2 reasons: 1) how easy it would/should be for the buyer to discover the issue; 2) these transactions generally have very detailed disclaimers / disclosure -- basically making them 'as-is' transactions. If I were a betting man, I'd bet the buyer knew about the issue and basically didn't care.
Yet security researchers go to prison for iterating the ID numbers in a URL to access private profile pages :/ This is negligent. If they are running banking ecommerce infrastructure and are unable to deal with 101 security risks then it is absolutely negligent. The "it is too complex for the average person" isn't an adequate defense. The only thing is that there has to be someone who lost something of real value for…
In your contact with companies you should say "Failing to fix this issue would be a violation of reasonably assumed security practices as required in LAW..."
Re: What Happens When You Send a Zero-Day to a Bank?
#424Archived copy, which can be read without JS enabled: https://archive.fo/8ZpDJ
I would like to migrate to my own domain with Jekyll or something. But I would not look forward to implementing commenting and trackbacks even though the blog is pretty modest any way in terms of using those features.
Re: What Happens When You Send a Zero-Day to a Bank?
#425Nitpick: was this disclosed to a bank or a broker? Not sure it matters tbf
Motivation was clickbait and/or fear that people would not understand the latter.
Re: What Happens When You Send a Zero-Day to a Bank?
#426Serious question: Would the FBI actually come to your door if you went full disclosure with a banking zero day? Is there real legal exposure here or was that just bluster from Zecco/TradeKing?
BUT actually this vuln may have been from upstream with Penson. And then it may affect many broker-dealers. They have many clients in US and Canada. (Don't laugh that such a ridiculous vuln could be in so many places.)
At the time, considering this (and Penson was on the phone) I understood that irresponsible disclosure could have serious consequences. FBI would have been warranted to knock on my door.
That's why I'm now publishing 10 years after the fact.
Re: What Happens When You Send a Zero-Day to a Bank?
#427I would not be surprised if this turns into a class action lawsuit. The negligence here is remarkable.
You need damages to have a class action lawsuit. What are your damages? I am not saying no one has damages, but if 100s of people had damages, I expect something would have happened...
Re: What Happens When You Send a Zero-Day to a Bank?
#428I'm not quite following the timeline: why did he end up under an NDA and the too-long wait to get it fixed? Why not say "I'm publishing this on my blog in 30 days so it better be fixed by then"? Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?
Next time I would change 30 to a reasonable number. In this case (multiple vendors and a large installed base) maybe even 180 days may have been fair. And then I would stick to my guns.
Re: What Happens When You Send a Zero-Day to a Bank?
#429Just to be clear I also find it appalling that any important institution would take their time in fixing such a simple exploit. But it seems the reason why these cases don't get resolved quickly is purely for economic reasons: the perceived cost of fixing the issue seems (to them) is far greater than the cost of dealing with the (remote?) possibility of the exploitation of the vulnerability. I also think the security…
FIRST, be reasonable. This is a good life axiom. Don't expect a large organization to confirm, engineer, test certify, and deploy a change that requires external documentation in less than 14 days. Even if the ship's on fire.
SECOND, be valuable. If you are reporting a vuln that is a bug report. When's the last time you got thanked for /any/ buy report for a non-GitHub project? If your report explains the cost and liability for lawsuit if they fail to fix your reported vuln then you are speaking their language.
---
I have a confirmed vuln reported to Apple under their "responsible disclosure" program since 2015. They have yet to fix it or provide credit as they promised. If you thought Apple was a magic company that "does the right thing", then I hope this dispels that myth.
Re: What Happens When You Send a Zero-Day to a Bank?
#430Earlier quoted context omitted.
He was afraid that he was bound by the NDA not to disclose it. Now, in 2017, he flouts the NDA and acts in the public interest.
But why now? What changed?