Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

441–450 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#441

I'm not quite following the timeline: why did he end up under an NDA and the too-long wait to get it fixed? Why not say "I'm publishing this on my blog in 30 days so it better be fixed by then"? Would you risk getting in legal trouble for publishing a way to do bank fraud (for example) - assuming you gave some reasonable timeframe for disclosure?

That's how I started the discussion with Zecco. The next phone call had the FBI on the line. Then I signed the NDA. Next time I would change 30 to a reasonable number. In this case (multiple vendors and a large installed base) maybe even 180 days may have been fair. And then I would stick to my guns.

Thanks for the follow up and good luck next time!

Re: What Happens When You Send a Zero-Day to a Bank?

#442
post #67

Archived copy, which can be read without JS enabled: https://archive.fo/8ZpDJ

Thank you and I am sorry that my blog has offended your browser. Would you like to recommend a better hosting service I could use instead of the wildly antiquated Blogger? I would like to migrate to my own domain with Jekyll or something. But I would not look forward to implementing commenting and trackbacks even though the blog is pretty modest any way in terms of using those features.

According to https://news.ycombinator.com/item?id=13355531 , JS requirement is not a problem with Blogger per se, but with some of its themes.

Re: What Happens When You Send a Zero-Day to a Bank?

#444
post #380

Earlier quoted context omitted.

I'm pretty surprised at this: >For every valid report they get, they get 3 that aren't valid. Because taking the time to write and to submit an invalid report is a total waste of the reporter's time. Reports aren't the type of thing that someone will accidentally say "oh this is a severe vulnerability! here's some cash" even though the researcher has submitted bullshit. So can you talk about "3 that aren't valid" for…

Here is some context for what I'm about to write: I managed a bug bounty for a sizable arm of BBVA. I have temporarily managed bug bounties for many smaller tech companies. In 2014, I surveyed the the industry as BugCrowd and Hackerone were coming into prominence. Bug bounties, on average, have a signal:noise ratio that is horrible. I advocate for the programs completely, but they require a lot of planning in order t…

Thanks for this detailed write-up! Super informative.

Re: What Happens When You Send a Zero-Day to a Bank?

#445
post #341

Earlier quoted context omitted.

My father is a (technically literate, he used to be a database architect) lawyer, and the general advice he gave me was that if you are in a situation where you have a critical vulnerability you should disclose it through a lawyer anonymously -- your identity is then protected under attorney-client privilege (assuming you haven't just asked your lawyer to commit a crime by disclosing it). IANAL though.

Interesting idea. Thank you for sharing. Is the goal just anonymity? Technically we already have solutions for anonymous disclosure of documents. Are there other benefits?

A technical solution to the anonymity problem would probably work just as well (assuming it wasn't backdoored), though the protections against a lawyer disclosing their client is legal rather than technical (so the "splatter" from a company's over-reaction are more likely to be smaller). You also get the additional benefit of the company probably taking a disclosure more seriously if it comes with a law firm's letterhead (unfortunately).

Re: What Happens When You Send a Zero-Day to a Bank?

#446
post #248

Earlier quoted context omitted.

>eg viewing a malicous email with the IMG tag in a webmail client The article mentions it would occur even without opening the email.

Well, it is possible your email client is doing prefetching. I wouldn't rate it as probable, since you're unlikely to have a client with the same cookies than your web browser, but still. You could also abuse Firefox and Chrome prefetching links. I'm not sure Gmail for example remove prefetching attributes in spam links. They do block images though.

Good point.

Anyways, how would it work with the server receiving any data from the client just by viewing the link in your browser?

Re: What Happens When You Send a Zero-Day to a Bank?

#447

Earlier quoted context omitted.

I am one such attorney.

Can I get your number?

My sn is my name. I am the only lawyer named Liberty that I am aware of.

More easily, my profile on my firm's website: lawyernamedliberty.com. I'm fairly easy to get in touch with.

Re: What Happens When You Send a Zero-Day to a Bank?

#448

On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…

Who logs into their bank from a public computer? Genuinely curious.

When on holiday this is quite common. With 2-factor auth this is fine.

Re: What Happens When You Send a Zero-Day to a Bank?

#449

Earlier quoted context omitted.

As someone who lives in Texas, I can confirm that Texas is a one-party state. I specifically do not need to inform people of recording devices if I am a party to the conversation . It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring.

> It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring. Google is based in California. There is a good probability that the act of recording occurs there. California is an all-party consent state. Also, even if the recording isn't happening in California, it's potentially tricky to be sure that no party to the call is in California (even numbers assigned to…

From my naive understanding and possible spotty recollection of the law(s) involved: in the US at least, as long as the recording party is in a one-party state then it doesn't matter where the other parties are located.

Re: What Happens When You Send a Zero-Day to a Bank?

#450

Earlier quoted context omitted.

You could always send an anonymous, or not, tip to KrebsOnSecurity.com. Brian has the skill to handle this kind of disclosure and the street cred to avoid pitfalls.

Has he said that he's willing to be a liaison like that? If not, you'd be putting an unfair burden on him by doing that.

Krebs has sources contact him all the time.
Post reply on HN