Earlier quoted context omitted.
I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.
The options aren't just returning it or stealing it, they can simply leave it where it is to avoid the hassle of having to return it. Hence why having a custom of paying a reward might be beneficial for wallet losers in general.
The Bank Job – breaking a mobile banking application
11–20 of 42 posts
Re: The Bank Job – breaking a mobile banking application
#12It's actually important to name the vendor responsible for this mess so this doesn't happen again.
Re: The Bank Job – breaking a mobile banking application
#13Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.
Re: The Bank Job – breaking a mobile banking application
#14Earlier quoted context omitted.
It would be common sense to pay a bounty. Similar to the reward you should get if you find somebody's wallet. If you are known for not paying a bounty (a finder reward) some people will not tell you your security holes (will not give you back your wallet). On the long run this will be more expensive than the bounty. But the problem might be that if the would pay a bounty, they would admit that the screwed it, what th…
I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.
Not sure if the finder or the business took the cash but I guess they got their own reward. Not what I would do, but I'm glad they didn't take the cash and trash the wallet..
Re: The Bank Job – breaking a mobile banking application
#15The post is interesting, but I do not know why people assume they would get a bounty for a security report if the company does not have responsible disclosure / bounty program.
OP here. I knew the bank wouldn't pay. But I wanted to initiate a discussion with the bank so they know that paying bounty for disclosures is a thing.
You gave them a tech analysis that should be worth some money, for free, at the same time (hopefully) bringing to their attention how bounty programs are a helpful thing for everyone. They should be feeling very lucky about it.
However, the thing that worries me with these things is that, what if some "bad guys" already knew about this and exploiting it and now that the bank is aware and might close the hole, makes them angry and looking for retaliation?
Hopefully you are taking precautions to be anonymous, but I know that where I live if I were to pull a stunt like that I would seriously consider watching my back for a while.
Sad world we live in :( so take care OP.
Re: The Bank Job – breaking a mobile banking application
#16It's actually important to name the vendor responsible for this mess so this doesn't happen again.
Re: The Bank Job – breaking a mobile banking application
#17It's actually quite heart-breaking to see the extent gone to to reveal the bug, and then to disclose it in full, for zero reward. Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.
As an aside, the OP claims it took 12 days to resolve but it is possible they took more immediate action by disabling the mobile app's ability to do transfers until they had resolved all the issues.
Re: The Bank Job – breaking a mobile banking application
#18Earlier quoted context omitted.
OP here. I knew the bank wouldn't pay. But I wanted to initiate a discussion with the bank so they know that paying bounty for disclosures is a thing.
Nice work OP. You gave them a tech analysis that should be worth some money, for free, at the same time (hopefully) bringing to their attention how bounty programs are a helpful thing for everyone. They should be feeling very lucky about it. However, the thing that worries me with these things is that, what if some "bad guys" already knew about this and exploiting it and now that the bank is aware and might close the…
Re: The Bank Job – breaking a mobile banking application
#19It's actually quite heart-breaking to see the extent gone to to reveal the bug, and then to disclose it in full, for zero reward. Whether or not a bug bounty programme exists at a company, if a bug this severe comes through the door, it should warrant a reward.
Presumably any reward would need to be approved by an executive other than just the IT director since clearly they have no policy in place. The IT director would not want his department's incompetence to be known higher up the board. As an aside, the OP claims it took 12 days to resolve but it is possible they took more immediate action by disabling the mobile app's ability to do transfers until they had resolved all…
Re: The Bank Job – breaking a mobile banking application
#20Earlier quoted context omitted.
It would be common sense to pay a bounty. Similar to the reward you should get if you find somebody's wallet. If you are known for not paying a bounty (a finder reward) some people will not tell you your security holes (will not give you back your wallet). On the long run this will be more expensive than the bounty. But the problem might be that if the would pay a bounty, they would admit that the screwed it, what th…
I would absolutely never expect or even accept a reward for a lost wallet. It's our duty as a member of a civilized society to not steal. If a wallet finder failed to give me my wallet back, I'd just call the police.