Live data from Hacker News

Sei pays out $2M bug bounty

usmannkhan.com

101–110 of 133 posts

Re: Sei pays out $2M bug bounty

#101

Earlier quoted context omitted.

Everything in finance... banks have the same bug bounty.

Not really. Bank transactions are reversible (especially when banks themselves are affected). And if you try to wire money to your account, you will be found trivially.

Sometimes they are. There's a network of seedy international banks that scammers use to take their victims money, because otherwise the scam wouldn't work.

Re: Sei pays out $2M bug bounty

#102

Earlier quoted context omitted.

Not really. Bank transactions are reversible (especially when banks themselves are affected). And if you try to wire money to your account, you will be found trivially.

Sometimes they are. There's a network of seedy international banks that scammers use to take their victims money, because otherwise the scam wouldn't work.

Do you have examples? People can avoid them

Re: Sei pays out $2M bug bounty

#103

Earlier quoted context omitted.

Everything in finance... banks have the same bug bounty.

Not really. Bank transactions are reversible (especially when banks themselves are affected). And if you try to wire money to your account, you will be found trivially.

Definitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe.

See also all the people pissed at zelle.

Re: Sei pays out $2M bug bounty

#104
post #102

Earlier quoted context omitted.

Sometimes they are. There's a network of seedy international banks that scammers use to take their victims money, because otherwise the scam wouldn't work.

Do you have examples? People can avoid them

The scammers wire the money out of your account into a bank account they control, and then put it in another bank, and then move it further on from there. Knowing which bank they have their account at doesn't help you avoid the problem.

Re: Sei pays out $2M bug bounty

#105
post #102

Earlier quoted context omitted.

Do you have examples? People can avoid them

The scammers wire the money out of your account into a bank account they control, and then put it in another bank, and then move it further on from there. Knowing which bank they have their account at doesn't help you avoid the problem.

Yeah I understood the mechanism, just wanted to know the companies that enable such things.

Re: Sei pays out $2M bug bounty

#106
post #98
post #92

Earlier quoted context omitted.

Try thinking through other comparisons to understand the difference: if I find a bug in the power grid, how do I cash out? There aren’t many buyers, it’s really hard to move a lot of cash without getting caught, and if I use any other electronic system I have to pay a ton of money to get help laundering it because the risks are so high. Criminal outfits in Asia play games trying to get gift cards or things like that…

I have a general rule of exploit sales which nobody has shot me down on yet and I'm increasingly confident about: people are buying non-speculative outcomes. Every dorm room conversation about vulnerability valuation inevitably veers into speculation about what bank-shot outcomes a buyer might hope to achieve with a purchase. The reality is that unless the buyer is getting exactly an outcome they already planned (and…

That’s a really good way to think about it. Having been security-adjacent for a long time, I definitely remember the reactions of dread which some of the earlier big vulnerabilities in things like OpenSSL got, which were never exploited at the feared scale, and that’s well explained by your theory: the NSA isn’t interested in every phone in a country, and a lot of unsexy vulnerabilities like WordPress exploits are going to be more widely attacked because people know how to make money with ad/affiliate spam, SEO, etc.

Re: Sei pays out $2M bug bounty

#107

Earlier quoted context omitted.

Not really. Bank transactions are reversible (especially when banks themselves are affected). And if you try to wire money to your account, you will be found trivially.

Definitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe. See also all the people pissed at zelle.

Nothing is true in absolute terms but banks care about loss percentages and that’s much better in the real banking sector.

For example, the national bank of Bangladesh was compromised in 2016, believed to be a well-resourced attack by North Korea, and the attacker was able to attempt to transfer $1B. That’s about as severe as it gets, but the U.S. Federal Reserve blocked 85% of the transferred funds and of the remaining funds, all of the money sent to Sri Lanka was recovered, and they were able to recover some of the funds laundered through a corrupt bank in the Philippines whose manager was subsequently charged. About $64M was laundered through casinos which were not at the time required to follow KYC.

https://www.bbc.com/news/stories-57520169

So, not great, but the losses are under 10% of the amount the hackers had access to and there’s still a chance of recovering the rest - that’s survivable with insurance and it’s basically the traditional finance world at its worst in terms of corruption & poor preparation. Compare it to cryptocurrency, where losses on that scale happen multiple times a year rather than once a decade, and the attackers have a much easier time laundering funds through the infrastructure setup for exactly that purpose. North Korea is getting over a billion dollars a year from cryptocurrency, which is much better than the tens of millions at greater risk they got here.

Re: Sei pays out $2M bug bounty

#109
post #107

Earlier quoted context omitted.

Definitely not true. My last company had the finance department phished and they never recovered the funds. It was about $50k I believe. See also all the people pissed at zelle.

Nothing is true in absolute terms but banks care about loss percentages and that’s much better in the real banking sector. For example, the national bank of Bangladesh was compromised in 2016, believed to be a well-resourced attack by North Korea, and the attacker was able to attempt to transfer $1B. That’s about as severe as it gets, but the U.S. Federal Reserve blocked 85% of the transferred funds and of the remain…

This discussion has really gone off the rails.

All I was saying was that banks have a bug bounty on their head, the next person responded that bank transactions are reversible, which isn't entirely true in all cases.

I wasn't trying to compare sizes or anything like that.

Post reply on HN