What Happens When You Send a Zero-Day to a Bank?
231–240 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#232On a similar, but separate note, my bank launched a new version of its online banking platform. From launch I noticed it opened my accounts in a new tab while leaving my credentials (password and all) in the sign-in form. Not so bad when signing in from home - horrific if you're signing in from a public computer. I tweeted to the bank and spoke to someone on the phone about it. It's been 3 months and the bug is still…
Who logs into their bank from a public computer? Genuinely curious.
Re: What Happens When You Send a Zero-Day to a Bank?
#233Earlier quoted context omitted.
Your statement is 100% incorrect. P.S. It might be of limited correctness, only in some states, in the USA. I'd suggest you don't talk people into signing perfectly valid contracts hoping for an unlikely loophole.
Care to explain why he's wrong, or are we to assume your expertise, random internet person?
You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.
Re: What Happens When You Send a Zero-Day to a Bank?
#234There needs to exist a legal entity/non-profit or company that acts as a shield and/or escrow for these kinds of situations. Basically, as a researcher you can have them deal with the company/organization for you, including dealing with any threats, collecting any bounties due, and such. The company could have domain expertise of the industry, laws, and generally be a force against these companies -- the analogy woul…
Come up with a good set of guiding principles for members. This would help avoid waiting 7 years and then sticking it online. Not criticising, I'm saying the situation here is pretty screwed up.
Members pay dues, the association provides backing. Company threatens to call the FBI and the association is the one they can deal with.
An organized group can help to provide the needed political pressure so that a properly disclosed vulnerability doesn't ever lead to the FBI and trumped up charges.
A respected group can lend credibility to a researcher. A bank may not give 2 shits about even a well respected member of the community. They will care if it's a group well known for finding and disclosing vulnerabilities.
This seems like an easier problem than the general case of software engineers because the community is smaller and you don't have the conflicting interests of "I can negotiate better on my own". Plus things like membership can be handled more easily, start with a small group of people who absolutely should be members. Extend via application and invite.
Re: What Happens When You Send a Zero-Day to a Bank?
#235Earlier quoted context omitted.
Care to explain why he's wrong, or are we to assume your expertise, random internet person?
Assume the expertise. A whole semester of university dedicated to contract law: Consumer contracts and B2B contracts in the national law, then the specifics when dealing with a party in another European country and internationally. You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.
http://www.nolo.com/legal-encyclopedia/consideration-every-c...
Re: What Happens When You Send a Zero-Day to a Bank?
#236Earlier quoted context omitted.
I believe that you'd need to tell them that they were being recorded or you could get yourself into trouble. Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
Just because evidence was not lawfully obtained (ie. call recorded without other the other party's consent where that is requirement of state statute), doesn't necessarily mean that evidence can't be used to protect yourself against a more wide-ranging claim. The various precedents against the use of tainted evidence are mostly used in favor of a defendant and against the state. A $50 misdemeanor fine for unlawfully…
Re: What Happens When You Send a Zero-Day to a Bank?
#237Earlier quoted context omitted.
This is actually pretty close to how I personally define a "professional": A professional is someone whose work can only be judged by other professionals of the same domain. Obvious failure modes are exempted. Anyone can tell you about a bad bridge after it has failed. But it would take a bridge engineer to tell you that before it fails. https://news.ycombinator.com/item?id=8960822#8963307
Your definition would include tradesmen and craftworkers, then, who are not strictly professionals. Anyone can work in wood long enough to say "That wooden bridge looks like it'll hold X people," and not have any way of conveying how they came to that conclusion, because they didn't learn via a means of studying a specific body of work that can be measured and accredited. Without this distinction, many professions wo…
According to what definition?
> Anyone can work in wood long enough to say "That wooden bridge looks like it'll hold X people,"...
I severely doubt that, given the complexity of trussed bridge designs [0]. There's a lot more to it than how much weight a 4-by-4 can support.
> ... and not have any way of conveying how they came to that conclusion...
If you can't transfer knowledge in a way that other people can independently verify, you're working in magic. If such a transfer is possible, but simply not possible for a particular person because they lack the tools, then that's a professional failing. For some reason, this state seems acceptable to you when we're talking about physics and complex loads. But could you imagine a doctor describing the appendix as "that thing sticking out where the long thin squiggly bit meets the short thick squiggly bit"?
> Also, your definition includes itself as part of its own definition, which is a circular definition fallacy.
You can't just throw out "circular definition is fallacy" and dismiss the idea. That itself is a fallacy -- "argument from fallacy". [1]
Yes, I use the word "professional" twice, but that's not necessarily a circular definition and especially not necessarily a fallacy. First, the two "professionals" are not the same person. The first mention of "professional" is an individual, while the second mention is a group. What I did is tie membership of a group to a conditional ability which is dependent on the group itself.
However, I did cheat a little bit. Because what I did not define is the individual ability necessary to meet that conditional. Because, of course, that changes depending on what group of professionals we are discussing.
For backup, let's look at a definition of malpractice [2]:
> a dereliction of professional duty or a failure to exercise an ordinary degree of professional skill or learning by one (as a physician) rendering professional services which results in injury, loss, or damage
In other words, malpractice is a professional doing something which such a professional should not do... Because the mere fact of a person being a professional implies that they should know better.
It's this same logic that I am using: A professional is someone who acts in a professional capacity, and understands the practices of such profession, and thereby is capable of judging whether another person understands and acts in a professional capacity.
[0] https://en.wikipedia.org/wiki/Truss_bridge#Truss_types_used_...
Re: What Happens When You Send a Zero-Day to a Bank?
#238Earlier quoted context omitted.
Your statement is 100% incorrect. P.S. It might be of limited correctness, only in some states, in the USA. I'd suggest you don't talk people into signing perfectly valid contracts hoping for an unlikely loophole.
Care to explain why he's wrong, or are we to assume your expertise, random internet person?
There isn't a bright line rule.
Re: What Happens When You Send a Zero-Day to a Bank?
#239Earlier quoted context omitted.
Assume the expertise. A whole semester of university dedicated to contract law: Consumer contracts and B2B contracts in the national law, then the specifics when dealing with a party in another European country and internationally. You'll see what a contract needs to be valid during these courses. There is simply nothing about both parties requiring to gain something.
You should demand your tuition money back. http://www.nolo.com/legal-encyclopedia/consideration-every-c...
The point stands. Your link doesn't infirm what I said.
Re: What Happens When You Send a Zero-Day to a Bank?
#240Earlier quoted context omitted.
What incentive, besides good-boy points and experience/publicity/etc (for more funding), do researchers have to do this?
It's "broken window" community policing. The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community. It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visib…