Earlier quoted context omitted.
Tell us what bank so we can avoid them.
I don't think it's HSBC, but they do similarly horrific stuff. Almost all banks have a truly terrible online service. I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).
What Happens When You Send a Zero-Day to a Bank?
361–370 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#362The NDA is not a valid contract because there is no consideration. For a contract to be valid each party has to gain something. This is why many contracts include a token consideration of $1. This one didn't, so it's invalid.
Consideration is a common law concept as far as I can tell. As someone unfamiliar with how it came to be: Why was consideration introduced? What's the rationale, the goal behind it?
Also, you have to ask why someone chose to sign a one-sided contract. Was it signed under duress? The court shouldn’t enforce that. Was it a gift? The court would rather not get involved with enforcing every casual promise!
Re: What Happens When You Send a Zero-Day to a Bank?
#363Earlier quoted context omitted.
Even if CERT doesn't do much actively, you've put the problem on record and can refer to that record when dealing with vendors. Most companies can ignore security vulnerability reports if they choose, but a bank cannot. They have an obligation to report the vulnerability to their auditors. It triggers certain Sarbanes-Oxley reporting requirements.[1] It's easier to fix the problem than deal with the problems of havin…
Sure banks can. Source: did software security for a number of banks. Big banks are chock full o' CSRFs, XSS, SSRFs, and SQLIs. They get found all the time. For every valid report they get, they get 3 that aren't valid. Nobody's hair achieves ignition over this stuff. There are two types of financial service organizations: the big banks, and random firms (like Zecco was, before Ally bought them). There's no point in c…
Hacker One doesn't have a program for BofA. You probably found this dummy (and slightly misleading) page: https://hackerone.com/bofa
Re: What Happens When You Send a Zero-Day to a Bank?
#364Earlier quoted context omitted.
There was a guy who got thrown in prison for bringing a vulnerability to the attention of AT&T. He was thrown in solitary confinement for over a year. Then his sentence got vacated. What did he do as soon as he was released from prison? He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRD…
This is brilliant. And if companies are going to be so resistant this is the obvious solution.
Re: What Happens When You Send a Zero-Day to a Bank?
#365Lots more information about disclosure:
* https://www.ee.oulu.fi/research/ouspg/Disclosure_tracking
* https://www.ntia.doc.gov/blog/2016/improving-cybersecurity-t...
* https://www.thegfce.com/initiatives/r/responsible-disclosure...
Re: What Happens When You Send a Zero-Day to a Bank?
#366Earlier quoted context omitted.
IANAL either but my understanding is that you can be prosecuted under U.S. law for poking around on servers in any unconventional way. The text of the CFAA forbids "unauthorized access" or "exceeding authorized access". I'll admit that viewing the source code and noticing this link would be a stretch, but I wouldn't necessarily expect it to be a slam dunk for the researcher, especially if he had assented to the site'…
"The text of the CFAA forbids "unauthorized access" or "exceeding authorized access"." BOOM! And they've been harsh on hackers for a long time. So, the vulnerability must not require violating access controls or system integrity to be safest. Hackers should be in the clear if it was simply noticing something in HTML/HTTP or whatever that indicated insecurity. An example might be a breakable cipher-suite or handling s…
Re: What Happens When You Send a Zero-Day to a Bank?
#367Re: What Happens When You Send a Zero-Day to a Bank?
#368Earlier quoted context omitted.
This is brilliant. And if companies are going to be so resistant this is the obvious solution.
Ha, true. And the hedge fund should make its trades public. "Sir, the vulnerabilties hedge fund just bought options on our stock.". "Fuck, which of our software is it?"
Re: What Happens When You Send a Zero-Day to a Bank?
#369I would have done the following:
1. Shut down my account. 2. Send the exploit to the company anonymously with a deadline to fix. 3. Upon deadline, post exploit and cc the company.
The inability to publish is a rub, but I think we need a cultural shift to drive back corporate idiocy and protect consumers.
Re: What Happens When You Send a Zero-Day to a Bank?
#370Earlier quoted context omitted.
This was fascinating. Can I read more somewhere?
https://en.wikipedia.org/wiki/Broken_windows_theory New York City based their increased focus on petty crimes on it. I don't think it is useful as the basis for a model of policing, though. In some ways, it is an embodiment of the slippery slope fallacy, where if security is not perfect, it's worthless, in the same sense that a roof with one leak in it is worthless, because that one leak becomes the beachhead for fur…
From the original article in 1982:
Consider a building with a few broken windows. If the windows are not repaired, the tendency is for vandals to break a few more windows. Eventually, they may even break into the building, and if it's unoccupied, perhaps become squatters or light fires inside.
Or consider a pavement. Some litter accumulates. Soon, more litter accumulates. Eventually, people even start leaving bags of refuse from take-out restaurants there or even break into cars.
Broken Windows, The Atlantic Monthly, March 1982
--
The way I would put it, based on my visits to my home town of Zagreb, Croatia:
Apathy is contagious.