Live data from Hacker News

What Happens When You Send a Zero-Day to a Bank?

privacylog.blogspot.com

431–440 of 454 posts

Re: What Happens When You Send a Zero-Day to a Bank?

#432
post #2

That's a lot of errors for one document.

I thought the author is non-native, considering TLD.

Native English speaker. Very jet-lagged. Posted from Doha airport and blogspot.com kept redirecting to that other domain. Thank you, I have made many corrections now.

Re: What Happens When You Send a Zero-Day to a Bank?

#434
post #223

Surely one acquisition and 9 years later this isn't still an open vulnerability… right? It'd be nice if the author discussed that.

I have closed my account and do not know the answer. Also, please if someone would be able to confirm in the affirmative in this or any other Penson site, then please start a new round of responsible disclosure.

Re: What Happens When You Send a Zero-Day to a Bank?

#435
post #223

Surely one acquisition and 9 years later this isn't still an open vulnerability… right? It'd be nice if the author discussed that.

Only briefly mentioned in the article:

> 2017 I have yet hear from FINRA that any action has been taken. I have yet to hear from ZECCO / TradeKing that the issue has been resolved.

Re: What Happens When You Send a Zero-Day to a Bank?

#436

Earlier quoted context omitted.

Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.

This is how FB & others track everyone on the web through ad frames, like buttons, etc.

Just FYI, I use the uBlock Origin extension for Chrome and I believe it solves all this for me.

Re: What Happens When You Send a Zero-Day to a Bank?

#438

this is a major bombshell. I'd hate to be those guys running zecco. The fact that they coerced an NDA to hide the millions of customer transactions that now have no way of proving were legitimate or not. I'm pretty sure the author wasn't the only guy looking for vulnerability. I'm pretty certain criminal minded folks would've already used it....with no way of finding out which are real or manipulated. Which further r…

Thanks for understanding. I was writing this up and wasn't sure anyone would really connect with the story or care about one line of code against a now non-existing broker. I'm so happy to hear this support.

Re: What Happens When You Send a Zero-Day to a Bank?

#439

In Finland, most online stores allow you to pay for your shopping directly using your online bank. The way it works is the online store calls the bank's e-payment API, which in turn lets the user authenticate using their normal online bank credentials and accept the payment. A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implem…

You have reached zugzwang in game theory parlance. The correct solution before this was to make an announcement: "Here is the announcement I have made disclosing the problem. It is in both our best interest that it get fixed before publication. I have irrevocably given it to a blind drop that will publish it on DATE. And I believe that is a reasonable DATE that you could fix the problem. Let's work together to fix th…

The thing about setting deadlines like that (blind drop or not) is that it's very easy to look at it as some form of extortion. "This guy has cyberweapons, and unless we do what he tells us, he's going to release them on DATE. Better call the lawyers."

Re: What Happens When You Send a Zero-Day to a Bank?

#440

Earlier quoted context omitted.

Also a big issue here, as with many software vulnerabilities, is that the people the public disclosure would actually damage are the users, not the company making the vulnerable software. The bank would only start losing money if the users (personal customers, business customers using their APIs) would notice the hack and start demanding their money back.

It would be very nice if your security disclosure report included a section about how you have provide good faith upfront notice to the vendor and that based on research and belief it would be negligent for the company to not fix the issue by X date. The wording you choose should be cognizant of your state's laws and the company's user agreement in such a way that the company is actually at risk if they ignore you. W…

Just to be clear, I haven't really disclosed anything publicly, not regarding the e-payment API issue or any other issues for that matter. The SlideShare from my comment references the e-payment API vulnerability but doesn't disclose any technical details. It's not possible to reproduce the attack based on the slides alone.
Post reply on HN