That's a lot of errors for one document.
What Happens When You Send a Zero-Day to a Bank?
431–440 of 454 posts
Re: What Happens When You Send a Zero-Day to a Bank?
#432Re: What Happens When You Send a Zero-Day to a Bank?
#433> October 2008 This may be a lot of it. In October 2008, a massive security breach affecting all accounts was maybe a solid #2 on their list of problems.
Re: What Happens When You Send a Zero-Day to a Bank?
#434Surely one acquisition and 9 years later this isn't still an open vulnerability… right? It'd be nice if the author discussed that.
Re: What Happens When You Send a Zero-Day to a Bank?
#435Surely one acquisition and 9 years later this isn't still an open vulnerability… right? It'd be nice if the author discussed that.
> 2017 I have yet hear from FINRA that any action has been taken. I have yet to hear from ZECCO / TradeKing that the issue has been resolved.
Re: What Happens When You Send a Zero-Day to a Bank?
#436Earlier quoted context omitted.
Images are loaded with the cookies of their own site. Example: go to google.com, then open the console and type the following: var i = document.createElement('img'); i.src= " http://news.ycombinator.com/y18.gif "; Then look at the cookies sent over the network.
This is how FB & others track everyone on the web through ad frames, like buttons, etc.
Re: What Happens When You Send a Zero-Day to a Bank?
#437What bank or financial firm has 100k branches? That's a HUGE presence.
I cannot verify that number but I am quoting it from a phone call with a Penson engineer.
Re: What Happens When You Send a Zero-Day to a Bank?
#438this is a major bombshell. I'd hate to be those guys running zecco. The fact that they coerced an NDA to hide the millions of customer transactions that now have no way of proving were legitimate or not. I'm pretty sure the author wasn't the only guy looking for vulnerability. I'm pretty certain criminal minded folks would've already used it....with no way of finding out which are real or manipulated. Which further r…
Re: What Happens When You Send a Zero-Day to a Bank?
#439In Finland, most online stores allow you to pay for your shopping directly using your online bank. The way it works is the online store calls the bank's e-payment API, which in turn lets the user authenticate using their normal online bank credentials and accept the payment. A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implem…
You have reached zugzwang in game theory parlance. The correct solution before this was to make an announcement: "Here is the announcement I have made disclosing the problem. It is in both our best interest that it get fixed before publication. I have irrevocably given it to a blind drop that will publish it on DATE. And I believe that is a reasonable DATE that you could fix the problem. Let's work together to fix th…
Re: What Happens When You Send a Zero-Day to a Bank?
#440Earlier quoted context omitted.
Also a big issue here, as with many software vulnerabilities, is that the people the public disclosure would actually damage are the users, not the company making the vulnerable software. The bank would only start losing money if the users (personal customers, business customers using their APIs) would notice the hack and start demanding their money back.
It would be very nice if your security disclosure report included a section about how you have provide good faith upfront notice to the vendor and that based on research and belief it would be negligent for the company to not fix the issue by X date. The wording you choose should be cognizant of your state's laws and the company's user agreement in such a way that the company is actually at risk if they ignore you. W…