What Happens When You Send a Zero-Day to a Bank?
privacylog.blogspot.com
privacylog.blogspot.com
This is for cases where you want the credit but still want the protections afforded by being somewhat anonymous. Similar to WikiLeaks but more focused on allowing the company or entity to solve their problems and representing fairness on all sides.
The report isn't public yet, but it's on record. You've reported it to the organization funded by Homeland Security to take such reports. In 45 days, CERT will disclose it to the public.[2] CERT may contact the bank themselves. If you do, you can cite the CVE vulnerability number they give you. This gives you some advantages when talking to a bank. "Have your technical people contact Homeland Security's US-CERT at (888) 282-0870 regarding CVE-NNNN" will usually deal with a bank's people. They can't make the problem disappear.
[1] https://vulcoord.cert.org/VulReport/ [2] http://www.cert.org/vulnerability-analysis/vul-disclosure.cf...
Yes, reporting to CERT is "safe"; you almost certainly aren't going to get sued for doing it. But don't count on CERT coordinating a fix or even figuring out how to report flaws to. It's unlikely that anyone at CERT knows who "Zecco" is.
CERT themselves ask you not to submit to CERT unless your vulnerability fits some specific criteria. "Unresponsive vendor" is one of those, but CERT's fine print says that they prioritize severe, multi-vendor vulnerabilities.
Anyone who runs a bug bounty program can tell you how unrealistic it is to rely on CERT for this stuff: triaging reports for just one vendor is a full-time job. CERT wants to get early warnings of things like OS and platform vulnerabilities. I don't think it's a good idea to report those to CERT either, but regardless, CERT isn't set up to handle your CSRF report in some random website.
[1] https://www.a2q2.com/blog/sox/29-cyber-security-and-sox/
He went on CNBC to argue that independent security researchers should start a hedge fund that short sells the stocks of companies affected by vulnerabilities. https://youtu.be/jxUWRRDdhVI
He seems to be of the opinion that this would be a less risky strategy than bringing those issues to the attention of many companies. He also believes that profit incentives for researchers will serve the public interest, because it creates economic disincentives against big companies having insecure software.
There are examples of honest people getting fucked over, but this isn't one of them.
As it stands, literally everyone who would have been in a position to be reasonable was someone he'd actively worked at pissing off. Not in the sense of someone he'd pissed off in the past, but as someone he was actively pissing off in conjunction with this issue. The moral of his story is that there's room for aggressive incident reporting, but not if one is going to be an insufferable jerk about it.
That is hilarious.
This was introduced 3 days ago https://twitter.com/martenmickos/status/854321634404061185
HackerOne will work with friendly hackers on a best effort basis to verify the legitimacy of a vulnerability, reach out to and verify the identity of an individual at the affected organization, then share the vulnerability with the organization so it can be resolved.
Seems like it address most of the problems of educating the organization so they don't threaten you.
The more realistic concern here is that for these kinds of findings --- CSRFs in random web applications --- there simply isn't going to be a contact at the target company, and H1 isn't going to find one for you. That's why they point out they can't promise a contact.
I think the disclosure assistance is a pretty clever idea for generating new sales leads, since by definition they will be talking to companies with an actual zero day situation.
But any person looking at their homepage would be a lot less concerned. Impressive logo's and a clear story for an enterprise audience.
If other people feel the same way, I'll fork and make a repo. EFF is a great starting point but it is not nearly usable as a HOWTO.
I'm putting my balls on the line by publishing this blog post. Actually I started this blog 10 years ago just to make this page, here is the original page: https://privacylog.blogspot.com/2008/10/pre-announcement.htm...
WeWork leases offices; they have a shared workspace area in all the buildings, but most of their buildings are private offices.
Apart from the fact that there's a good chance the company you're trying to report to already has an H1 program running, what they're promising to do here is to spend some effort trying to track down security contacts for you. They profit from this, of course: if you give them a good bug, and they facilitate its reporting, the target company is very likely to sign up for H1. But it costs you nothing and might solve a problem for you.
(I'm ambivalent about H1 --- we run a couple H1 bounty programs that existed prior to us taking over security at our clients --- but I don't think it's a good idea to be dismissive of them.)
I wonder if an org like the EFF could add this to their scope.
https://twitter.com/Snowden/status/839168025517522944
Maybe if they were required by statute to accept anonymous submissions and make FOIA-style responsible disclosures after a reasonably short period of time, they wouldn't end up colluding right away.
The offensive organization wold probably then still sit on vulnerabilities only it knew about, but at least this would be better than the current situation.
Unlikely. They are still here to protect americans, in a sense. Stealing money from a bank or a regular business is not on their agenda.
There is a 10% of vulnerabilities that might have re-use for intelligence purpose, but it shall be alright for the bulk of it.
That may be the charter of the the organization. But the individual people running the FBI goals are to 1) be reappointed / not get fired 2) continually expand their budget / power. Given US politics 1&2 are not always congruent esp in short term with "protecting americans".
The EFF seems like a good choice. In general you would need to pick an organization that does not have a vested interest in using exploits.
> The National Security Agency is now able to share raw surveillance data with all 16 of the United States government's intelligence groups, including the Central Intelligence Agency, Federal Bureau of Investigation, Department of Homeland Security and Drug Enforcement Administration.
refs: https://www.engadget.com/2017/01/12/obama-expands-the-nsas-a... https://en.wikipedia.org/wiki/United_States_Intelligence_Com... http://www.reuters.com/article/us-dea-sod-idUSBRE97409R20130...
If you don't care about your reputation, you post anonymously. An anonymous full disclosure post is a good way to report a bug without dealing with drama about your "incentives".
The more unpatched vulnerabilities there are in existence, the more lucrative it is to be involved in any part of the computing crimes community.
It's like reglazing a broken window in your neighbor's garage at your own expense, because you don't want burglars to see it and start casing other properties in the same neighborhood based on the conditional probability that a visible broken window indicates a higher incidence of other exploitable vulnerabilities.
It's also important to pursue the very easily exploited vulnerabilities, because when you get rid of all the low-hanging fruit, the people who can't already climb the tree won't survive long enough to learn how. You're cutting a lot of bootstraps so that immature criminals can't pull themselves up by them.
Have you heard of Elizabeth Kubler-Ross's '5 stages of grief' model that summarizes people's typical responses to bereavement? EKR argued that people generally go through a cycle of denial, anger, bargaining, depression and acceptance. IME this is a good rule of thumb for how people typically handle any kind of unwelcome news.
In this case:
o There is no such problem
o Grr why did you hack us I'll call the police
o How about you take this pittance and STFU
o We're just trying to run a business and you ruined everything
o OK we'll fix it and alert our customersBut stipulate that there's some number here, and the answer is: because nobody in management at Zecco ever built a plan for how to handle incoming vulnerability reports, and so nobody who got the report was empowered to do anything but escalate the issue --- and halfheartedly, at that, because nobody in management at Zecco ever build a policy that ensures anyone cares about vulnerabilities, so this is for them the moral equivalent of a WONTFIX.
How diligently would you escalate a WONTFIX?
Escalation enough?
Large firms wouldn't survive at high enough rates to dominate public life as they do, if they weren't underwritten by the state at every turn.
You can use a lawyer for this, this is a standard piece of advice for other kinds of bounties-- e.g. reporting criminal tax evasion.
In a situation like this I'd probably directly ping taviso or someone else from the Google Project Zero team. Their contact information (email, G+, twitter (DM)) is not impossible to get at.
From there, I could get advice about next steps (the Project Zero team are going to know a few people) or maybe they could run with it themselves (depending on the bug; I don't know what the response would have been in this case).
Mind sharing how you've achieved this? I haven't had the same level of success, with my couple of attempts (thus far) to try to resolve various issues falling flat.
https://vulcoord.cert.org/VulReport/ http://www.zerodayinitiative.com/about/
/sarc
Come up with a good set of guiding principles for members. This would help avoid waiting 7 years and then sticking it online. Not criticising, I'm saying the situation here is pretty screwed up.
Members pay dues, the association provides backing. Company threatens to call the FBI and the association is the one they can deal with.
An organized group can help to provide the needed political pressure so that a properly disclosed vulnerability doesn't ever lead to the FBI and trumped up charges.
A respected group can lend credibility to a researcher. A bank may not give 2 shits about even a well respected member of the community. They will care if it's a group well known for finding and disclosing vulnerabilities.
This seems like an easier problem than the general case of software engineers because the community is smaller and you don't have the conflicting interests of "I can negotiate better on my own". Plus things like membership can be handled more easily, start with a small group of people who absolutely should be members. Extend via application and invite.
I'd like to work in an organization like this. I'm not sure if anyone would want to join. It seems like everyone else is either completely independent like my own IDJGAF strategy or they are full corporate like HackerOne and other brokers.
It's next door to the military intelligence folks.
(ba-da-bump)
[EDIT] I decided to log in today just to see if it's still there (was a couple days ago), and it's finally been patched. If I had used a throwaway I would gladly let you guys know the bank, but I won't since it's trivial to find out who I am from my handle.
Oh, new bank? Just assume it's your bank, and do whatever you would do next.
Hm, I recall the Comodo hack. I think it Comodo was hacked twice or more times that year. It won many rewards and continued leading the CA space. The market did not work apparently...
The other end are buyers. Most of them don't know what to expect for security or how to evaluate it. Most attempts to solve this failed. They've been conditioned to expect constant hacks, crashes, or data loss. So, they see Comodo etc get hacked and shrug. They'll usually stay if their end of whatever they bought works. The sector that will pay for highly reliable or secure software is probably under 1% of the market or projects. It's enough companies keep forming to do real thing but tiny, tiny few struggling to justify the extra costs or less features necessary for higher security.
Although I guess it could help align customer and business goals, since no one wants to lose money
http://www.pcworld.com/article/3155990/security/stock-tankin...
A company discovered vulnerabilities in some medical devices, then shorted the stock of the company before disclosing them.
I'm a happy user of N26. I very, very highly recommend it to all european customers. I'm never dealing with shitty bank service again. https://n26.com/ (Email me if you want a referral invite).
https://www.reddit.com/r/personalfinance/comments/66n4li/i_j...
My bank (arguably) condones use from public computers by asking me if they should "trust" the computer I'm on.
Or, you know, poor people.
"Sign this NDA or we will send the FBI to arrest you because you found that our banking website's security was completely fucking broken and told us about it." Jesus fucking christ.
The researcher is lucky that TradeKing believed their NDA trick was sufficient. Even if the case here is weak, and I wouldn't necessarily assume it is, it would still seriously damage the researcher's life.
Here's how it goes when you get sued by a big company. Their lawyers essentially have a heyday doing everything possible to obstruct and delay the process so that they can maximize their time on the corporate teat. It will go on for years; they won't mind because it's business as usual for them, and they're getting paid big bucks to torment you. Your life will be ruined: assets seized pre-emptively, reputation and credit destroyed, inordinate quantities of time consumed by legal research and tedious paperwork, struggling (if not immediately blatantly failing) to keep your incompetent counsel paid at $250/hr and meet the retainer, and eventually failing to file some document or pay some fee that will cause the court to enter a default judgment against you and permanently confiscate everything you own, leaving you with the albatross of a massive outstanding judgment waiting to be enforced, bank accounts garnished any time you get any money, etc. And that's the short version!
And then guess what -- if, by some miracle, you don't lose in the first round, this whole process will repeat as they file appeal after appeal. Hunker down because the proceedings will last at least 5 years.
The corporate lawyers will be able to justify all of it to their clients without blinking an eye, who probably forgot that they even asked them to sue you. Everyone at the company and the law firm will go home and sleep soundly on their piles of money, and you'll have learnt your lesson that trying to stop the subterfuge of an online trading platform is a terrible offense.
Good reading: http://www.nissan.com/Lawsuit/The_Story.php
IANAL.
IANAL though.
Otherwise, in court I'll be happy to defend myself. If it is necessary to spend time to defend yourself then that is a blessing. I have successfully sued the government (the US Army and Veterans affairs, no less) http://www.gao.gov/docket/B-413723.2 when they do things wrong. Just be persistent and be right. Then we came out with a nice settlement. Sorry GAO used to publish fulltext docket outcomes but I don't see it here.
Fuck Nissan. (Can we curse here on HN?) Because their cars suck and because of this case that I am well aware of. The sad thing is that Mr. Nissan spent so much money in defense. I should hope that he would be able to be more effective with less money.
Companies that run formal bug bounty programs (either directly or through a third party like HackerOne) show some recognition of this and some goodwill, especially those that include payouts of five figures or more, but those companies have to be careful that they don't accidentally create an environment where bidding wars between exploiters and companies are legitimized.
This contract might actually be egregious enough to warrant an unqualified declaration of invalidity, in which case you should go the other direction and overstate your case with conclusory statement and some word like "clearly" or "patently". "This contract is patently invalid!" and then explain why.
This isn't even an IP question!
A contract is what lets you sue someone over a private transaction. That's what it does, that's all it does. If for whatever reason you're not willing to bring a contract dispute to court, then your contract doesn't do anything and you wasted your time writing it. Contract = right to sue for breach of contract.
In order to sue someone, you need to be able to describe what damages have been done to you. The goal of a lawsuit is for the responsible party to 'make you whole,' i.e. pay you back an amount equal to the damages done to you.
In a contract dispute, the 'damages' of breaking the contract is equal to the 'consideration' of fulfilling the contract. In other words, the promised consideration is the actual thing that you can sue over.
If there is no consideration, then there are no potential damages, and there is no potential lawsuit. And since the only point of a contract is to enable a lawsuit, a contract that doesn't do that isn't a contract.
This is categorically incorrect.
Damages for breach of contract are supposed to put you back in the position you'd have been in had the contract been performed. It's not related to the value of the consideration.
Consideration is one of the things needed to make a contract binding in English law (along with offer & acceptance, and "intention to create legal relations").
Jurists still debate the rationale for consideration, but the best answer I've found is that contract in English law is seen as an exchange or a “bargain”. There is no gratuitous contract, donations are not contractual right.
By comparison, a contract under French law is based on "consent of the parties" and the theory of individual autonomy. There's no requirement for consideration.
In a "mutual NDA", consideration is easy to find; each party agrees not to disclose confidential information disclosed by the counterparty.
Another way to make an agreement binding without consideration is to sign it as a deed.
https://blogs.warwick.ac.uk/anneprudhomme/entry/consequences...
If I say, "I'm going to give you some apples in six months, after the harvest" and then there's a blight and I don't actually end up with any apples, society (at least in America) decided that I should be able to just say, "Oops, sorry, I'm not going to be able to give you those apples after all" and be done with it.
On the other hand, if I say, "I am going to sell you some apples in six months, in return for $100", American society collectively decided that I'm on the hook to get you those apples, regardless of whatever difficulties should ensue.
Also, you have to ask why someone chose to sign a one-sided contract. Was it signed under duress? The court shouldn’t enforce that. Was it a gift? The court would rather not get involved with enforcing every casual promise!
You, sir, have unfortunately failed that test.
Worth noting that just because it doesn't stand up as a contract doesn't necessarily mean a claim can't be made under breach of confidence (I doubt it would be applicable here, but just pointing out that contracts aren't the only form of legal protection provided to confidential information).
Definitely not. The bank did not disclose the vulnerability to him, he discovered it on his own. He had absolutely no obligation to the bank.
Yes, that is exactly right.
> doesn't seem like a gain
Why not? If you don't think that's a gain, why are you wasting your time doing the interview in the first place?
A chance for employment (over an outright dismissal) is a recognizable gain.
You are however, free to decline with the appropriate consequences.
I think it's totally fair to reject an NDA but I don't blame him for fearing an overzealous reaction on their part. Even being on the right side of criminal and civil law, you really do have to be willing to spend time and money to mount an affirmative defense.
Edit: looks like this could be possible without getting into trouble depending on the state you're in: http://lifehacker.com/5491190/is-it-legal-to-record-phone-ca...
A $50 misdemeanor fine for unlawfully recording a phone conversation, may well be a small price to pay - if the content of that recording can successfully protect you from a potentially bankrupting civil case.
And you always have the option of not disclosing the recording if that is your lawyer's recommended advice.
It bothers me a lot when services, such as Google Voice, announce to all parties that such recording is occurring.
Google is based in California. There is a good probability that the act of recording occurs there. California is an all-party consent state. Also, even if the recording isn't happening in California, it's potentially tricky to be sure that no party to the call is in California (even numbers assigned to landlines don't assure that the person ultimately connecting is in a particular place.)
It's completely legal to record a phone call in Canada as long as you are a party to that conversation. However I still cannot find an app for my Android phone to do this.
Second, those beeps probably exist to reinforce that the audio is unmolested. A beep every 5 seconds means you would have to cut audio in five-second increments, which is not likely to be convenient to whatever segment of audio you actually want to cut.
A few months back I did some research [1] on these e-payment APIs and noticed that one of the major banks had a serious flaw in their API implementation. It was possible for the end-user to manipulate the signed API calls to change the payment amount, effectively paying less than the actual price for products they buy.
I reported the issue to the bank and got a swift response where they acknowledged my report and said they were looking into it more closely. A few days later I got another email where they basically said "ok, this looks bad, and we can see it's pretty trivial to exploit, but... it's too expensive to fix, so we won't do anything".
I wasn't comfortable with this, so next I reported it to NCSC-FI/CERT-FI. They also agreed that it looked bad, but said that they had no way of forcing the bank to take action. So that got me nowhere either. I haven't heard from either NCSC-FI or the bank since, but the issue does appear to be partially mitigated now.
I've since found several other issues in the same bank's systems but haven't bothered to report them since they don't really seem to care.
[1] https://www.slideshare.net/JuhoNurminen/the-sorry-state-of-f...
I really take issue with the notion that security is important, so you're fully justified in screwing people and companies over as much as possible to prove a point. That seems to be a common attitude in the security community. I get the frustration people have with the intransigence of corporations and programmers, and people's general stubborn unwillingness to understand the severe impact of vulnerabilities, but if just security-shaming companies into fixing bugs actually worked we would have a much more secure internet today than we actually do. Unless you can get regulatory agencies to start holding companies and individuals legally accountable for security issues (that is, making it more expensive not to fix than to fix), nothing will change, even if you have all the technical solutions and social pressure in the world.
So no, publicly exposing an issue does not always work if there are no incentives for anyone to fix it.
The correct solution before this was to make an announcement:
"Here is the announcement I have made disclosing the problem. It is in both our best interest that it get fixed before publication. I have irrevocably given it to a blind drop that will publish it on DATE. And I believe that is a reasonable DATE that you could fix the problem. Let's work together to fix the problem."
What do you think about this type of approach? There is probably a name for it in Art of the Deal. (Whatever you think of the man, the book is worth reading.)
However if the FBI and NCFTA were /genuinely/ interested in disclosing this in their forum for other banks then maybe my phone call with them may have been a win-win. But I think they were not genuinely interested.
No bug bounty but oh well.
It doesn't matter how we regard CVEs as a community, this is the truth of the matter outside of it. We're handing them over a bomb, and they want to know why. It feels very Spy vs Spy to me, as silly as that sounds.
I tried reporting it to the credit card, and to the issuing bank, and to the FBI. The only thing I asked was that they cancel the credit card accounts and put a "potential fraud source" note on each customer's account. Each party I called was more concerned with threatening me, and trying to find out what kind of criminal angle I was playing, and what my ulterior motive was, etc etc. I honestly expected to hear "Oh dang, that sucks, we'll close the accounts and contact the victims", and was depressed at the hostility I encountered.
Why should we be strictly ethical in the face of behavior that is unethical? We deserve protection, too.
That's pretty much trying to shut down business with their customers. You don't see how they'd interpret that as hostile? Future actors would know how to apply similar techniques if the outcome was in their favor (e.g. Anonymous suddenly produces a large file of cc#'s and threatens bank!)
> The only thing I asked..
In fact, why were you making demands about how they handle their customer relationships, instead of simply presenting what you'd found?
That's not how credit cards work. You close that account, transfer the balance to a new card, and issue it to them in the mail. I've done it a half dozen times, and my CC company is only out for odds and ends like postage and stamping a new card.
> In fact, why were you making demands
I wrote "asked", and then you pasted that, and misquoted it as "demanded"? If you hadn't included my quote, I'd accuse you of dishonesty, but now it's just weird.
I asked them to proactively protect their customers, because my grandfather had been through hell after his identity was stolen, and I wanted to do my best to protect other people from the same.
https://jeremytunnell.com/2014/12/22/swab-password-policies-...
Password + token is a common pattern in systems where hardware/software/OTP tokens were bolted on after the fact.
Not just that, but on certain systems (think a Windows login screen, or a POP3/IMAP login for your e-mail client), you can't have a 3rd "token" field -- they're hardcoded to ask for just a username and password.
So vendors came up with the idea of appending the token value onto the password, and their middleware (say, a PAM module) splits the provided value into password and token and validates both.
EDIT: That's not to say that Schwab is doing it right (in the front-end, seriously???), but just pointing it it's not as uncommon as you think.
So have it with no encryption, and the back-end can pull the password and 2FA code apart and verify both of them, for all kinds of systems which have only a username/password prompt for logins.
I no longer hold any assets at Schwab, but I do poke around every now and then, and it's possible they changed things without me noticing.
Don't be so sure. If they didn't disclose this to their buyers they are guilty of fraud. The statute of limitations has probably run out (I don't know which state has jurisdiction here), but delayed discovery rules may apply.
If I were a betting man, I'd bet the buyer knew about the issue and basically didn't care.
This is negligent. If they are running banking ecommerce infrastructure and are unable to deal with 101 security risks then it is absolutely negligent. The "it is too complex for the average person" isn't an adequate defense.
The only thing is that there has to be someone who lost something of real value for it to go to court as negligence does it not?
Wouldn't the FTC want to know about this though, as this would be a great way to execute a pump-and-dump scam...
I would like to migrate to my own domain with Jekyll or something. But I would not look forward to implementing commenting and trackbacks even though the blog is pretty modest any way in terms of using those features.
What is he trying to say here? How on earth would it be possible to execute the url in the context of your zecco cookies unless it's openend in a (browser) in which you've logged into zecco?
The pre-fetching will use the user's context (and cookies) because it's executed by the user's web browser.
On a similar note, your web mail could fetch images in emails ahead of time, but that would still be out of your browser's context
*America
Terrible nonetheless. Reminds me of how Mt. Gox used to hand out password resets with plaintext passwords in the query string on their own forums.
Sounds like somebody should write a book about all of the missteps in that debacle.
It's like circumnavigating the globe backwards in order to avoid using a crosswalk.
I'm pretty sure the author wasn't the only guy looking for vulnerability. I'm pretty certain criminal minded folks would've already used it....with no way of finding out which are real or manipulated.
Which further raises the question, why they would go to extreme length to cover their tracks? They could've easily saved themselves trouble by coming clean but because they've gone such great length to hide it and threaten anyone who tries to expose it makes this a hollywood type story. That just seems so over the top like they are protecting something much bigger.
It's unlikely, but my point is it's a hole in their system which would allow this to happen and it seems like they've deliberately let it continue. :(
Motivation was clickbait and/or fear that people would not understand the latter.
BUT actually this vuln may have been from upstream with Penson. And then it may affect many broker-dealers. They have many clients in US and Canada. (Don't laugh that such a ridiculous vuln could be in so many places.)
At the time, considering this (and Penson was on the phone) I understood that irresponsible disclosure could have serious consequences. FBI would have been warranted to knock on my door.
That's why I'm now publishing 10 years after the fact.
Pardon my ignorance, but how would this work?
"But this only affects people that are logged in, right? Yes ..."
So I suppose what happens is, that the user is already logged into the service and thus has a cookie for the service in his browser.
If the user then somehow executes a request to the URL in the article with the same browser (eg viewing a malicous email with the IMG tag in a webmail client), the browser will enclose the cookie in the header of the request. This makes the request automatically authenticated.
The article mentions it would occur even without opening the email.
You could also abuse Firefox and Chrome prefetching links. I'm not sure Gmail for example remove prefetching attributes in spam links. They do block images though.
I am not saying no one has damages, but if 100s of people had damages, I expect something would have happened...
With sufficient preparation it's likely, that the bank (and prosecutors) wouldn't be able to prove that crime beyond all reasonable doubt, and he wouldn't be convicted for it, but it still carries a risk that they could prove that (e.g. by forensic analysis of his computer) and he'd go to jail.
Furthermore, even if he manages to prevail in the criminal case, in the civil case (where the criteria is less strict) it is quite likely that after reviewing all possible evidence they'll manage to get to the correct judgement that the "unauthorised trades" claim was false, thus not getting him anything anyway.
I would have done the following:
1. Shut down my account. 2. Send the exploit to the company anonymously with a deadline to fix. 3. Upon deadline, post exploit and cc the company.
The inability to publish is a rub, but I think we need a cultural shift to drive back corporate idiocy and protect consumers.
Of course you would. The bank would call the FBI and tell them you're hacking the bank, and the FBI would then knock down your door, tear up your house and drag you away. The system would then do everything it could to represent what you did as a crime, and if you are lucky you get away with only a year in court, many thousands in debt and your name dragged through the mud.
tl;dr The actual legality of an action is only tangentially related to how the legal system will be used against you in response to it.
I still hope this is not the case in most places outside the US - that is, I hope the responsible disclosure is complete proof you are in fact not hacking anyone.
Next time I would change 30 to a reasonable number. In this case (multiple vendors and a large installed base) maybe even 180 days may have been fair. And then I would stick to my guns.
But it seems the reason why these cases don't get resolved quickly is purely for economic reasons: the perceived cost of fixing the issue seems (to them) is far greater than the cost of dealing with the (remote?) possibility of the exploitation of the vulnerability.
I also think the security researchers have an 'overgrown' sense of the urgency upon having discovered such exploits, and it never seems to get fixed fast enough from their point of view.
But understanding the forces that are at play, also helps understanding such an 'irrational' decision. Big institutions are not known to be proactive and the political climate in such environments does not incentive the 'doers' but does get people in panic mode to try to stop the leak, instead of the root cause (the exploit).
FIRST, be reasonable. This is a good life axiom. Don't expect a large organization to confirm, engineer, test certify, and deploy a change that requires external documentation in less than 14 days. Even if the ship's on fire.
SECOND, be valuable. If you are reporting a vuln that is a bug report. When's the last time you got thanked for /any/ buy report for a non-GitHub project? If your report explains the cost and liability for lawsuit if they fail to fix your reported vuln then you are speaking their language.
---
I have a confirmed vuln reported to Apple under their "responsible disclosure" program since 2015. They have yet to fix it or provide credit as they promised. If you thought Apple was a magic company that "does the right thing", then I hope this dispels that myth.
Lots more information about disclosure:
* https://www.ee.oulu.fi/research/ouspg/Disclosure_tracking
* https://www.ntia.doc.gov/blog/2016/improving-cybersecurity-t...
* https://www.thegfce.com/initiatives/r/responsible-disclosure...
Now, in 2017, he flouts the NDA and acts in the public interest.
For example, if you'd stolen millions of credit cards in 1983 you'd have a special session of Congress dedicated to going after you, whereas now we (rightly) blame Target.
> 2017 I have yet hear from FINRA that any action has been taken. I have yet to hear from ZECCO / TradeKing that the issue has been resolved.
This may be a lot of it. In October 2008, a massive security breach affecting all accounts was maybe a solid #2 on their list of problems.
https://www.paloaltoonline.com/news/2017/04/20/pausd-student...
Imagine this conversation were the user to have discovered a parameter which let the user execute trades on behalf of another user.
For example, a realistic exploit would be to slowly buy up a bunch of a random penny stock; and then post an image link to some forum frequented by users of that software with the order "buy 10000 units of stock_x, okthxbye". The order will be executed by users viewing that forum and will bump up the price as you dump it.
The police rappel down the sides of your house in full gear and shoot your dog.
Or, per the article, the company pressures you to sign an NDA, and mentions "FBI" to instill fear of rappelling.
TLS1.2 and proper crypto schemes should be mandatory at this point.
https://cdn2.hubspot.net/hubfs/281302/Resources/Migrating_fr...
var i = document.createElement('img');
i.src= "http://news.ycombinator.com/y18.gif";
Then look at the cookies sent over the network.
var i = document.createElement('img');
i.src= "https://news.ycombinator.com/y18.gif";
document.body.insertBefore(i, document.body.firstChild);
The image appeared in the upper left of the Google home page.So, I clicked over to the Network tab and viewed the headers. The request headers do not include any cookies. If Hacker News were a broker using GET requests to buy shares, and the image URL was such a request, HN would not have known whose account to buy the shares for, even though I'm logged in in another tab.
So, presumably, the hack does not work in Chrome 57.
Edit: Never mind. It's because I have third-party cookies blocked. If I unblock third-party cookies, my HN cookie does get sent.
in chrome
Is that a common element of an NDA's term?
I cannot verify that number but I am quoting it from a phone call with a Penson engineer.
Heh.