You might want to consider fighting it, though. It seems that it was a decision done at a pretty low level, or even automatically. Chase, like most US big banks, are under constant scrutiny and hate bad PR. Write to their top HR, say you are submitting a formal request to <pick a four-letter financial oversight agency> and send a copy to your congressman. What do you have to lose?
Since it's a financial institution and the accounts were closed by the bank, I wouldn't be surprised if this dinged his credit report in some serious way.
Having Chase cut off five accounts involuntarily probably looks pretty bad to whatever "AI" is used to create the scores.
Wells is notoriously crooked. Bank of America was a primary player in structuring withdrawls to maximize overdraft fines on their customers.
Chase has its own problems, but it would add a lot of inconvenience to your life to eliminate it.
Those three big players have purchased the majority of other banks in the country, leaving a scattered few credit unions and smaller banks around, which will be extra inconvenient when you travel and they absolutely will not offer the same range of credit cards with good rewards programs.
You don't need to touch Wells, Chase, or BoA to have financial infra in the US, although you might be stuck with them if you have a mortgage, auto loan, or other lending they originated or service. My condolences in that case.
[1] https://www.fidelity.com/cash-management/fidelity-cash-manag...
[2] https://www.schwab.com/checking
[3] https://thepointsguy.com/guide/amex-membership-rewards-vs-ch...
[4] https://www.mycreditunion.gov/about-credit-unions/credit-uni...
https://www.usaa.com/inet/wc/why_choose_usaa_main (Control-F “Who can join”)
It is slightly less convenient, but much better for the country.
Examples:
* it's 2020 and my credit union doesn't have autopay for my credit card.
* someone stole my cards and made some unauthorized charges at an unattended parking lot -- they did it almost 40 times in a single day across 3 cards that I rotated between. Chase and Amex took a 5 minute phone call each. My credit union took more than ten hours of work to get my money back, including demanding that I go to a -- remember, unattended -- parking lot that was near a job I hadn't worked at in 6 months to try to get a refund.
The real answer is if you qualify for eg a chase sapphire reserve, you get excellent service and an excellent product.
The balance that I have found works good for me is that I keep liquid assets at credit unions and I will get a debit card from them, but try to avoid using it if at all possible. I also hold credit cards with the major banks (except Wells Fargo, which I refuse to bank with in any capacity). I make all purchases throughout the month on credit cards with the exception of things like mortgage, car payment, etc.. Obviously also paying those cards off each month. There are numerous advantages to using credit cards over debit cards that I won't get into here.
I have a variety of credit cards that use Chase, BofA, AMEX, and Capital One. I also have at least one of each of the three major card brands (Visa, Mastercard, Amex).
Then of course I have a couple investment accounts I use for holding long term assets.
I find that this balance is the best that you can come up with. My liquid assets (money I make from work for example) goes into my primary credit union account. I try to hold mortgage and car loans through the same credit union and those get paid directly from the checking account. I try to avoid any other line items on that account other than payments to pay off credit cards. Then day-to-day expenses (food, amazon, stuff from Target, etc) get paid with credit cards. This way no one has direct access to my liquid assets if a card number gets compromised. I also don't have to deal with the bad online banking experience of the credit unions because I don't really use them for much other than a selected number of major payments each month. Instead my general purchases are on well known credit cards that have really good apps (Like Chase for example) and online experiences and reward programs.
This balance is great. You build a good relationship with a credit union and you keep your primary liquid assets with them instead of the major banks. Credit Unions are particularly good when you want things like Mortgages, construction loans, lines of credit, or car loans. So you can use credit unions for these things and maintain a good relationship with them. But where the credit union is weak, you leverage the strength of the major banks for good credit cards, good rewards programs, good fraud detection, good apps, and so forth. But at the end of the day they don't actually hold any of your money.
Everything takes much longer and major hassles are far more frequent. They have automated little to none of their operations. They are so small that their tiny staff has never had to deal with your particular issue before, and doesn't know what to do about it.
The big banks, on the other hand, deal with other versions of your problem dozens to hundreds of times a day, and have evolved a very high degree of efficiency in handling your case.
It doesn't have to be an either/or proposition.
* I keep my savings, checking, and loan accounts at a local bank, which also issues a debit card.
* I have credit cards from Discover and BoA, so that I get big-bank services for them.
The bulk of my value as a customer is tied to my mortgage, so my local bank, and possibly Fannie Mae, holds onto those profits.
This stuff is just wonderful. No monthly fees. Can use a debit anywhere Mastercard is valid, even overseas.
> The problem is most credit unions suck.
This has not been my experience. Chase is miserable, but if you need a business account, credit unions can't help you there.
A lot of credit unions are members of the CO-OP program, which gives you access to more ATMs than any of the big banks (possibly more than all of the combined). At least for travel within the US, being part of that CO-OP credit union is much more convenient than BoA and their ilk.
I just checked: 50 BoA ATMs within 20 miles of me. Over 100 within the CO-OP network. This is in a decent sized metro area.
I just checked my small undergrad town: 3 in the city, and 2 in the adjacent city. BoA has only 1 - and only in the adjacent city.
In my experience, it's always been able to find a Co-Op ATM than a BoA one.
Others complained about poor services, web sites, etc. I suppose that can be true, but it isn't for mine. In fact, I had to ditch one of the national banks because it couldn't provide simple features that my local credit union does - stuff like limiting which of my checking accounts is tied to my ATM card - without limiting it in their online site. So if I tied my ATM card to only one account, then when I logged in to the account's site, it would not let me transfer money between the accounts that are not on the ATM (although it would let me view transactions, etc).
I've also used my debit card in other countries. It worked just like any other card would (I did have to inform them in advance so it wouldn't trip up fraud detection).
> and they absolutely will not offer the same range of credit cards with good rewards programs.
You do not need to have a bank account with Chase and other companies to get good credit cards with rewards programs.
The reward program through the credit union is not that great, but I'm okay with that.
Your comment would imply a huge gap between this top tier of 3 banks and the rest of FDIC banking; there are quite a large number of large banking institutions available which are not as small as you've positioned them. https://www.mx.com/moneysummit/biggest-banks-by-asset-size-u...
(there are similarly very large Credit Unions such as NavyFederal with lots of asset: https://www.mx.com/moneysummit/biggest-us-credit-unions-by-a... )
FWIW, Citigroup is almost as big as Wells Fargo.
You're probably thinking of employer-paid business travel, passing on "air miles" to an employer. It's 2020, my friend.
More seriously, is it possible to get in writing that disclosure would not result in negative repercussions if there is no bounty program? Perhaps dealing with large banks in a security context requires a less forgiving mentality.
Did you have to return the $5k? At least maybe you gained that?
The only compensation I received with this whole situation was the termination of my accounts, and a family members account being terminated as well.
It's very hard to know the reasoning behind the termination as they never gave me any information.
My gut agrees with this statement.
Technically, if a SAR was filed, even the engineer he spoke to would not have known. Every training I've ever taken in that field basically says you don't tell anyone but your company's team that you filed such a report. Not a coworker, not even a Manager.
I was extremely disappointed. :(
Thank you for sharing.
You would think out of all people a bank would have deep enough pockets to afford a proper bounty program, as well as treat researchers well.
And in practice, it's less than one bit, since not all characters are letters.
So yes, I absolutely expect them to be good at saying, "Well, if we pay $X this year for bugs, that's better than losing $Y directly and paying $Z in cleanup costs."
Sorry but trusting local cops with anything technical is a fools errand.
You want things on record in any way possible.
Just getting an emailed "okie dokie" back from some company executive and then doing something that could later be construed as illegal is a bad idea.
Maybe let's just agree to get a good lawyer first and follow their advice about who to talk to.
You're almost right. You have your attorney notify law enforcement. That's what he's for. He'll keep all the records and act as a buffer between you an any misunderstanding with the police.
Lawyers are paid to keep your best interests in mind.
Cops will investigate the shit out of you and will do nothing to help, at all.
Yes, he disclosed exactly how he did it to the bank. Yes, he returned it all. Yes, he had no intent to keep it. And yes, he still defrauded them in the process. Yes, he had permission to do so. But permission doesn't always prevent situations from going awry, even if it can help clear things up after the fact.
If you walk into a physical bank and notice a potential security issue, point out the potential security issue to the teller, come back to exploit that potential security issue just to see if you can, succeed and make off with $70k, then bring it all back in and walk the bank manager through how you robbed his bank, he's still going to call the cops on you. Or maybe you spoke to him before and got permission, but his communication to corporate after the fact gets misconstrued/misunderstood and someone else calls the cops.
Closing all of the accounts like they did was a crap reaction, but he could have just as easily been hand delivered an arrest warrant by an FBI agent for bank robbery and fraud if someone internally decided to take the position that what he did was analogous to the above scenario. And it may have just as easily occurred due to some internal miscommunication/misunderstanding by a non-technical person or being flagged by some type of automation/reporting, rather than deliberately taking such a stance.
That's where involving a lawyer would have been valuable. It may not have protected him from the consequences that did occur, since they could close his accounts for whatever reason they wanted. But a lawyer would have provided greater assurance against substantially worse outcomes, by ensuring more drastic outcomes were identified and addressed/mitigated upfront. And potentially saved his accounts from getting closed - the decrease in his cumulative credit limit plus closure of such long-lived credit cards translates into real economic harm due to the likely impact on his credit score. I could see a lawyer being able to use that fact somehow to persuade Chase that it was not in their best interests to take such an action.
Law enforcement - I'd leave that up to the lawyer. As another user commented, your lawyer is explicitly employed to protect your interests. If involving law enforcement furthers that aim, they'll tell you. If involving law enforcement is detrimental to that aim, they'll tell you. So consult with several first, hire one second, and let them direct what happens after. If what they do/recommend ends up being incredibly stupid, you at least have their malpractice insurance to appropriately compensate you for their stupidity. But you have no such insurance to compensate you for your own.
> Once I had permission quickly made a proof of concept ...
So unless you want to accuse him of lying, there's no fraud here. And the fact that Chase didn't file a police report makes me convinced there was nothing remotely illegal about his actions.
As I said, such a situation could have occurred due to a miscommunication/misunderstanding, rather than taking a deliberate stance to prosecute him. A team (or member on said team) or some automated system unaware of that permission could have flagged the fraud and involved the authorities. Communication silos are a fact of big businesses. Politics and power tripping executives are too, who may decide whoever gave such permission didn't have the authority and push ahead anyway for whatever reason. And inflexible legacy systems are too, which may trip some automated fraud detection system that automatically triggers a legal reaction.
The charges may have ultimately been dropped when everything got sorted out, or a judge could have dismissed the case based on the permission he was given (if the situation got to that point). But that's not for the law enforcement agent serving your warrant to decide, his job is just to bring you in. And in the event that happens, it's far better for your lawyer to already be prepared on how to address the situation than only getting them involved at that stage.
It seems like he took great pains to keep it legal, but the presence or absence of a police report means nothing.
No he didn't. Intent / mens rea matters.
He established a pretty solid record of prior communication about what his intent was.
Involving your lawyer isn't a foolproof preventative measure either. But your lawyer having an established line of communication with their lawyers can get things cleared up a whole helluva lot faster than if you get booked, have no lawyer, and are having to find and get one up to speed only after you're sitting in jail.
The entire experience with Chase while I was assisting them was very positive, and they even mentioned something about putting me on their upcoming researcher leaderboard.
Since chase is a very big organization I would have to assume that another department took over the situation after, and decided to terminate my accounts to avoid any risk.
I will never know for certain as they have been very close lipped about the whole event.
Local branch manager was frustrated but couldn't get any more information. The timing really made my life difficult for a few months, completely unnecessarily.
That was the last time I banked with Chase. A few colleagues told me they proactively left after also, due to the way it was handled - who knows if that was true.
I've got several Chase accounts myself, and glad to know they're not horribly hostile to such disclosures.
The original comment I replied to asked what difference it would have made in response to someone's "always involve a lawyer instead of trust these companies to do the right thing" post. Which is a generally good rule of thumb, as there's no guarantee someone else's experience would go as positively as yours did with Chase. So I wanted to point out a much more hostile outcome someone may feasibly experience in such a situation, to highlight the difference involving a lawyer could make.
So far as I know, fraud isn't a strict liability crime. It requires intention ("mens rea") as well as action ("actus rea") to be prosecuted.
I am of course not a lawyer.
But
1) Mens rea isn't an absolute defense. It doesn't refer to malicious intent, but more so specific intent[1], in this case, specifically performing a sequence of actions in order to discover/validate/confirm a vulnerability. You also don't have to know if what you're doing is a crime; if what you did fit the legal definition of fraud, and you performed that action fully cognizant of and in control of what you were doing, then it's still a crime irrespective of your awareness that it was a criminal act.
2) Mens rea is a legal argument. It may protect you from successful prosecution, but if you've hit this point, lawyers are already involved and you've more than likely already been arrested/charged.
3) The prosecutor could dismiss the case if they feel the likelihood of successful prosecution is minimal (such as when you produce the original permission you received) or the bank requests it. Or they could force a settlement if they think the case is shaky. Or they could be an ass and force the court/judge to decide. But you've still been arrested, your life has been disrupted, you've potentially sat in jail for some amount of time (at least until your bail hearing), and you've likely been economically harmed (via legal bills, cost of bail, potential impact to your state of employment, potential impairment to future earnings based purely on the arrest record even without prosecution, etc).
Which is why it's always good to involve or consult a lawyer before engaging with the company - the cost of doing so is effectively an insurance policy protecting you from ending up in a situation where you need to employ one for damage control. And you're likely to end up with a far larger bill if you end up having to pull a defense attorney in after the fact for damage control/crisis management than the bill you'd get for upfront risk mitigation.
I absolutely agree. Always have your own lawyer!
This story is exactly why the newer fintech startups will take over banking.
Most lawyers will give you an initial consultation for free. Even if you don't hire one, just consulting with one can immensely improve your ability and confidence in navigating things solo.
"Can you also confirm if this allows additional points to become available for use?"
This was why I had to remove the negative points, and make a transfer to prove that they indeed could be used.
[1] https://www.forbes.com/sites/advisor/2020/07/15/how-airlines...
The post doesn't actually confirm this. Might that be the problem?
But
- Shit happens. Even legitimately contracted pentesters can run into legal issues. These guys[2] worked for a firm hired by the state court system to pen-test the courts (from application testing to physical building security), were ultimately arrested due to a power play, railroaded by an embarressed local authorities, had their charges trumped up to the point of being considered a felony, were disavowed by the powers that hired them who went into "cover our ass" mode, and ultimately spend 5 months fighting the charges before the state legislature ultimately pressured the local authorities to drop them. And even with the charges dropped, the felony arrest record was not expunged and has lasting damage/implications both personally and professionally.
- In the above case, the client was not only the very same court/legal system overseeing their case, but also had an established, multi-year relationship with the security firm they worked for. Yet it still went that terribly wrong, took almost half a year to get legally resolved, and resulted in permanent felony arrest records. If things can go so terribly wrong for legitimately contracted professionals, how badly do you think it could go for a private citizen, with no official contract in place and only some form of written permission from the company that has not been vetted by a lawyer representing that individual's interests, and may not have even been vetted by that company's lawyers?
- He was dealing with a bank. Who are subject to a massive amount of legal and regulatory requirements for their customers that are specific for the banking industry, all of which tend to get interpreted/applied from a conservative standpoint due to the risks and penalties they're subject to for non-compliance.
- He was using his real, live accounts during the process. His actions could have easily triggered their fraud detection system to automatically generate and submit a SAR[3] due to "suspicious activity that might signal criminal activity* report for For example, it could have triggered. Even if someone fully aware of the situation (and granted permission) intercepted such a SAR before it was submitted, it may be decided that such actions from a private individual not contracted by the company to perform such work fit the threshold of "might signal" and still ultimately get submitted. Triggering who-knows-what downstream repercussions/investigations after it's submitted to the government.
- Their responsible disclosure program[4] did not exist at the time, so there were no explicitly documented and legally vetted acceptable rules of engagement publicly available. It's possible that rules of engagement were part of his communications with them, but not mentioned in the article (nor again, vetted by a lawyer bound to represent his interests).
So while there was ultimately no problem in this instance beyond the inconvenience of his accounts getting closed, doing so without the aid/guidance of legal counsel involved assuming an unknown and potentially substantial large amount of personal risk/liability in the process. Which is why it would be highly advisable for someone in a similar situation to speak to or retain a lawyer.
[1] https://news.ycombinator.com/item?id=24990202
[2] https://www.darkreading.com/vulnerabilities---threats/pen-te...
[3] https://www.occ.treas.gov/topics/supervision-and-examination...
[4] https://responsibledisclosure.jpmorganchase.com/hc/en-us
I'm interested in why do security researchers or bug hunters do this kind of work for free. It really devalues the proposition long term imo, but I don't have a horse in the race. My POV is megacorps with bottomless pockets and armies of highly paid engineers miss these critical security issues all the time, and the best reporters can hope is chump change (if not abuse).
edit: Even more specifically I'm wondering why can't the security community work together, denounce the current practice of exchanging bugs potentially worth $$$ for ~nerd cred? Make some high profile disclosure if that is what it takes to take the work seriously. Wouldn't it work out better in the long run?
They were one of the first companies to have solid mobile banking.