3 ms·
Would he not have a case of gross negligence against Zecco if he were a customer? Is there something preventing a lawsuit, outside of the possibly non-binding N
by dvcc 9y ago
Would he not have a case of gross negligence against Zecco if he were a customer? Is there something preventing a lawsuit, outside of the possibly non-binding NDA?
- scott00 9y agoNo damages, assuming no unauthorized trades were executed in his account as a result of the unpatched vulnerability.
- idbehold 9y agoCouldn't he simply claim unauthorized trades were executed? How would the bank be able to prove otherwise? Especially considering the bank knew about this huge security hole.
- lr4444lr 9y agoYeah, but presumably he'd claim it on an asset in the red, and for a large enough amount of money to be worth risking lying about under oath. Zecco could have the court subpoena the ISP to prove the IP was in use at the time by the defendant.
- idbehold 9y agoOf course it was from his IP, the only way the transaction works is if your browser has the proper cookies. The whole vulerability is that all someone has to do is put that <img> into ANY webpage you visit and so long as your browser still had the cookies, the transaction would go though without you needing to do anything.
- lr4444lr 9y agoGood point. IANAL, but I would think burden of proof is still on the claimant that the transaction was fraudulent. If it had happened to multiple users around the same time frame who provably visited a similar set of potentially malicious websites, it might work, but then the company could respond that it's strange he conveniently didn't notice anything on the statements or confirmation of purchase e-mails until the exploit was publicized.
- PeterisP 9y agoIn order to do so, he would have to actually declare a claim that a particular trade was unauthorised. Assuming that he actually did execute all his trades himself (which, frankly, is quite likely), making that claim in court would be a crime (perjury + fraud), a much serious issue than the security vulnerability. With sufficient preparation it's likely, that the bank (and prosecutors) wouldn't be able to prove that crime beyond all reasonable doubt, and he wouldn't be convicted for it, but it still carries a risk that they could prove that (e.g. by forensic analysis of his computer) and he'd go to jail. Furthermore, even if he manages to prevail in the criminal case, in the civil case (where the criteria is less strict) it is quite likely that after reviewing all possible evidence they'll manage to get to the correct judgement that the "unauthorised trades" claim was false, thus not getting him anything anyway.
- idbehold 9y agoHow is the bank able to get to get the correct judgement in the civil case? There's proof the bank knew about the security hole, there is proof that at least one person outside of the employment of the bank had discovered this vulnerability (meaning there were likely more), and there is no way for the bank to prove that the transactions were legitimate. The article mentions that unauthorized transactions were indistinguishable from legit ones: > Also their engineers made it clear that unauthorized transactions like this and later shown below would not be distinguishable from other legitimate transactions.
- PeterisP 9y agoFor starters, all the details on how that particular transaction was performed, timestamps, IP addresses, all the browser fingerprints visible in the logs of that request (they tend to be quite identifying), subpoenaed logs from the claimant's ISP. They don't have to prove that it couldn't have been someone else, they have to convince the court that it's more likely than not. Motive matters a lot - if there's some way how that transaction would have been useful for a fraudster (i.e. if it was a money transfer to them), then it's one thing; but if there's no indication of why someone else would want to make the fraudulent trade (which is the case for most stock purchases/sells) and a clear motive why the claimant would want the trade to be reversed (i.e. the stock buy seemed good on that day but turned out to be bad afterwards) then if there's any technical evidence whatsoever pointing towards the claimant, it's hard to be convinced. If data shows that the transaction is e.g. done from some Starbucks and local security cameras show the claimant near that Starbucks at that time, it's probably not enough to get a conviction but likely enough to make them lose the civil claim. The criminal case would be expected to get much more evidence than an ordinary civil claim, so they'd likely wait for its results and use everything that the police/prosecutors gathered to dismiss their civil claim.