19 ms·
Disclosure: Unlimited Chase Ultimate Rewards Points
- ic4l 6y agoDue to fear of retaliation I decided initially not to share this story, but enough time has passed, and I feel the security community should know how one of the largest banks treats security researchers.
- irjustin 6y agoThanks for sharing and sorry such a shitty action was the result. More seriously, is it possible to get in writing that disclosure would not result in negative repercussions if there is no bounty program? Perhaps dealing with large banks in a security context requires a less forgiving mentality. Did you have to return the $5k? At least maybe you gained that?
- ic4l 6y agoI gave them a detailed report of everything, and the $5,000 USD, and the remaining 4,500,000 rewards points were returned. The only compensation I received with this whole situation was the termination of my accounts, and a family members account being terminated as well. It's very hard to know the reasoning behind the termination as they never gave me any information.
- nullc 6y agoAs I was reading your story and got the the part where they said they didn't have a bounty -- for some reason I anticipated that the next line would be them telling you that you could keep the $5,000. I was extremely disappointed. :( Thank you for sharing.
- ic4l 6y agoEven their newly developed responsible disclosure program doesn't have bounties. You would think out of all people a bank would have deep enough pockets to afford a proper bounty program, as well as treat researchers well.
- pnutjam 6y agoWhat? That's their bread and butter. You wouldn't expect a pizza place to give away pizza....
- whatl3y 6y agoUhh, I would expect them to do exactly that for someone who presented them valid proof and and an MVP for how someone could get away with stealing tens, hundreds, thousands? of pizzas undetected. Rewarding someone for helping them with their “bread and butter” is how I would expect to be compensated for helping.
- ic4l 6y agoOr maybe just be allowed to return to the pizza shop in the future, and keep ordering pizzas.
- wpietri 6y agoThe core skill of bankers is trading money and risk. They lend you money based on one risk calculation. They put aside more money against default if your loan gets riskier. They set budgets for whole departments of people based on how much they help mitigate risk. So yes, I absolutely expect them to be good at saying, "Well, if we pay $X this year for bugs, that's better than losing $Y directly and paying $Z in cleanup costs."
- pnutjam 6y agosarcasm seems to be unnoticed...
- bonestamp2 6y agoI suspect they know they have a lot of vulnerabilities and they don't want to encourage people to poke around. I mean, their passwords aren't even case sensitive. This is also probably why they fired you as a customer, to discourage anyone else from even trying.
- etothepii 6y agoThis sounds like the closure was due to Anti Money Laundering. I suspect this sort of activity triggers the banks AML procedures and it's standard operating procedure (sometimes mandated by law) that you can't disclose if an account was closed due to AML breaches. Obviously agree that you weren't money laundering but that's what this closure sounds like.
- gpapilion 6y agoSame thought, and I don’t think they get a lot of choices of this is triggered.
- csharptwdec19 6y agoYou don't. My gut agrees with this statement. Technically, if a SAR was filed, even the engineer he spoke to would not have known. Every training I've ever taken in that field basically says you don't tell anyone but your company's team that you filed such a report. Not a coworker, not even a Manager.
- ic4l 6y agoThis could be possible as well, because they never gave me any information.
- nijave 6y agoI would think some regulators may be interested in this
- baggachipz 6y agoAre there even still any regulators? Sarcastic yet honest question.
- nijave 6y agoJPMorgan Chase is an international company with a massive portfolio of products so there are quite a lot regulators floating around. Even outside Chase Ultimate Rewards, I imagine someone, somewhere would be concerned with their vulnerability disclosure process/practices.
- a_imho 6y agoWhy did you report it in the first place? What did you expect to happen? Let's say they did not terminate your accounts but sent a thank you letter, would that be satisfactory? I'm interested in why do security researchers or bug hunters do this kind of work for free. It really devalues the proposition long term imo, but I don't have a horse in the race. My POV is megacorps with bottomless pockets and armies of highly paid engineers miss these critical security issues all the time, and the best reporters can hope is chump change (if not abuse). edit: Even more specifically I'm wondering why can't the security community work together, denounce the current practice of exchanging bugs potentially worth $$$ for ~nerd cred? Make some high profile disclosure if that is what it takes to take the work seriously. Wouldn't it work out better in the long run?
- tyingq 6y agoMight be an interesting add to a resume/cv for a security related job.
- ic4l 6y agoThis was the original reason why I wanted to report it, also the fact that I really liked chase at the time. They were one of the first companies to have solid mobile banking.
- nfRfqX5n 6y agothink you would get popped for wire fraud if they caught on to it
- crusso 6y agoAlways involve an attorney and possibly law enforcement rather than trusting that these companies will do the right thing.
- riskable 6y agoDon't involve law enforcement unless you absolutely have to. The first thing they'll do is investigate TF out of you and your friends/family and they absolutely cannot be trusted to "do the right thing" or especially not to protect you in any way. They are not your friend.
- mtnGoat 6y ago100% this! Sorry but trusting local cops with anything technical is a fools errand.
- mxskelly 6y agoDon't talk to the cops about anything, ever. Especially not this. Lawyers are paid to keep your best interests in mind. Cops will investigate the shit out of you and will do nothing to help, at all.
- dls2016 6y agoCops protect capital.
- criddell 6y agoWhat difference would it have made in this case?
- cosmie 6y agoSuperficially speaking, he defrauded a US bank of $70k ($5k of which he transferred to his bank account). Yes, he disclosed exactly how he did it to the bank. Yes, he returned it all. Yes, he had no intent to keep it. And yes, he still defrauded them in the process. Yes, he had permission to do so. But permission doesn't always prevent situations from going awry, even if it can help clear things up after the fact. If you walk into a physical bank and notice a potential security issue, point out the potential security issue to the teller, come back to exploit that potential security issue just to see if you can, succeed and make off with $70k, then bring it all back in and walk the bank manager through how you robbed his bank, he's still going to call the cops on you. Or maybe you spoke to him before and got permission, but his communication to corporate after the fact gets misconstrued/misunderstood and someone else calls the cops. Closing all of the accounts like they did was a crap reaction, but he could have just as easily been hand delivered an arrest warrant by an FBI agent for bank robbery and fraud if someone internally decided to take the position that what he did was analogous to the above scenario. And it may have just as easily occurred due to some internal miscommunication/misunderstanding by a non-technical person or being flagged by some type of automation/reporting, rather than deliberately taking such a stance. That's where involving a lawyer would have been valuable. It may not have protected him from the consequences that did occur, since they could close his accounts for whatever reason they wanted. But a lawyer would have provided greater assurance against substantially worse outcomes, by ensuring more drastic outcomes were identified and addressed/mitigated upfront. And potentially saved his accounts from getting closed - the decrease in his cumulative credit limit plus closure of such long-lived credit cards translates into real economic harm due to the likely impact on his credit score. I could see a lawyer being able to use that fact somehow to persuade Chase that it was not in their best interests to take such an action. Law enforcement - I'd leave that up to the lawyer. As another user commented, your lawyer is explicitly employed to protect your interests. If involving law enforcement furthers that aim, they'll tell you. If involving law enforcement is detrimental to that aim, they'll tell you. So consult with several first, hire one second, and let them direct what happens after. If what they do/recommend ends up being incredibly stupid, you at least have their malpractice insurance to appropriately compensate you for their stupidity. But you have no such insurance to compensate you for your own.
- ptero 6y agoSince they effectively banned you from Chase service, what other retaliations were you worried about? Honest question. You might want to consider fighting it, though. It seems that it was a decision done at a pretty low level, or even automatically. Chase, like most US big banks, are under constant scrutiny and hate bad PR. Write to their top HR, say you are submitting a formal request to <pick a four-letter financial oversight agency> and send a copy to your congressman. What do you have to lose?
- abfan1127 6y agoserious question, why would you want to continue banking at a place that does this?
- popctrl1 6y agoRight? Sounds like they did him a favor. I had to jump through all kinds of loops to close my Chase account
- awakeasleep 6y agoIn the USA the three main banks are Chase, Wells, and Bank of America. Wells is notoriously crooked. Bank of America was a primary player in structuring withdrawls to maximize overdraft fines on their customers. Chase has its own problems, but it would add a lot of inconvenience to your life to eliminate it. Those three big players have purchased the majority of other banks in the country, leaving a scattered few credit unions and smaller banks around, which will be extra inconvenient when you travel and they absolutely will not offer the same range of credit cards with good rewards programs.
- seretogis 6y agoWe don't need to rely on profit-driven banks while credit unions exist. I'd really recommend that anyone and everyone switch to their local credit union to deprive these awful banks of their money. It is slightly less convenient, but much better for the country.
- rbarnes01 6y agoPlease, submit a complaint to the CFPB. I promise you that the bank will flip over backwards to resolve your issue.
- greyhair 6y agoThe CFPB has been declawed by the current administration.
- lukeramsden 6y agoI wonder if legal obligations surrounding responsible disclosure and treatment of security researchers should be brought in. GDPR-sized fines for treatment like this, as well as negligence in fixing reported vulnerabilities, could go a long way to improving the lives of security researchers wrt security of their livelihood, and improve the security of the digital world for all of us.
- Schiendelman 6y agoWe need to pass laws that forbid retaliation against disclosure, and require bounty programs. It might even make sense to have disclosure go through a public agency to arbitrate, and bond companies to that agency, much like we do with contractors.
- ic4l 6y agoI agree, especially with risky parties like banks, or government institutions. It's always a scary experience. The funny thing is according to them I was the only contributor from 2016 to the end of 2017. So they must not get many reports. Since then they did develop a disclosure program, but it would be great to hear from anyone else that reported things to them after the end of 2017.
- tyingq 6y ago"The funny thing is according to them I was the only contributor from 2016 to the end of 2017. So they must not get many reports." Probably because there's no obvious way to submit one.
- ic4l 6y agoThey had one a few months after https://responsibledisclosure.jpmorganchase.com/hc/en-us https://responsibledisclosure.jpmorganchase.com/hc/en-us
- Defenestresque 6y ago>All attack payload data must use professional language Huh.
- aidenn0 6y agoThey probably want to check PoC into their repository and banks take a very dim view on unprofessional language in the DB. I would only be slightly surprised had the terms included: "All code must be written while wearing professional attire"
- FriendlyNormie 6y agoBankster bootlicker. You could have made yourself a millionaire with this and instead chose to suck bankster dick and ruin your own life at the same time. You are astonishingly retarded. Good job scoring points for the bad guys and doing it for free. People like you deserve death.
- wdb 6y agoFunny that they are always quick to close your accounts and credit cards but if it's about mortgages/loans they leave those open. If they write you off as a client for accounts/credit cards, why not also for the mortgage/loans?
- colejohnson66 6y agoBigger write off amount for a mortgage (possibly a million plus) vs credit cards (most likely a few thousand)
- flerchin 6y agoYou would still owe on the credit card.
- ic4l 6y agoI'm sure they would send a Debt Collector after me if I had any balances on my credit cards. Back when this originally happened they gave me 60 days for the credit cards, and 30 days for the checking/savings account.
- joshjje 6y agoOuch, that's rough. Did that impact your credit score a lot?
- refurb 6y agoI'm guessing because they sell off the mortgages and loans they originate? So they are only acting as a processor and there are no other processors to send you to (or it would be a massive hassle to do it).
- 0xffff2 6y agoI'm pretty sure they do not. I'm currently working on a refi for my house and I considered Chase solely because I already have one account with them and it would simplify things if my mortgage was there too. I asked and was told that they do not sell their loans.
- tyingq 6y agoWow. You did the best you could to let them know about the problem, returned the $5k, etc. And they chose to be arseholes and just close your accounts and pretend you don't exist. This will have some amount of Streisand effect. I doubt they've really fixed the race conditions. And, the story itself is interesting enough to take off.
- okl 6y agoYes, IMO OP should have disclosed it to the SEC right after Thomas confirmed that closing the account was intentional.
- ic4l 6y agoThey said it was intentional but did not state why, and said that they could not tell me why. From what I understand they can close your accounts for any reason.
- hedora 6y agoThey probably claim that, but it’s not true. For one thing, they have to worry about discriminating against protected classes of people. Of course, in the US, it’s essentially impossible to get your case to be tried in a fair court.
- ceejayoz 6y agoWhy the SEC? The CFPB or the FDIC are far more likely to have jurisdiction here.
- exabrial 6y agoRemember Chase is the bank where your passwords couldn't contain special characters and were limited to 12 characters up until 2017-2018 (I lost track, don't quote me). I wouldn't hold my money there if they paid me.
- rickyc091 6y agoPasswords weren't limited to 12 chars, but you are correct that they didn't allow special chars for a while.
- exabrial 6y agoLike I said I can't remember :) There was a max length I kept running into though. I believe also the passwords were case-insensitive.
- kevindong 6y agoAt one point, my main bank (Charles Schwab) limited passwords to 6-8 characters (inclusive). You could type more if you wanted, but it would get truncated down to 8 characters. https://arstechnica.com/information-technology/2013/04/why-your-password-cant-have-symbols-or-be-longer-than-16-characters/#:~:text=The%20brokerage%20and%20banking%20company,sit%20well%20with%20some%20customers https://arstechnica.com/information-technology/2013/04/why-y....
- milksteak42 6y agoThat's nothing. One of the largest banks in North America (BMO), limited passwords to 6 characters. Worse, for compatibility with telephone banking the characters were mapped to digits. That means there were only 1,000,000 possible unique passwords! They have 12,000,000 customers! They only just changed to complex passwords this year.
- parthdesai 6y agoTD would ignore casing in your password till 2 years ago
- phantom_oracle 6y agoOne would think that banks, who are the prime target for every person that "wants to hack", would be leading the way in terms of bug bounty programs and benefiting from smart people finding gaping holes in their systems. This bank could have gotten into serious trouble with regulators if a bad actor exploited this bug and stole millions. Don't expect them to adjust their behavior any time soon, but the "HN effect" might make them undo this action to avoid bad PR and make a few vague promises about "fixing the issue to avoid it happening in the future".
- trevyn 6y agoI think banks have much bigger concerns when it comes to regulators.
- chairmanwow1 6y agoCan someone please explain to me why companies make decisions like this? I have been on HN long enough to see many stories like this, but never once hear the suggestion of a rational line of human behavior. Is it lawyers misunderstanding the value of security research?
- lukeramsden 6y ago> Is it lawyers misunderstanding the value of security research? I would've thought it would be more likely some middle manager who doesn't understand tech and just knows this person was ""abusing"" their system.
- ceejayoz 6y ago"Someone closed an account with a balance of -5M reward points" might automatically trigger this. Plenty of account closures happen without a human ever seeing it.
- ic4l 6y agoThis termination did not happen instantly. The account was brought back to normal well before the termination of all of our accounts. I also expected them to have automatic triggers, but at the time they did not.
- ThePadawan 6y agoOP confirmed that his (allegedly human) contacts at Chase were aware of the closure, and chose not to comment. I would generally also suggest incompetence above malice, but above fact makes that very hard.
- closeparen 6y agoIt would be a federal crime to mention the words "money laundering," let alone specific tells, to the owner of an account suspected of money laundering. Chase policy probably applies this gag rule to any account being closed by Chase rather than splitting hairs about AML vs. other reasons.
- gjs278 6y agoi figured out that first midwest bank used to let me transfer money from a shared parent account to my own account. the money was mine, I was just supposed to get their permission first. if I tried to transfer money between the accounts at the bank in person they would stop me. I just edited the html of the transfer form and it went through without checking. I never bothered telling that or trying an account number that wasn’t mine though. they use a different system now.
- superfunny 6y agoThis story will hurt the bank's ability to hire talented programmers and developers in the future.
- CKN23-ARIN 6y agoWhich will, in turn, result in a higher likelihood of similar bugs in the future.
- ARandomerDude 6y agoIt was 4 years ago and Chase has very deep pockets. They could hire talent this morning if they wanted to.
- mrfox321 6y agoLike they want to pay competitive salaries to devs... Banks lose talent because they view tech as cost centers.
- user5994461 6y agoBanks are like the second employer of tech right behind web companies. They can be quite competitive, though usually more on the investment/market side than the retail side.
- nunez 6y agoI can assure you that it won't.
- mint2 6y agoA recruiter reached out to me and I was already leaning towards not replying because banks seem terrible tech environments. I’m not replying.
- spopejoy 6y agoIt won't, but don't worry -- megabanks can't hire anybody good anymore now that FANG pays the big bucks. Yes, they've got deep pockets, but they are bean counters and notoriously cheap -- startups and tech cos are way, way better about everything from decent coffee to healthcare benefits. They're buried in deep strata of horrible legacy tech, they have huge middle-manager bureaucracies and politics, ridiculous and ineffective security that slows IT processes to a crawl, and the whole thing bleeds money to maintain -- so in the end they are kind of tech-hostile and will do anything to keep programmer salaries down, avoid promotions, etc.
- dhanvantharim1 6y agoI dont think this behaviour is reserved only to banks. I once worked for a tech company which treated a security researcher who found a vulnerability with the same hostility, They had an "easter" egg in the code saying "F* you <name of the researcher>". Needless to say I left that place soon after this incident. It baffles me why companies wont reward these people for doing the testing for them instead of taking these disclosures as act of war against them.
- ashtonian 6y agoHope you cited that incident as part of your reason leaving.
- dhanvantharim1 6y agoYes, but I don't think that would have made any difference.
- rhexs 6y agoInteresting that the bounty program is only mentioned in the text screenshot and not the article. While it’s unfortunate that this happened, randomly pen-testing a bank then presumably asking for money is not something I would advise.
- ashtonian 6y agoHe talked to support first, they didn't have a bounty program until a year+ after the incident.
- royroyroys 6y agoWould this kind of attitude by an organisation incentivise malicious/nefarious activities? Is it because if actual funds are stolen they'd be covered by insurance and could leverage law enforcement, but open security research may just cause extra internal costs?
- mkoryak 6y agoabout 5 years ago I took my infant son for a morning stroll and found an SSD drive laying in the grass next to a busy street (jamaicaway in JP). I picked it up and later looked to see what was on it because I wanted to know why someone would throw out a perfectly good SSD (they were still expensive back then). Long story short, I found a bunch of mdb files with personal information about people's ambulance rides. I reached out to EMS and they were very nice and took the drive back with them. A few weeks later I got a scary lawyer email asking me to submit all my computers for a search because I hacked their security to get the data. It eventually turned out OK, but the moral of the story is that I will never again do the right thing if I happen to discover a problem that makes a large entity look bad.
- ciabattabread 6y agoThat’s why you launder the information via a news organization. In 2008, in London, a commuter found top secret counterterrorism documents on the train. That person was smart enough to go to a BBC reporter.
- pluies 6y agoNote that in the EU this would be a pretty bad violation of GDPR, so going to your local branch of government responsible for GDPR enforcement (e.g. the Information Commissioner's Office[1] in the UK) would be another good avenue. [1] https://ico.org.uk/ https://ico.org.uk/
- wil421 6y agoDoing the right thing in these situations is like playing with fire. Lots of times nothing happens but you can easily get burned hard. Legal expense to defend yourself are no joke. I heard a similar story years ago about a high school student finding an SD card. It was full of illegal underage pictures so he turned it into the school admins, told the story, and ended up getting charged for it.
- outworlder 6y ago> I got a scary lawyer email asking me to submit all my computers for a search because I hacked their security to get the data. Did you actually have to do that?
- jakobdabo 6y agoThis is why the so called responsible disclosure isn't a silver bullet. I believe, in cases when there is no bounty program and no substantial risk for the users' data or resources, one should go with full, anonymous disclosure.
- ic4l 6y agoThis is very hard because the actual research required you to use real accounts, and you would need to contact them to correct your account after you proved it was indeed an issue.
- 0goel0 6y agoGood timing. I just ended my moving from Chase to Ally as my main bank account.
- MetalGuru 6y agoWhy do security researchers keep being nice to these companies when said companies mistake good intentions with malicious ones and treat the security researchers like shit?
- b0afc375b5 6y agoFool me once, shame on you. Fool me twice...
- schoolornot 6y agoWhy do security people feel compelled to pen test sites without a contract or formal engagement? Such a super simple lesson to be learned. If you are not approached, leave it alone. If you offer your services and they aren't accepted, leave it alone. Just because I keep my front door unlocked it doesn't mean you can walk in nor does it mean you can break the glass on my back one. Leave it alone. And thinking that some community rep on the frontlines of a Twitter account can give permission to run a security exercise is totally asinine.
- jolmg 6y ago> Why do security people feel compelled to pen test sites without a contract or formal engagement? They didn't in this case. Though, maybe you could argue that the engagement wasn't formal enough. They found the initial hint of the bug from normal use, and requested permission before doing the actual pen test. Regarding the analogy, this isn't some random house they wanted to test. It's an essential service they used and depended on. Perhaps your analogy can be improved by them being an apartment building resident interested in the security issues of the building as a whole, since it affects the security of their own apartment. Even then, it doesn't seem like a perfect analogy that accurately reflects the situation. In the analogy, you could argue that they should change buildings if they're concerned, but banking options seem way more limited in comparison.
- Communitivity 6y agoYou had the best of intentions, and tried to do everything right. Unfortunately, in modern times that just paints a bigger target on your back. This is why I got out of cybersecurity. Even when you are a good guy, the other folks look at you like it's only a matter of time before you steal the crown jewels while their back is turned. And if you are disclosing vulns you found when not actually hired to do so, forget about it - the best you can hope for is a thank you and a bounty that doesn't make it worth the time it took. The sky's the limit on the worst you can get. The prospects of folks probing systems for the fun of it and disclosing how to secure them better to the owners in order to make the world a better place have become too grim. If you really want to do this, then I recommend you join a security company and do it as an employee to get that protection. Every decade since 1989 I have marveled at how much closer our world has gotten to the world of Shadowrun. I just wish we had gotten the magic to go with the pall of shadows that hang over us now.
- czbond 6y agoI agree with you. My view now when approaching all (and similar) situations in life - is "Can someone with mild to average intelligence interpret this negatively against me and act upon that perception?" Because let's be honest, that is Occam's razor most probabilistic outcomes.
- jjoonathan 6y ago100%. Joe Bureaucrat doesn't give one whit about race conditions in his employer's business logic. He has no reason to. If he can creatively interpret the situation as himself catching a hacker (the hacker being the researcher submitting the report)? That's prime. He can brag about it to the end of his days and monetize it at promotion time.
- czbond 6y agoI love the application of phrasing of "race conditions" to one's logic; I had never thought of that concept. And your deduction on the outcome is very likely!
- offtop5 6y agoVery very strange that instead of getting written approval from their counsel you just did it. This is the type of thing to test in a QA environment, not in real life with your real money.
- mtnGoat 6y agoAnd this is why I've never notified anyone about any security issues I find, better to laugh and move on. Twenty years ago or so, I offered help to parties and every one of them accused me of causing the problem or otherwise being malicious. Let them find their own problems, I'll focus on my own. A major US retailer used to have their entire OMS/back-office on an ip, it was that way for years despite multiple reports. And then they got ravaged when the first bad actor came along, easily preventable and they were warned.
- DevX101 6y agoCongratulations Chase. You've just increased the probability that the next security researcher who discovers a vulnerability says nothing to you, or worse sells the exploit on the black market.
- xvector 6y agoThe next researcher should absolutely sell on the black market. Chase deserves no less.
- webel0 6y agoIt is interesting that the only way to draw attention to this issue was via Twitter DM. For many big companies this seems to be the one place where you can hope to get a response. For example, a year ago I was in a pinch and ended up booking a flight on Delta via Twitter DM. The problem with this is that the escalation chain and documentation to go along with it is unclear. The author could only hope that he was being connected with the right people. Likewise, I was just crossing my fingers that there was, indeed, a ticket waiting for me.
- deleted 6y ago[deleted]
- duxup 6y agoNot long ago I worked at a big name tech company and with someone who interacted with folks who reported security concerns. Half the time the security team was scrambling to prevent various people from sending legal on a crusade to attack the latest researcher who responsibly told them about a security issue. It only got better after legal was educated enough to not just shoot from the hip with threats... but really they were just acting like a firewall for much of the management team who saw any such disclosure as some sort of attack. And this was a tech company, everything they did was technology, located in the valley... they still didn't get it. Even just getting these researchers token recognition (many asked for almost nothing) was an uphill battle. One of the challenges was that the folks on the security team were really passionate about doing the right thing and they didn't want to break relationships they had with researchers / the community. They were prone to leave companies who were bad at handling those relationships ... leaving bad companies with fewer such people and accordingly things would fester. The security industry is full of straight up charlatans and legit people. The legit people are super sensitive about being associated with charlatans and thus the charlatans are often left to their own devices after the legit folks run for cover (elsewhere). For the record this is my perception from working with security minded folks, and not actually working in that industry myself.
- nerdponx 6y agoWhat incentive does legal even have for acting this way? Internal commendations? Bonuses?
- duxup 6y agoI never had a good view of what their motivations were. Honestly I've found legal groups in companies to be generally pretty secretive. But I'm inclined to think to start that groups in a company are incentivized to do what they think their job is... bring something to legal, they'll have a legal type answer. Bring something to the engineers, you'll get some code. Need a customer to stop clicking a button? Engineering will code it to be disabled at times. Legal will demand a prompt with a legal agreement you have to check before the action takes place. HR might even come up with some training classes ;)
- texasbigdata 6y agoIs this legal? The chase team should follow up, because it seems like a termination elligible offense on their end. Especially as the individuals are clearly identified. Access to credit and banking is a protected right in America. If Dave and friend want to circumvent the rules they should be eligible to lose their jobs as well.
- astura 6y ago>Access to credit and banking is a protected right in America It is? In what way? Afaik banks give themselves a lot of power to close your accounts for a lot of different reasons - "suspicious activity," "rewards abuse," etc.
- texasbigdata 6y agoIt’s regulated on race / etc, it’s also (as written) potentially retaliation what happened to the family member. Credit is a resources and having old accounts be deleted like that causes real damage to an individual. Fair on the reward abuse though. But to close ALL accounts?
- astura 6y ago>it’s regulated on race / etc Okay, but so is every other service open to the public. It also has nothing to do with this situation >it’s also (as written) potentially retaliation what happened to the family member But in no way illegal (or retaliation) to close associated accounts when terminating a relationship with a customer. The GP was probably once a joint account holder with the family member, or had them as an authorized user on their credit card. >Credit is a resources and having old accounts be deleted like that causes real damage to an individual. Okay... So? That doesn't make it somehow "a protected right," legally speaking. From everything I've read financial institutions have gigantic leeway to close accounts for basically any reason The personal experiences I've heard back this up. https://money.cnn.com/2014/05/07/pf/bank-account-closing/index.html https://money.cnn.com/2014/05/07/pf/bank-account-closing/ind... >"Nobody has the right to a credit card, a bank account, a debit card or a merchant account," said Ulzheimer. "You have to earn it and the banks set the rules. If you are what they perceive to be too risky, they'll shut you down and you have no recourse." >Fair on the reward abuse though. But to close ALL accounts? When a financial institution chooses to end their relationship with your they generally end their relationship with you.
- t0mmyb0y 6y agoThis is a company that banned me from online access to an account because I don't keep cookies on my computer. Terrible company with swiss cheese security.
- rs999gti 6y agoThe OP won in the casino too much, so they decided to show him out and bar him from the property.
- minusSeven 6y agoI guess the consensus I can draw from this post is that is it's never worth the effort to disclose security vulnerabilities.... Feels kind of an American thing.
- athenot 6y agoThanks for sharing this. I just closed my account citing Chase's poor behavior towards security researchers.
- pfortuny 6y agoThe terrible summary is: never ever do a favour to a Company. Ever. The risk is not worth the merit.
- projektfu 6y agoReminds me of Patrick Coombs and his junk mail check experience. “I wonder what happens...” https://www.ft.com/content/93a47a62-daf0-11e1-8074-00144feab49a https://www.ft.com/content/93a47a62-daf0-11e1-8074-00144feab...
- corn13read2 6y agoFuck chase, they did the same to me and my family too
- rootsudo 6y agoYou weren't the only one, back then it was known race conditions triggered stuff on Chase. I can't find anything referencing it, but something happened similar with Zelle back 2017, and then 2015 also with it's mobile app.
- retox 6y agoWe aren't seeing the whole set of messages here but from what is in the post the customer rep asked for confirmation that an account could be left with negative point balance so the researcher went ahead and created negative 5 million points and cashed out $5000. This doesn't seem responsible in the slightest.
- PhantomGremlin 6y agothe researcher went ahead and created negative 5 million points and cashed out $5000. This doesn't seem responsible in the slightest. Your statement is misleading. By "cashed out" he transferred $5000 into another account of his at Chase. It's not like the took the money out of an ATM and spent it on hookers and blow.
- retox 6y agoYou're right, I worded it badly. By "cashed out" I only meant that they turned imaginary points into 'real' money, though both are probably treated as a liability by Chase.
- 1vuio0pswjnm7 6y agoGuesses why the HTML page is URL-encoded and inserted into a script tag. To read without Javascript: curl https://chadscira.com/post/5fa269d46142ac544e013d6e/DISCLOSURE-Unlimited-Chase-Ultimate-Rewards-Points|sed ' s/%3A/:/g; s/%2C/,/g; s/%2F/\//g; s/%3D/=/g; s/%3B/;/g; s/%3F/?/g; s/%26/\&/g; s/%22/\"/g; s/%20/ /g; s/%28/(/g; s/%29/)/g; s/%3C/</g; s/%3E/>/g; s/%27/'"'"'/g; s/%0D//g; s/%0A//g;'|grep -o "<p>.*</p>" > 1.htm firefox ./1.htm
- zxcvbn4038 6y agoI once applied for an IT Security job at Citibank - as I’m walking to the conference room for the interview I notice that every single desk had a beat-up dog-eared copy of “Computer Security For Dummies” on it. It didn’t do them much good, a year later I read they had lost $60 million because you could go into their web banking system, and once authenticated you could access any retail bank account by changing the account number in the URL. Years earlier I was at Chase Manhattan when they decided to hire at IT security role. The guy they selected was a tradesman who specialized in brickwork. Computer Security For Dummies was also his goto and it never left his hands. Most of our interaction with him was his trying to find “the NFS”. We told him several times that we didn’t use NFS but he was convinced we did and were hiding the NFS from him. He called all of us individually into meetings with him and our manager to try and get us to crack and admit where we had hidden the NFS but was unsuccessful - it was a conspiracy. He hired in a couple of consultants find where the NFS was but they couldn’t find it either. When I left he was having the network engineers trace all of the cables to see if we had hidden the NFS in a closet or under the floor.
- 6456457 6y ago> This happened on November 17th 2016, and I am just publicly disclosing it today. > While transferring balances between accounts on an unstable internet connection I saw that the system did a double transfer resulting in one card having a negative balance. > This reminded me of issues I reported in the past with Starbucks US, and Starbucks TH. Both of those entities had major issues with race conditions. How does this happen in 2016? It's as if software developers have somehow gotten collectively worse than they were 20 years ago.
- parksy 6y agoI was involved in a somewhat similar situation in the late 2000's when working on a team building an eCommerce website. We found a major national bank's newly public merchant gateway allowed anyone who knew the IP address of an authorised merchant facility (such as an EFTPOS terminal) to spoof its IP address and submit requests to the gateway. It seemed they just relied on the supplied IP address in the XML payload to verify that a device was authorised to use the gateway. A small proof of concept showed that it was exploitable, e.g. a small script proved a bank card would be processed successfully without needing to actually be on an authorised network or go through any kind of session handshake - we didn't try any of the other functions like requesting refunds or cancelling payments but figured the bank would like to know they had a big glaring hole in their security. After finally getting through their merry-go-round of customer "support" to someone in their IT/Security team, the initial cordial emails stopped and we received a threatening letter from their legal department blathering about legal repercussions of cyber crime and fraud etc. They also contacted the client and threatened to shut down their accounts and merchant facilities for our transgressions. Anyway, definitely makes me think twice about reporting any public-facing security issues directly to a company, I don't have the resources or willpower to fight a major corporation if they decide to swing that way, that's for sure.
- ca98am79 6y agoMy wife and I got banned by Chase, also. They don't tell you why, but I accidentally submitted two credit card applications (one for myself and one for my wife) with identical northwest airlines frequent flier miles numbers. I think this must have flagged something because one day I noticed all of my Chase cards and accounts stopped working and I got a letter in the mail a few days later. There was no phone number, only an address to mail a letter for further inquiries. I mailed a letter explaining that I thought they made a mistake. Someone called me back and told me it wasn't a mistake and they wouldn't give me any more information. I suppose somehow, legally, this became the best course of action for Chase bank - to cut the customer off immediately and give them zero information about it. But it really doesn't feel right and made me never want to do business with Chase again.
- MidnightRaver 6y agoI like crypto lockers. It means researchers can set the price of the vulnerabilities discovered, not shitty corporations.