Live data from Hacker News

How Hackers Stole $100M from the New York Fed

zerohedge.com

71–80 of 87 posts

Re: How Hackers Stole $100M from the New York Fed

#71

I would be all for banning submissions from zerohedge.com outright. It's just noise that makes it harder for me to skim headlines for actual content.

It's already penalized [1] and most submissions would get flagged anyway.

[1] https://news.ycombinator.com/item?id=11263530

Re: How Hackers Stole $100M from the New York Fed

#73

I find ZH amusing.. In some ways I think it's the anti hackers news.. Hyper negative about the future.. Constant hate for new tech.. (Fear of skynet).. The system is always rigged and the little guy will never succeed... Posts by Right coast angry ex-traders.. The comments are inane...the cherry picked stories out of left field but plausible. Etc. The one place the two sites do often intersect is the fear and loathin…

I read it every day. If only to contextualize the other news sources I read. FWIW I throw in some infowars when something big happens so I can see how certain segments will try to spin something.

Re: How Hackers Stole $100M from the New York Fed

#74
post #17

Earlier quoted context omitted.

I'm surprised they haven't started putting RFID tags in every chip so they can track exactly how much each player spends at each game. Combined with proper record keeping, if chips were ever stolen, you could flag them and make sure they can't be redeemed for cash. Maybe in Vegas?

>I'm surprised they haven't started putting RFID tags in every chip so they can track exactly how much each player spends at each game. and how would casino be laundering money then? :)

The casino doesn't need chips to launder money. That's how other people use the casino to launder money.

Re: How Hackers Stole $100M from the New York Fed

#75
Worked at a bank. Usually stayed late/came early/irregular hours. Therefore had access code to the key safe, for confirming everyone put their keys in the key safe.

But this was for front office and back office. Access to all keys. Small team, 10 people.

That's important.

Knew how much we had in the petty cash bank account. Usually around USD 40MM. Liquidity usage, etc. Also had access to the cheque book (via key locked cabinet), where via sealed internal mail, cash payment requests (cheque) were sent to the banking department.

Speaking to a friend in the banking department, he remarked that whitelists of authorised payment receivers where being introduced. Being introduced? "Sure, if a payment request comes in, and it is authorised correctly (signature, in case of cheques), we send it ASAP." "Do you telephone the signer to verify? No." "Any transaction limits?" "No." This was 2005.

Could have walked away with USD 40MM - then fled rapidly to another country. But didn't. Well, did go to another country.

2 factor authentication is essential, and whitelists too - a central bank doesn't change their account number. The FED seems to have had neither.

Re: How Hackers Stole $100M from the New York Fed

#76
post #74
post #17

Earlier quoted context omitted.

>I'm surprised they haven't started putting RFID tags in every chip so they can track exactly how much each player spends at each game. and how would casino be laundering money then? :)

The casino doesn't need chips to launder money. That's how other people use the casino to launder money.

>The casino doesn't need chips to launder money.

they do need plausible lack of total control and accounting of all chips' movements.

Re: How Hackers Stole $100M from the New York Fed

#77
So SWIFT, the backbone of international monetary transfers, doesn't have some sort of automated way to verify that requests are legitimate? It would seem to me that once a request is received, the only secure thing to do would be to send a hash of the request back to a known system belonging to the originator to verify that the request was authorized.

If SWIFT security is really as bad as this incident seems to suggest, I'm shocked that more fraudulent transfers don't occur.

Re: How Hackers Stole $100M from the New York Fed

#78

Earlier quoted context omitted.

Reuters: http://www.reuters.com/article/us-usa-fed-bangladesh-typo-in... Bloomberg: http://www.bloomberg.com/news/articles/2016-03-09/the-1-bill...

The zerohedge article has more information than either of those articles. It uses those two as sources, plus some Philippine newspapers. Right now it gives a fairly effective summary of the situation. Switching to either of those would be a downgrade, in my opinion.

The zerohedge article is misleading (e.g. "And yes, it does appear that hackers managed to bypass the Fed's firewall") and lacks any semblance of objectivity.

Re: How Hackers Stole $100M from the New York Fed

#79

If the funds were sent to casinos, shouldn't the casinos have logs of what the money was used for?

unlikely. The best way to legally launder money is to use a casino. You bring in your dirty money, exchange it for chips. Then sit on your chips for a week, maybe a month, then go back and cash out your chips for clean money. Meanwhile, all the cash you moved through the casino is now scattered to some 50-100 different banks as it gets deposited in their daily drops and then transferred as necessary between the banks…

The large value chips have rfid tags in them. You would be investigated. You'd need to play some game with a slight loss to the casino to swap them out.

Re: How Hackers Stole $100M from the New York Fed

#80
post #54

Earlier quoted context omitted.

unlikely. The best way to legally launder money is to use a casino. You bring in your dirty money, exchange it for chips. Then sit on your chips for a week, maybe a month, then go back and cash out your chips for clean money. Meanwhile, all the cash you moved through the casino is now scattered to some 50-100 different banks as it gets deposited in their daily drops and then transferred as necessary between the banks…

But I don't understand something. You showed up with lets say $50k at the casino, you departed with the same $50k. If you'll be investigated, you still can't justify the money you walked in with.

Criminal 1 buys $50k in chips using wired funds. Gives chips to criminal accomplices 2, 3 and 4.

CA2, CA3 and CA4 come into the casino a few different times over several months, gamble for while for a net zero gain or loss, and then convert their "winnings" from chips into cash in chunks of $5k or so - flying under the radar.

C1 never needs to come back to the casino where the police might catch him - and he is the only one who is linked to the big heist.

Post reply on HN