Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

11–20 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#11
>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit.

Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable.

Why does outlook have to pass such documents to Word? Why does Word have to open and run macros so willingly? Why does Windows allow word to talk to the internet so easily? I just don't understand the use case these links are meant to address. Are there really so people out there installing software via links inside word documents? That this has to be a seamless user experience? There are so many opportunities to limit such such infections. Why do we still tolerate this?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#12
post #4

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

Especially in the sentence prior to it where it says "the ATM started disgorging cash without either man touching it" What's the bank card for if they just stood there and it spit money out in a timed fashion?

Good catch.

Either it's a misstatement from the author, or law enforcement don't want to reveal how they actually caught them.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#13
post #9
post #5

From the headline alone I assumed it was going to be about the tech industry's theft of the world's data

And I thought they were going to talk about cryptocurrencies... :)

They do say a lot of theft cash ended up converted to Bitcoin. So, at least a measurable chunk of the liquidity in the market is down to this...

Re: The Biggest Digital Heist in History Isn’t Over Yet

#14
post #7

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

... or the Russian FSB officer forgetting all about VPN and logging on from his office. [1]

People make stupid mistakes.

[1] https://news.ycombinator.com/item?id=16653671

Re: The Biggest Digital Heist in History Isn’t Over Yet

#15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught.

Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version of Internet Explorer so old, it didn't support Ajax. Asynchronous requests were made by changing the src attribute of a 1px .

This was in 2015.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#16

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

Well, you know what they say:

- You have to be lucky every time to continue free... I only have to be lucky once to catch you.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#17
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught.

Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc.

Further, being easy to get caught is the definition of good security. It's super easy to physically enter a bank and take all available cash at gunpoint. Nearly impossible to get away with it. That's good security. Extend that to the digital realm.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#20

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

[deleted]
Post reply on HN