Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

21–30 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#21
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…

Better security is not letting them get the cash at all.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#22

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

Every piece is desired in some fashion.

We want Outlook to open our attachments without having to explicitly choosing the program.

We want Word to have those advanced macro features.

We want Word to have hyperlinks to things on the internet.

We want to be able to install things downloaded from the internet.

In isolation, each of those things are desirable to some segment of the userbase. It just so happens that the chain basically allows you to install a program from an email attachment.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#23
post #5

From the headline alone I assumed it was going to be about the tech industry's theft of the world's data

Is it stealing if the person gives it to you?

Maybe not stealing but extortion. “Give us all your data or you can’t use the service all your friends use to keep in touch”.

It’s even worse when the service we’re talking about goes beyond social networking and becomes a must-have like a cell phone (referring to major US carriers secretly selling location data to a marketing company).

Re: The Biggest Digital Heist in History Isn’t Over Yet

#24
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

The fact they supposedly recovered 15k Bitcoins tells me he wasn't sophisticated enough to secure his private key sufficiently. If he had memorized a BIP39 mnemonic for his private key we wouldn't be reading about $162 million dollars worth getting seized. Brain wallets are pretty tough to crack.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#26
post #24
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

The fact they supposedly recovered 15k Bitcoins tells me he wasn't sophisticated enough to secure his private key sufficiently. If he had memorized a BIP39 mnemonic for his private key we wouldn't be reading about $162 million dollars worth getting seized. Brain wallets are pretty tough to crack.

A wrench is all you need apparently. https://xkcd.com/538/

Re: The Biggest Digital Heist in History Isn’t Over Yet

#27
post #9

Earlier quoted context omitted.

And I thought they were going to talk about cryptocurrencies... :)

They do say a lot of theft cash ended up converted to Bitcoin. So, at least a measurable chunk of the liquidity in the market is down to this...

The authorities often resell the bitcoins so they could reenter the market.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#28
post #4

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

Especially in the sentence prior to it where it says "the ATM started disgorging cash without either man touching it" What's the bank card for if they just stood there and it spit money out in a timed fashion?

the ATM was a Taiwanese ATM, and they were Russian, so they could have had their own Russian debit card.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#29

Earlier quoted context omitted.

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…

Better security is not letting them get the cash at all.

In some banks in Europe, a customer needs to be buzzed in to enter the premises.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#30

Earlier quoted context omitted.

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…

Better security is not letting them get the cash at all.

Cost of dealing with a dead teller is probably higher than the amount of cash that will satisfy most traditional robbers. If that robber-satisfying amount can be recovered with a certain degree of reliability, the security model is effective in deterring attacks, minimizing attack damage, and ensuring physical safety of team members.
Post reply on HN