Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

41–50 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#41
post #30

Earlier quoted context omitted.

Better security is not letting them get the cash at all.

Cost of dealing with a dead teller is probably higher than the amount of cash that will satisfy most traditional robbers. If that robber-satisfying amount can be recovered with a certain degree of reliability, the security model is effective in deterring attacks, minimizing attack damage, and ensuring physical safety of team members.

There are only around 5,000 bank robberies in the US each year. If they each walked away with 100,000$* which is unlikely that's only 0.5 billion which is peanuts vs the 44 billion retail loses from shoplifters and other issues.

PS: 100k in 20's is ~11 pounds. Some people might leave the bank with more than that, but not that much as most branches don't much have cash and simply simply moving it becomes difficult.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#42
post #12
post #4

Earlier quoted context omitted.

Especially in the sentence prior to it where it says "the ATM started disgorging cash without either man touching it" What's the bank card for if they just stood there and it spit money out in a timed fashion?

Good catch. Either it's a misstatement from the author, or law enforcement don't want to reveal how they actually caught them.

Which implies parallel construction

Re: The Biggest Digital Heist in History Isn’t Over Yet

#43
post #27

Earlier quoted context omitted.

The authorities often resell the bitcoins so they could reenter the market.

I've not heard any cases of bitcoins being "seized" by government authorities yet, although I see that happening in the future as probably inevitable. Have any examples?

https://www.wired.com/2013/12/fbi-wallet/

Re: The Biggest Digital Heist in History Isn’t Over Yet

#44
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses.

I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims.

It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#45
post #27

Earlier quoted context omitted.

The authorities often resell the bitcoins so they could reenter the market.

I've not heard any cases of bitcoins being "seized" by government authorities yet, although I see that happening in the future as probably inevitable. Have any examples?

You mean exactly like this bitcoin that was seized and sold by the government: http://fortune.com/2017/10/02/bitcoin-sale-silk-road/

Re: The Biggest Digital Heist in History Isn’t Over Yet

#46
post #44
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses. I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims. It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.

[deleted]

Re: The Biggest Digital Heist in History Isn’t Over Yet

#47
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

It's valid concern, but I'm not so sure in this case. Spear phishing is a skilled art, and requires relatively significant knowledge of the target and their domain. Sure the rest is a essentially a stackoverflow post away, but it requires real determination to research this kind of attack and real skill to carry it out and see it through to millions in cash popping from ATMs in foreign countries. Just the people management alone is impressive

And finally, I don't think stackoverflow cover ATM maintenance procedures yet. These guys weren't kiddies

Re: The Biggest Digital Heist in History Isn’t Over Yet

#48
post #7

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

The criminals have to be lucky continually - the detectives only need to be lucky once.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#49
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

The door code for one of the US's top banks' offices used to be 0000. I wonder if they finally changed it? EA QAs their games better than a lot of financial institutions as well

EA is largely hosted and managed by rackspace, who, for years, had default passwords on their iLOs - with public IPs. ;)

Re: The Biggest Digital Heist in History Isn’t Over Yet

#50
post #7

Am I the only one that finds it suspicious that one of these guys would drop a debit card at a heist?

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

>Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name".

I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.

Post reply on HN