Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

51–60 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#51
post #27

Earlier quoted context omitted.

The authorities often resell the bitcoins so they could reenter the market.

I've not heard any cases of bitcoins being "seized" by government authorities yet, although I see that happening in the future as probably inevitable. Have any examples?

Silk road seizures were the first and biggest (by amount of coins) but they are much more commonplace now.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#53

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

Not all of us do. I personally find Windows usage entirely unacceptable in security-sensitive environments.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#55
post #47
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

It's valid concern, but I'm not so sure in this case. Spear phishing is a skilled art, and requires relatively significant knowledge of the target and their domain. Sure the rest is a essentially a stackoverflow post away, but it requires real determination to research this kind of attack and real skill to carry it out and see it through to millions in cash popping from ATMs in foreign countries. Just the people mana…

I'm not saying they are script kiddies. I make no claim about their skills. I have no idea what it takes to pull of a conspiracy like this.

I'm just saying I don't believe sensationalizing journalists or law enforcement. Pretty much every time when I've known anything about the case, there have been wild exaggerations.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#56
post #7

Earlier quoted context omitted.

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.

I think the biggest thing is you don't realize how big something will get. You talk about an idea you're working on in IRC or ask a question on stack overflow while you're toying with the idea, then clean up later when it (surprisingly) takes off.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#57
post #3

The article doesn't really go into the thieves' backgrounds at all strangely enough. How did Katana end up in the bank heist business? How did he acquire the skills to turn making fake bank transactions into an "art"? I always wonder about the kind of person who ends up in these criminal dealings and where they come from.

He probably worked for a bank. Lots of smart people learn the "loopholes" of their trades.

My mom worked at a car dealership and realized that you could steal a car from them and it would be upwards of a year before they figured it out, since that's when they did inventory. Back then, the keys were all kept in an marginally secured cases.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#58
post #35
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

It is and it is (sorta). I worked in the bank industry for many years and I could have stolen money a hundred different ways without getting caught. The problem is that in the end the money has to go somewhere or be spent (why else steal it?). Also to live a legal life (house,car,boat) you have to have a source of income/spending that does not set off red flags. If you are a high paid bank employee why even bother? M…

Many (most?) financial type crimes have no statue of limitations so to get away you literally have to get away with it for the rest of your life

At least in the US, this is inaccurate. Most financial/fraud crimes have a statute of limitations of 3-5 years, both at the state and federal level. Some federal crimes specifically against financial institutions have a SOL of 10 years. Generally the only crimes that have no statute of limitations are punishable by life/death (such as first degree murder). See https://www.justice.gov/usam/criminal-resource-manual-650-le...

Re: The Biggest Digital Heist in History Isn’t Over Yet

#59
post #42
post #12

Earlier quoted context omitted.

Good catch. Either it's a misstatement from the author, or law enforcement don't want to reveal how they actually caught them.

Which implies parallel construction

I think it's parallel construction iff they submit a false line of evidence to a judge.

It's not illegal to tell tall tales to the press. Maybe they want to protect an informant. Or, maybe they just want to protect some technical dragnet they've set up, for the time being.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#60
post #35

Earlier quoted context omitted.

It is and it is (sorta). I worked in the bank industry for many years and I could have stolen money a hundred different ways without getting caught. The problem is that in the end the money has to go somewhere or be spent (why else steal it?). Also to live a legal life (house,car,boat) you have to have a source of income/spending that does not set off red flags. If you are a high paid bank employee why even bother? M…

Many (most?) financial type crimes have no statue of limitations so to get away you literally have to get away with it for the rest of your life At least in the US, this is inaccurate. Most financial/fraud crimes have a statute of limitations of 3-5 years, both at the state and federal level. Some federal crimes specifically against financial institutions have a SOL of 10 years. Generally the only crimes that have no…

SOL is a timer from time of crime to time of indictment, and indictment doesn't necessarily require knowing the precise identity of the defendant or capturing the defendant.

In GA, fleeing stops the clock, and in WA, "John Doe" can be indicted, subject to some restrictions.

https://tollefsenlaw.com/statute-limitations-tolled-against-...

Post reply on HN