Earlier quoted context omitted.
> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…
Better security is not letting them get the cash at all.
The Biggest Digital Heist in History Isn’t Over Yet
61–70 of 92 posts
Re: The Biggest Digital Heist in History Isn’t Over Yet
#62Earlier quoted context omitted.
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
>I would think it's easy to get in, and hard to not get caught. Imagine you're an new employee at a big old company with a lot of legacy tech that's had mediocre maintenance and documentation over the years as is typical. You are going to leave footprints everywhere just learning to do your job. Imagine how many footprints you leave when you're an outsider who has to learn it all from scratch without documentation or…
Re: The Biggest Digital Heist in History Isn’t Over Yet
#63I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…
I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses. I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims. It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#64The article doesn't really go into the thieves' backgrounds at all strangely enough. How did Katana end up in the bank heist business? How did he acquire the skills to turn making fake bank transactions into an "art"? I always wonder about the kind of person who ends up in these criminal dealings and where they come from.
He probably worked for a bank. Lots of smart people learn the "loopholes" of their trades. My mom worked at a car dealership and realized that you could steal a car from them and it would be upwards of a year before they figured it out, since that's when they did inventory. Back then, the keys were all kept in an marginally secured cases.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#65Earlier quoted context omitted.
> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…
Better security is not letting them get the cash at all.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#66Earlier quoted context omitted.
People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…
> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#67>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…
Re: The Biggest Digital Heist in History Isn’t Over Yet
#68I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
Sounds like Jack Henry. My bank uses them for their client web portal. Up until last year, they had an 8 character max limit on your password, and you couldn't use any special characters or spaces.
But at least they make you verify your "personal photo" every time you log in. Which is more than useless since I assume they are trying to protect you from phishing and any decent phishing attempt would just skip that step and no one would notice. Or, if they wanted, they could just port your username to the real site and pass the photo along to you through the phishing site UI.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#69Earlier quoted context omitted.
I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses. I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims. It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.
Generally, defendants don't need to defend against bombastic statements in the media. In fact, such statements can help the defendant, as they can prejudice and disqualify jurors, leading to mistrial.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#70Earlier quoted context omitted.
People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…
> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.