Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

61–70 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#61

Earlier quoted context omitted.

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…

Better security is not letting them get the cash at all.

True but not particularly relevant. In reality, we almost never expect 100% perfection, we assign a cost/benefit ratio and multiply by failure rate.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#62
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

>I would think it's easy to get in, and hard to not get caught. Imagine you're an new employee at a big old company with a lot of legacy tech that's had mediocre maintenance and documentation over the years as is typical. You are going to leave footprints everywhere just learning to do your job. Imagine how many footprints you leave when you're an outsider who has to learn it all from scratch without documentation or…

At some point, if the attacks got too frequent or severe, insurance rates would climb to the point where attacks would be better defended or retaliated against.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#63
post #44
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses. I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims. It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.

Generally, defendants don't need to defend against bombastic statements in the media. In fact, such statements can help the defendant, as they can prejudice and disqualify jurors, leading to mistrial.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#64
post #3

The article doesn't really go into the thieves' backgrounds at all strangely enough. How did Katana end up in the bank heist business? How did he acquire the skills to turn making fake bank transactions into an "art"? I always wonder about the kind of person who ends up in these criminal dealings and where they come from.

He probably worked for a bank. Lots of smart people learn the "loopholes" of their trades. My mom worked at a car dealership and realized that you could steal a car from them and it would be upwards of a year before they figured it out, since that's when they did inventory. Back then, the keys were all kept in an marginally secured cases.

Johnny Cash figured how to steal them from the factory

https://www.youtube.com/watch?v=18cW_yHo3PY

Re: The Biggest Digital Heist in History Isn’t Over Yet

#65

Earlier quoted context omitted.

> IT security at banks ... is pretty crappy? I would think it's easy to get in, and hard to not get caught. Yes it is not state of the art. They need a compliance regime in order to be secure, and they meet that and that only. But I think you're missing an aspect, things like passwords that change daily and require collusion, advanced social engineering, physical access, etc. Further, being easy to get caught is the…

Better security is not letting them get the cash at all.

there are barriers and dye bags amoung other things. in this instance it's about security and safety plus they are insured.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#66
post #7

Earlier quoted context omitted.

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.

If that was the flaw, then why did he try so hard to remain anonymous?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#67

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

Microsoft Office was years ahead of the Open Web / JavaScript in providing all the convenience and security of remote code execution at the request of arbitrary untrusted third-party systems.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#68
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> I have a friend who briefly worked at a company which exclusively makes software for financial institutions.

Sounds like Jack Henry. My bank uses them for their client web portal. Up until last year, they had an 8 character max limit on your password, and you couldn't use any special characters or spaces.

But at least they make you verify your "personal photo" every time you log in. Which is more than useless since I assume they are trying to protect you from phishing and any decent phishing attempt would just skip that step and no one would notice. Or, if they wanted, they could just port your username to the real site and pass the photo along to you through the phishing site UI.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#69
post #63
post #44

Earlier quoted context omitted.

I wonder if anyone accused of these things has ever thought to bring in HN users as expert witnesses. I'm sure even a random sample would cause a huge reduction in these inflated "master hacker" claims. It seems that if you can have a few people rationally explain to a jury what the accused did, the crimes would seem much less diabolical.

Generally, defendants don't need to defend against bombastic statements in the media. In fact, such statements can help the defendant, as they can prejudice and disqualify jurors, leading to mistrial.

Sorry if I wasn't clear - my comment was directed at overly aggressive prosecutors.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#70
post #7

Earlier quoted context omitted.

People are always shocked at the stupid mistakes that big criminal masterminds make. Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". And so on. There are ten thousands different mistakes that you can make, you need to guard against all of them. And against whatever unknown tech exists. In this story, that dropped bank card turns out to not be that significant. The real break…

> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.

Isn't not getting caught sort of part and parcel of silk road style evangelism?
Post reply on HN