Live data from Hacker News

A fraudster got $12M out of a Canadian university

thestar.com

111–119 of 119 posts

Re: A fraudster got $12M out of a Canadian university

#111
post #98

Earlier quoted context omitted.

But the process is broken by people not realizing that invoices are fraudulent. The method of delivery, be that email or some other system, is completely orthogonal. Running their invoices through SAP or having gpg signed pdf invoices or using more node.js would not help because all of those solutions fail to address the fact that people are dumb and need to be trained to avoid scams.

Yes, the problem is people on the paying side not realizing that payment change requests are fraudulent. So a better process removes people on the paying side routinely changing payment information. Require that payees sign into a separate service and they change the payment information themselves.

Again I think that just slapping a new service in there doesn't address the fundamental problem which is that the university did not conduct sufficient verification of payment details before sending out 12 million dollars.

All it would have taken is a phone call to the company's accounting department confirming the change.

"Verification of changes to banking details as a service" is not the answer. It's a Band-Aid solution.

Re: A fraudster got $12M out of a Canadian university

#112

This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…

At IBM they would randomly send people phish mails, if you clicked on them you landed on the site that provided remedial training! I always thought this would be a good service to offer companies. You could call it "Phish for Compliance" :-)

We're getting some here. The first time it happened, everyone received an email, so the first to click on the link warned the other not too.

Re: A fraudster got $12M out of a Canadian university

#113
post #111

Earlier quoted context omitted.

Yes, the problem is people on the paying side not realizing that payment change requests are fraudulent. So a better process removes people on the paying side routinely changing payment information. Require that payees sign into a separate service and they change the payment information themselves.

Again I think that just slapping a new service in there doesn't address the fundamental problem which is that the university did not conduct sufficient verification of payment details before sending out 12 million dollars. All it would have taken is a phone call to the company's accounting department confirming the change. "Verification of changes to banking details as a service" is not the answer. It's a Band-Aid so…

And my perspective is that as long as you have a process where administrative staff are making the changes, they will cut corners. For them, these transfers are routine. They do dozens every month. You need a process which removes them from the loop.

Re: A fraudster got $12M out of a Canadian university

#114
post #106

Earlier quoted context omitted.

As is, say, bathing.

Useless, pedantic innuendo

It only requires one black swan to counter the proposition that all swans are white. Bathing is my swan. Surely it's clear that a direct contradiction is not "innuendo." Nor pedantic - hardly, since everyone is familiar with bathing. (They didn't have to be familiar with the philosopher of science Hempel's writings - the origin of the black swan remark, here - to understand the contradiction.)

Re: A fraudster got $12M out of a Canadian university

#115
post #106

Earlier quoted context omitted.

Useless, pedantic innuendo

It only requires one black swan to counter the proposition that all swans are white. Bathing is my swan. Surely it's clear that a direct contradiction is not "innuendo." Nor pedantic - hardly, since everyone is familiar with bathing. (They didn't have to be familiar with the philosopher of science Hempel's writings - the origin of the black swan remark, here - to understand the contradiction.)

Honestly at this juncture I haven't a clue what your point is. At no time have you offered anything resembling a direct contradiction.

Instead of vague implications and analogies, just state your opinion clearly.

Re: A fraudster got $12M out of a Canadian university

#116

This is why all staff, whether at a corporation, nonprofit or government that handle money should be put through a two hour anti-phishing training course. There's lots of good free training material out there. There are also services which you can hire. You give them a list of staff emails, and they send test phishes to everyone. Those who respond or click on links (there's a GUID in each phish) can be sent for furth…

At IBM they would randomly send people phish mails, if you clicked on them you landed on the site that provided remedial training! I always thought this would be a good service to offer companies. You could call it "Phish for Compliance" :-)

there's a company called phishme which does this as a service.

Re: A fraudster got $12M out of a Canadian university

#117
post #115

Earlier quoted context omitted.

It only requires one black swan to counter the proposition that all swans are white. Bathing is my swan. Surely it's clear that a direct contradiction is not "innuendo." Nor pedantic - hardly, since everyone is familiar with bathing. (They didn't have to be familiar with the philosopher of science Hempel's writings - the origin of the black swan remark, here - to understand the contradiction.)

Honestly at this juncture I haven't a clue what your point is. At no time have you offered anything resembling a direct contradiction. Instead of vague implications and analogies, just state your opinion clearly.

So much abuse yet here's what I was replying to: "Taking email out of the loop is a technical solution to a problem that is inherently social, not technical." The clear implication being that you can't solve social problems with tech, but we do this all the time and have, forever, as my example shows. Q.E.D.

Inherently social problems are commonly solved by technical interventions, e.g. distressing human smells by bathing or perfuming.

Did that really need rererepeating? No, the point was clear the in first instance, you just disagreed and preferred vituperation it to addressing my point. People who just gainsay here annoy me, but you've hit a new low.

Re: A fraudster got $12M out of a Canadian university

#118
post #115

Earlier quoted context omitted.

Honestly at this juncture I haven't a clue what your point is. At no time have you offered anything resembling a direct contradiction. Instead of vague implications and analogies, just state your opinion clearly.

So much abuse yet here's what I was replying to: "Taking email out of the loop is a technical solution to a problem that is inherently social, not technical." The clear implication being that you can't solve social problems with tech, but we do this all the time and have, forever, as my example shows. Q.E.D. Inherently social problems are commonly solved by technical interventions, e.g. distressing human smells by ba…

>No, the point was clear the in first instance

It most certainly was not and still isn't. Drop your holier-than-thou attitude and you might actually make some friends on the internet.

Pretty much all you said was "bathing". It was not clear to what you were replying. It was not clear what your point was. It was not clear what you were implying.

Bathing is not a social problem that I'm aware of. We as a species have been bathing for more than 4000 years and have been doing it fundamentally the same way (wash body with water and potentially with soap or other solvent) for most of that time. There have been no major technological advances in bathing that I'm aware of since perhaps the invention of the shower. I would argue that is not a technical solution to a social problem.

In any case, this entire farcical tangent has nothing to do with the social dynamic of fraudsters exploiting weaknesses in the human psyche, and I think you know that.

I am convinced you are just trolling and will not respond again.

Re: A fraudster got $12M out of a Canadian university

#119
post #118

Earlier quoted context omitted.

So much abuse yet here's what I was replying to: "Taking email out of the loop is a technical solution to a problem that is inherently social, not technical." The clear implication being that you can't solve social problems with tech, but we do this all the time and have, forever, as my example shows. Q.E.D. Inherently social problems are commonly solved by technical interventions, e.g. distressing human smells by ba…

>No, the point was clear the in first instance It most certainly was not and still isn't. Drop your holier-than-thou attitude and you might actually make some friends on the internet. Pretty much all you said was "bathing". It was not clear to what you were replying. It was not clear what your point was. It was not clear what you were implying. Bathing is not a social problem that I'm aware of. We as a species have b…

Astonished, sir.
Post reply on HN