Live data from Hacker News

BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

securityweek.com

31–40 of 49 posts

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#31
post #24

On a related note: The Bank Of America ATMs are really, really great. Their ATMs and their online bill pay service are some great banking tech. They're the only reason I'm a BoA customer for my checking and cashflow accounts. With their BillPay service, I can have BoA download e-bills from, say, credit card companies or utilities, and pay the amount of the bill on its due date. I never have to worry about it. I can s…

With their BillPay service, I can have BoA download e-bills from, say, credit card companies or utilities, and pay the amount of the bill on its due date. I never have to worry about it. Really? I can't even figure out how to tell Bank of America to auto-pay my Bank of America credit card every month.

Yeah, first you have to go underneath the "Billpay" tab and add a "Pay To" account. After you do that, you'll get a little icon that displays if that account is eligible for E-Bills.

Once you request E-bills, you can setup an E-Bill Initiated Payment Plan.

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#33
post #8

People in charge of the BofA mortgage signature fraud should go to prison too. http://www.cbsnews.com/8301-504803_162-20049744-10391709.htm... But I guess it's a lot easier to prosecute people who can't afford expensive lawyers.

Prosecuting financial fraud is usually a great deal slower and more complex because it's more difficult to prove intent (compared to both incompetence and pursuit of legitimate profit), because it can involve so many more people (many of whom may not have been doing anything wrong at the individual level, but whose actions taken together were wrong at an institutional level), and because the rewards are more diffuse and indirect (unit profits lead to pay rises or career advancement for those involved, rather than bags of cash or deposits into secret accounts).

That's not to say that people can't or shouldn't be prosecuted, just that it's a more difficult undertaking. A recent example: http://www.housingwire.com/2011/04/19/ex-tbw-ceo-lee-farkas-...

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#35
post #8

People in charge of the BofA mortgage signature fraud should go to prison too. http://www.cbsnews.com/8301-504803_162-20049744-10391709.htm... But I guess it's a lot easier to prosecute people who can't afford expensive lawyers.

Prosecuting financial fraud is usually a great deal slower and more complex because it's more difficult to prove intent (compared to both incompetence and pursuit of legitimate profit), because it can involve so many more people (many of whom may not have been doing anything wrong at the individual level, but whose actions taken together were wrong at an institutional level), and because the rewards are more diffuse…

Signing someone else's name at the behest of a department head is pretty clear fraud (and more obvious when it's 1000's of documents being signed with someone else's name and backdated). Watch the 60 Minutes segments.

Prosecutors don't want to take on the financial sector because it ruins their achievement record if they lose or it takes too long because the defendant can afford good lawyers. They stick to the people who cannot afford a defense.

No-one has been prosecuted for the financial crisis, I mean the economy was DESTROYED, we are years into it now.

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#36
I'm just dying to know how exactly he did it and how they tracked him down. I've joked about this type of thing with friends, but it would be absolutely hilarious if he did something to the effect of putting his information within the malware which led cops right to his doorsteps. I have a feeling, this may be something at the level of a burglar leaving footprints in the snow right to his home... I mean, wouldn't they have locked him up and thrown away the keys if it were more of an Oceans 11 type plan & they had to chase him down spending tons of federal money? 400k & 27 months for what essentially is equivalent to bank robbery?

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#37

I'm just dying to know how exactly he did it and how they tracked him down. I've joked about this type of thing with friends, but it would be absolutely hilarious if he did something to the effect of putting his information within the malware which led cops right to his doorsteps. I have a feeling, this may be something at the level of a burglar leaving footprints in the snow right to his home... I mean, wouldn't the…

My guess is that when the money in the ATMs didn't reconcile.

It may be normal for a set of ATMs to be off by a few hundred a year, but anything higher than the norm would be enough to set off alarms.

After that, it just involves reviewing code checkins and camera footage.

Just a guess, though. Hell, maybe he used ATM card first before each "heist".

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#38
post #32

Earlier quoted context omitted.

That is a line from "Hackers" one of Angelina Jolie's first movies!

Or he could actually be asking how he was caught.

I totally did not read Hansy's comment that way since it was posted in a weird place in the thread. I thought he/she was referring to line from "hackers"

Hansy, I apologize.

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#39
post #12
post #7

One would wonder if there were any code reviews in place or not? Any code that has monetary effects has to go through a series of code reviews (saying from my experience working with a client in banking industry) and tests. I would be curious as to how the 'bug' went undetected until deployment!

Any code that has monetary effects has to go through a series of code reviews The article reported that he installed malware on select ATMs. I acknowledge that this leaves a great deal to the imagination, but one suspects a code review would not catch the problem. The code was clean, the implementation on certain machines went awry.

In other words, he did some kind of internal hacking to install his code - illegally bypassing the code review process.

Re: BofA Programmer Heads to Prison After Coding ATMs to Spit Out Free Cash

#40
post #13

On a related note: The Bank Of America ATMs are really, really great. Their ATMs and their online bill pay service are some great banking tech. They're the only reason I'm a BoA customer for my checking and cashflow accounts. With their BillPay service, I can have BoA download e-bills from, say, credit card companies or utilities, and pay the amount of the bill on its due date. I never have to worry about it. I can s…

And yet they still use the Windows "ding" for everything, because of course there's no budget for sound design in an ATM project. I hear those weirdly-out-of-place Windows sounds everywhere. It grates on me the same way Comic Sans grates on those who appreciate type. Someone who does sound design could pick up this banner and impress everyone with set of free UI sounds that are classic and usable.

Ha! The New Jersey Transit ticket kiosks at 8th street station in Philly make the same Windows ding noise. It sounds like a program is stuck on an error, and it's like a dog whistle to me.

That said, about your comment "Someone who does sound design could pick up this banner and impress everyone with set of free UI sounds that are classic and usable." -- I'm betting that's exactly what MS was trying to do. They commissioned Brian Eno to do the Windows 95 startup sound, and brought on Robert Fripp for Vista's startup sound (along with Tucker Martine and Steve Ball). Mind you, I'm not sure who's responsible for the various system sounds.

It's very easy to say "make classic, usable, impressive UI sounds" but incredibly difficult to actually do that.

Post reply on HN