Live data from Hacker News

Ozarks Technical Community College robbed of nearly $900k

bransontrilakesnews.com

51–60 of 88 posts

Re: Ozarks Technical Community College robbed of nearly $900k

#51
post #36

Earlier quoted context omitted.

Like it or not, this is the price of "privacy". Being able to easily pretend to be anyone, in the absence of an overarching identity framework -- and leaving identity recognition to the end user -- makes cybercrime a lot easier than it has to be.

This is a really upsidedown take. Spam was rampant prior to better safeguards around privacy, for one. It almost took down the internet iirc.

"Better safeguards around privacy"? How is Google or Cloudflare or NSA or whoever peeking at your incoming emails to determine what gets through good for "privacy"? That is upside down and backwards.

Please explain.

Re: Ozarks Technical Community College robbed of nearly $900k

#52
post #49
post #36

Earlier quoted context omitted.

Like it or not, this is the price of "privacy". Being able to easily pretend to be anyone, in the absence of an overarching identity framework -- and leaving identity recognition to the end user -- makes cybercrime a lot easier than it has to be.

Privacy does not mean anonymous interaction with known parties. It means the CIA can’t see me make an account transfer over the wire. In other words, without a warrant. Authentication and privacy are compatible. Privacy and anonymity are orthogonal.

The CIA can and will monitor your offline and online behavior if your profile is interesting to them. No amount of "muh privacy" appeals will stop them.

Privacy and anonymity are absolutely not orthogonal. How do you KYC? By "violating" their privacy (storing and querying personal records) to identify (deanonymize) someone.

Re: Ozarks Technical Community College robbed of nearly $900k

#53
post #36

I feel like spammers and cyber criminals are getting better. Stuff is starting to get through Google spam filter by mashing up with elements that seem very real and urgent. Like yesterday I got this spam in my Gmail primary inbox with a subject line like "RE: Department of Education Case #295720186". It made me wonder if you could autogenerate filter-evading spam using GANs? Train a GAN to generate email that fools a…

Like it or not, this is the price of "privacy". Being able to easily pretend to be anyone, in the absence of an overarching identity framework -- and leaving identity recognition to the end user -- makes cybercrime a lot easier than it has to be.

The bank account and the bank that the funds were misdirected to both have government-issued identities attached, so exactly what "privacy" are you talking about?

Re: Ozarks Technical Community College robbed of nearly $900k

#54
post #50
post #46

https://archive.ph/YtPLb The site is not available for European visiotrs due to legal reasons: >>> We recognize you are attempting to access this website from a country belonging to the European Economic Area (EEA) including the EU which enforces the General Data Protection Regulation (GDPR) and therefore access cannot be granted at this time.

For websites with specifically-American audiences, it can often be easier to only allow people from their intended readership access than to correctly understand and implement compliance to a foreign law. In this case, it's a local news website.

It’s not that complicated. Just don’t collect any private/profiling information and you’re good.

They’d probably rather stay with a more limited audience that keeps their ad CTRs up, than dilute the numbers with unmonetized visitors.

Re: Ozarks Technical Community College robbed of nearly $900k

#55
post #32

Oof, if a $900,000 invoice doesn't trigger review from their accounting dept, kind of their fault for not having a process of the common sense to question that bill.

Google and Facebook got bilked out of $100M, and you would guess they had lots of processes and technology in place. https://www.npr.org/2019/03/25/706715377/man-pleads-guilty-t...

Oh they have more technology than thinking people in many non-technical departments. Automate the decision process and forget the edge cases seems to be the modus operandi.

Re: Ozarks Technical Community College robbed of nearly $900k

#56

I feel like spammers and cyber criminals are getting better. Stuff is starting to get through Google spam filter by mashing up with elements that seem very real and urgent. Like yesterday I got this spam in my Gmail primary inbox with a subject line like "RE: Department of Education Case #295720186". It made me wonder if you could autogenerate filter-evading spam using GANs? Train a GAN to generate email that fools a…

Its just different people disrupting the spam space.

Someone looked at the operational assumptions of “lets target gullible people by using stupid obviously fraudulent scenarios so that we can weed out everyone who wont play along” and noticed it is missing a very large target market unnecessarily.

Re: Ozarks Technical Community College robbed of nearly $900k

#57
post #33
post #21

Earlier quoted context omitted.

On the other hand, I’m seeing more and more legitimate stuff land in Gmail’s spam filter. Like virtually of San Francisco Marathon’s newsletters. Sure they’re pushy and really really want you to sign up for more races and I definitely need to unsubscribe … but I did subscribe and that means it isn’t spam.

One of the things that I assume happens is that, even when people have explicitly signed up for something or at least not opted out of receiving updates etc., they'll just "report spam" rather than unsubscribe and when enough people do this it gets put in everyone's spam folder unless enough people reclassify it. There's not much stuff that ends up in my spam folder that I really care about and a fair bit I don't kno…

> they'll just "report spam" rather than unsubscribe

I'm guessing this is a major part of it. But then again, if a legitimate service is so spammy that people will just "report as spam" rather than unsubscribing, maybe they should change their behavior.

Re: Ozarks Technical Community College robbed of nearly $900k

#58
post #43

Naive question, but why can't banks undo a fraudulent transaction? Is there no such framework in place?

The scammers typically recruit fall guys to open accounts to receive the funds by offering them some small portion of the take. Along with a story about it being a favor , like "I'm from outside the country and don't have a bank account to receive my recent inheritance, etc" . With perhaps some intermediate transfers to other fall guys if it's a large amount. The funds are withdrawn in sub $10k chunks by the fall guy…

It happens across multiple chains of "fall guys" accounts making reversing very difficult.

Re: Ozarks Technical Community College robbed of nearly $900k

#59

> "Although the blame for this incident rests squarely on the criminals who committed this act“ Hm, and the inadequate financial controls structure of the college.

Right but when there is a victim its because someone did an illegal or victim creating action.

We don't blame the victim for the success rate of the perpetrator, because it was still up to the perpetrator to do the action to create the victim.

I’m curious about the details here, like if they swapped out wire details in the system or made a whole bank account in the vendors name etc

Re: Ozarks Technical Community College robbed of nearly $900k

#60
post #52
post #49

Earlier quoted context omitted.

Privacy does not mean anonymous interaction with known parties. It means the CIA can’t see me make an account transfer over the wire. In other words, without a warrant. Authentication and privacy are compatible. Privacy and anonymity are orthogonal.

The CIA can and will monitor your offline and online behavior if your profile is interesting to them. No amount of "muh privacy" appeals will stop them. Privacy and anonymity are absolutely not orthogonal. How do you KYC? By "violating" their privacy (storing and querying personal records) to identify (deanonymize) someone.

> The CIA can and will monitor your offline and online behavior if your profile is interesting to them.

That’s because we don’t have adequate privacy safeguards in modern western society.

> Privacy and anonymity are absolutely not orthogonal.

Privacy and anonymity are not synonymous. I can have a private conversation with a friend. That does not require anonymity. In fact it precludes anonymity because my friend and I know who each other are. Privacy says nobody else knows what we discussed or even that we had a conversation.

> KYC?

Know Your Client? This is a new term to me but sounds like an authentication concept. Which is compatible with privacy but precludes anonymity, by definition.

Post reply on HN