Live data from Hacker News

Ozarks Technical Community College robbed of nearly $900k

bransontrilakesnews.com

61–70 of 88 posts

Re: Ozarks Technical Community College robbed of nearly $900k

#61
post #6

Earlier quoted context omitted.

EFTs are reversible but have much lower limits. To move this much money they probably used a bank wire. This can be reversible if you catch it in time. But wires happen so fast the thieves will surely transfer the money elsewhere before the originator even finds out.

Are the banks not liable, when they don't know there customer?

If it's a transfer using your authentication details they might put the transaction on hold or call you, but, no, they generally aren't liable with the processes they have in place unless there's significant negligence. The college might have been the one authorizing the transfer here to the wrong party. Banks can't or don't typically verify all of your vendors and clients and transactions. They provide the money pipes.

Re: Ozarks Technical Community College robbed of nearly $900k

#62
post #51

Earlier quoted context omitted.

This is a really upsidedown take. Spam was rampant prior to better safeguards around privacy, for one. It almost took down the internet iirc.

"Better safeguards around privacy"? How is Google or Cloudflare or NSA or whoever peeking at your incoming emails to determine what gets through good for "privacy"? That is upside down and backwards. Please explain.

E2e encryption to prevent that peaking didn't really debut until the 2000's, as that's right when the crypto wars ended. Spam was actively fought in 1990's, and then improved measurably into 2000. See projects like Hashcash in 1997, anti-spam tool.

So your premise doensn't make sense with that timeline. Right when consumer privacy measurably improved via encryption availability and the end of related legal challenges is right around the time spam improved as well.

Which is to say, there is no correlation that's logical b/t the two in my mind, but if anything the timeline invalidates privacy improvements -> worsening spam without more evidence.

Re: Ozarks Technical Community College robbed of nearly $900k

#64
post #2

“We can’t provide all of the specifics at this time,” Higdon said, “but it appears the criminals succeeded in impersonating one of our vendors online and directed payments from the college into a fraudulent account.” - so they sent a fake invoice and the college paid it?

They pretended to be the vendor and probably got the college to "update" vendor payment info to the fraudster's controlled account's details.

Re: Ozarks Technical Community College robbed of nearly $900k

#65
post #51

Earlier quoted context omitted.

This is a really upsidedown take. Spam was rampant prior to better safeguards around privacy, for one. It almost took down the internet iirc.

"Better safeguards around privacy"? How is Google or Cloudflare or NSA or whoever peeking at your incoming emails to determine what gets through good for "privacy"? That is upside down and backwards. Please explain.

Html enabled email can easily contain tracking. Even without JavaScript, you could insert an img tag pointing at a uniquely generated address and log the query...

It becomes a question of who you trust more: the service you've chosen for handling your email (and spam protection), or the people sending spam emails. If you don't trust your provider, you should find another provider.

Re: Ozarks Technical Community College robbed of nearly $900k

#66

I feel like spammers and cyber criminals are getting better. Stuff is starting to get through Google spam filter by mashing up with elements that seem very real and urgent. Like yesterday I got this spam in my Gmail primary inbox with a subject line like "RE: Department of Education Case #295720186". It made me wonder if you could autogenerate filter-evading spam using GANs? Train a GAN to generate email that fools a…

Its just different people disrupting the spam space. Someone looked at the operational assumptions of “lets target gullible people by using stupid obviously fraudulent scenarios so that we can weed out everyone who wont play along” and noticed it is missing a very large target market unnecessarily.

That almost sounds like an argument for why old school scammers are relatively ethical.

Re: Ozarks Technical Community College robbed of nearly $900k

#67
post #60
post #52

Earlier quoted context omitted.

The CIA can and will monitor your offline and online behavior if your profile is interesting to them. No amount of "muh privacy" appeals will stop them. Privacy and anonymity are absolutely not orthogonal. How do you KYC? By "violating" their privacy (storing and querying personal records) to identify (deanonymize) someone.

> The CIA can and will monitor your offline and online behavior if your profile is interesting to them. That’s because we don’t have adequate privacy safeguards in modern western society. > Privacy and anonymity are absolutely not orthogonal. Privacy and anonymity are not synonymous. I can have a private conversation with a friend. That does not require anonymity. In fact it precludes anonymity because my friend and…

Know Your Customer, a vital concept in financial services, which basically makes it much easier to track down and prevent money laundering and fraud.

Re: Ozarks Technical Community College robbed of nearly $900k

#68

Naive question, but why can't banks undo a fraudulent transaction? Is there no such framework in place?

They can undo. But if there's some Marty Byrde on the other side, there are ways of making the txn durable, not subject to undo.

Re: Ozarks Technical Community College robbed of nearly $900k

#69
post #60

Earlier quoted context omitted.

> The CIA can and will monitor your offline and online behavior if your profile is interesting to them. That’s because we don’t have adequate privacy safeguards in modern western society. > Privacy and anonymity are absolutely not orthogonal. Privacy and anonymity are not synonymous. I can have a private conversation with a friend. That does not require anonymity. In fact it precludes anonymity because my friend and…

Know Your Customer, a vital concept in financial services, which basically makes it much easier to track down and prevent money laundering and fraud.

I can privately communicate with my bank. But I cannot do so anonymously. LEO can’t see what I am doing on the wire. But with due process they can compel my bank to reveal what I have been doing with my money.

Re: Ozarks Technical Community College robbed of nearly $900k

#70
post #50
post #46

https://archive.ph/YtPLb The site is not available for European visiotrs due to legal reasons: >>> We recognize you are attempting to access this website from a country belonging to the European Economic Area (EEA) including the EU which enforces the General Data Protection Regulation (GDPR) and therefore access cannot be granted at this time.

For websites with specifically-American audiences, it can often be easier to only allow people from their intended readership access than to correctly understand and implement compliance to a foreign law. In this case, it's a local news website.

Why would a local news site care about GDPR compliance? It's not like enforcement is even feasible.
Post reply on HN