Live data from Hacker News

Tech CEO sentenced to 5 years in IP address scheme

krebsonsecurity.com

111–120 of 311 posts

Re: Tech CEO sentenced to 5 years in IP address scheme

#111

The underlying crime was wire fraud, and it happened to be about acquiring IP addresses. He wasn’t prosecuted because he got too many, but for how he got them.

Get out of here with your facts. I want to live in a world where I can believe an individual will get hard time for acquiring too many IP addresses.

Re: Tech CEO sentenced to 5 years in IP address scheme

#113

The underlying crime was wire fraud, and it happened to be about acquiring IP addresses. He wasn’t prosecuted because he got too many, but for how he got them.

> The underlying crime was wire fraud

The other crime was looking like a douche canoe for his profile pic - https://krebsonsecurity.com/wp-content/uploads/2019/08/amirg...

Re: Tech CEO sentenced to 5 years in IP address scheme

#114

The underlying crime was wire fraud, and it happened to be about acquiring IP addresses. He wasn’t prosecuted because he got too many, but for how he got them.

> The underlying crime was wire fraud The other crime was looking like a douche canoe for his profile pic - https://krebsonsecurity.com/wp-content/uploads/2019/08/amirg...

"The prosecution would like to present Exhibit A..."

Re: Tech CEO sentenced to 5 years in IP address scheme

#115
post #109

Earlier quoted context omitted.

> law enforcement agents would require cause (warrant? subpoena? IANAL) to obtain the records, right? No. If I took you to arbitration and think you acted illegally, I can send the case documents to law enforcement. Most people don't do this, because it's a hassle. But if you pissed me off or were morally offensive, hell yes I'm doing it. After that, yes, they need to execute searches to follow up on the information.

> If I took you to arbitration and think you acted illegally, I can send the case documents to law enforcement. Only if the terms of arbitration allow you to share said documents.

There aren't any terms of arbitration that can prevent you from sharing evidence of a criminal conspiracy with the police.

An NDA cannot stop you from reporting criminal conduct. You can be sued by the criminal for doing so, but this is America, you can be sued for anything by anyone. It doesn't mean that they'll win (And will look a hell of a lot like witness intimidation in their criminal trial.)

Re: Tech CEO sentenced to 5 years in IP address scheme

#116
post #21

The underlying crime was wire fraud, and it happened to be about acquiring IP addresses. He wasn’t prosecuted because he got too many, but for how he got them.

IPv4 addresses are like Socks. You can never have too many...

Back around the turn of the millennium, there was a company called AllAdvantage. They paid you to install spyware/ad injection software and watch you browse, and sold the add space and analytics to corporations. They'd pay you for... I think it was 48 hours of ad-injected spied browsing per month, and then stop paying you (but keep injecting ads and spying on you). There was also a pyramid aspect where you'd get something like 10% of all of the amount earned by your direct referrals, with no monthly cap. Also, 48 hours of browsing wasn't enough to hit their minimum threshold for AllAdvantage to mail you a cheque.

Edit: maybe there wasn't actually spyware and it just injected extra banner ads in your browsing. I never looked into installing it myself.

A /16 subnet was routed to our fraternity house, licensed to house up to 22 people. 65,536 (minus broadcast, gateway, and network address) IPv4 addresses for 22 people. My roommate bought 1 GB of RAM (about $4k at the time) and a VMWare student license for his Linux desktop. He cut down Win95 to be able to run in 32 MB of RAM (including his COM scripting bot, Internet Explorer, and the AllAdvantage spyware). I seem to remember him configuring the VMs to run 16-bit color to save memory footprint. He scripted the Win95 boot process to read a CSV file off of NFS, remove the top line, and write the file back. The CSV file contained fake name, fake address, etc. The VM would register itself with AllAdvantage, with my roommate as the referrer, and then randomly click on links in Internet Explorer until hitting the payout limit, and then shut down the VM. A Perl script (remember the late 90s?) on the Linux host would re-launch a clean VM every time an old VM shut down, and keep the CSV populated with fake account details.

30 VMs were browsing 24x7 for ALlAdvantage. My roommate set up a caching proxy on his Linux box, so he didn't hose the house's T1 connection. 10% of the payout (the referral fees) over something like 4-5 months paid for the whole desktop. AllAdvantage never got returned cheques from the fake addresses because they never paid out. I think he ran his system for over a year before AllAdvantage went out of business, for a total of something like $12k in profit.

He ran his own DNS server that hopped randomly all over the /16 to reduce the probability of detection. He's pretty convinced AllAdvantage's fraud people noticed him as an extreme outlier. He suspects they ignored him because the data he was generating for them cost 1/11th as much as most of the other data they were selling to customers.

Edit: a quick search shows the AllAdvantage rate was maybe $0.40/hr. 10% of this was $0.04 x 30 VMs = $1.20/hr 24x7. 8766 hours/year works out to about $10,000 per year. $12k in profit, $4k in RAM, and $1k for the rest of the machine works out to a bit under 2 years of running the system, if the rest of my memory is roughly accurate.

A few years later, our school kept the /16 allocated to us, but only routed the first /24 to the house. I'm sure my roommate wasn't the only one to get up to shenanigans with so many IP addresses.

Edit: He also found some online casinos that didn't explicitly forbid bots and he set up some poker bots that would keep track of its winning percentages against all other players. He set up some monitoring/control software for his feature phone (or was it a PDA?) so he could watch his losses from class and shut it down if necessary.

He kept records of every card seen in every game his bots played. I asked on at least 3 occasions for access to that data, to check for (1) naive shuffling (2) using a linear congruential generator instead of cryptographic quality random numbers and (3) seeding with time instead of a true random seed. He told me at least 3 times that he would give me FTP access to card histories, but never did. A couple years later, a paper came out detailing a code review of the most common online poker software finding (1) naive shuffling (2) using a linear congruential generator (3) seeded using only the time the game started and (4) containing an off-by-one error in the naive shuffle. The off-by-one error might have prevented me from figuring it all out from the poker bot histories, but there's some alternate history where we made millions in online poker, fully within the published rules of the sites. (Unfortunately, the millions would have come entirely from other players, the online casinos not bearing any of the costs of the shoddy coding.)

He mused several times that it would be fun to create a cardboard box with one of those see-through windows for a shipping label... and two subtle slits allowing a continuous roll of various shipping addresses and an advancement mechanism to be hidden within the package. He'd use a battery and/or inertial energy harvesting weight to power a device to change the sipping address every 4 hours. He wanted to send such a package with tracking information and watch it ping-pong around the country until someone realized something was fishy with the package.

He eventually dropped out of school and was living off of his poker bots until (without health insurance) his appendix burst and he was forced to get a day job to pay off his medical debt.

I hope he gets elected to Congress someday (though he's not very political) just to make a great epilogue to a biographical film.

Re: Tech CEO sentenced to 5 years in IP address scheme

#117
post #39

The underlying crime was wire fraud, and it happened to be about acquiring IP addresses. He wasn’t prosecuted because he got too many, but for how he got them.

Yep. If he had real people or real companies buying these IP addresses (even if they are shell companies) he would be fine. Apparently he started like that but then he got greedy and said: fuck I will just invent some fake people. The actual criminal activity (fradulent affidavits, forged signatures) started in 2017.

I worked for a dial-up ISP that was going out of business and their last hurrah was selling renting servers doling out clean IPs from their /16 blocks so the clients could spam like crazy.

Then we encountered these spammers were willing to forge BGP LOA stating that they could announce certain, defunct and unused blocks on BGP.

I left there in a hurry, but it seems like they got away with it for a while. It would've been pretty catastrophic if their upstream ISPs decided to cut them off because they were announcing blocks they should not have been.

Re: Tech CEO sentenced to 5 years in IP address scheme

#118
post #105

Earlier quoted context omitted.

Wire fraud, wire fraud, it's nearly always wire fraud. Elizabeth Holmes, George Santos, Charlie Javice, all the people who got fake Covid funds - wire fraud, wire fraud, wire fraud. In this day and age if you're committing fraud it's pretty hard for it not to be wire fraud given how everything is transmitted digitally. And penalties for wire fraud are extremely steep (up 20 years for each charge), and it automaticall…

If he had used e.g. the USPS mail service, would it then have been mail fraud instead? Similar sentencing?

Yes. Also, you do not want the Postal Inspectors showing up looking for you. Like, for real.

Re: Tech CEO sentenced to 5 years in IP address scheme

#119

Earlier quoted context omitted.

I guess you missed this part: > Prosecutors showed that each of those shell companies involved the production of notarized affidavits in the names of people who didn’t exist.

No I didn't. I'm wondering how putting someone that is arguably a smart entrepreneur behind jail for 5 year is going to better our society. We need to think about the bigger picture and how this fits into rehabilitation.

I'm all for rehabilitation, but the serious amount of criminal energy that went into this scheme would have been better spent building something useful. A thought clearly lost on this individual. Furthermore, he used his ill-gotten IP addresses to house spammers, which was actively causing harm beyond just hoarding addresses.

Re: Tech CEO sentenced to 5 years in IP address scheme

#120
post #105

Earlier quoted context omitted.

If he had used e.g. the USPS mail service, would it then have been mail fraud instead? Similar sentencing?

Yes. Also, you do not want the Postal Inspectors showing up looking for you. Like, for real.

Story time? What makes Postal Inspectors so feared.
Post reply on HN