Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

11–20 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#12

Magnetic stripes are the most hilarious thing ever, but still work almost everywhere on the globe. I am amazed that magnetic stripes are still the norm for credit cards in the US. Europe has managed to move all but completely to chip-based cards, but the US hasn't. Does the cost of fraud due to magnetic stripes outweigh the cost to upgrade the entire US system, or is the market just too fragmented to coordinate such…

The whole chip and pin thing is pointless though, my company credit card gets used by plenty of people who don't know the PIN thanks to online/phone purchases, and in the past when I've forgotten a PIN, or just got a new card which I haven't yet received a PIN for, I've had no problem persuading shops to let me swipe them (magnetic strip) and sign for it instead.

Re: IAmA a malware coder and botnet operator, AMA

#14

The fact that this guy even posted an AMA shows that it's either entirely fake (doesn't seem it), or he's way too cocky. I suspect some trouble may be coming his way soon. He seems to think that he's infallible and that he won't catch a charge for running a botnet.

From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.

Re: IAmA a malware coder and botnet operator, AMA

#16

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.

Re: IAmA a malware coder and botnet operator, AMA

#17

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

at least for mastercard this is true: as per my banks tos i have to take care that nobody gains access my 'securecode' and i am liable for any unauthorized charges. (because the 'securecode' is supposed to guarantee that it is me who is using the card)

Re: IAmA a malware coder and botnet operator, AMA

#18
post #14

The fact that this guy even posted an AMA shows that it's either entirely fake (doesn't seem it), or he's way too cocky. I suspect some trouble may be coming his way soon. He seems to think that he's infallible and that he won't catch a charge for running a botnet.

From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.

For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.

Re: IAmA a malware coder and botnet operator, AMA

#19

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.

Richard Clayton (etc) have lots of interesting stuff about bank security (and the lack of) - they've attacked chip and pin, which means that if someone does manage to defraud the card the owner might have some chance of getting the cash back.

Re: IAmA a malware coder and botnet operator, AMA

#20

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

> Does anyone know if this (using verified-by-visa, mastercard-securecode remove any payment protection if you get key-logged etc) is correct?

Yes. It's the whole point of the system, to remove even more risk from the CC companies and banks, and put it on you.

Post reply on HN