Earlier quoted context omitted.
You'd be surprised how many vendors and merchants simply do not care. I was employed with an e-commerce vendor that indefinitely stored CVV2 in plaintext (among other numbers).
When I see claims like this, why is it there's never any additional information about this company so I can avoid the hell out of it?
IAmA a malware coder and botnet operator, AMA
71–80 of 203 posts
Re: IAmA a malware coder and botnet operator, AMA
#72Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.
The user is liable if the card is stolen, and it is used to conduct fraud using the PIN code.
If the card is stolen, and the fraudster simply uses it online, or via some place that doesn't ask for a PIN, then you are not liable for that fraud.
I'm sure there are rare edge cases, but my experience with Barclays has always been very good in this regard.
Re: IAmA a malware coder and botnet operator, AMA
#73Well, clearly this guy's moral compass is a bit out of whack, but the IAmA does offer some fascinating insights into this world...
yea, the world is a weird place. seeing a lot of angry ethical reactions on reddit, i can't help but think: on one side, there are people like this guy in the comments who left marketing a health product due to false claims, or me refusing to code for certain clients based on "personal" ethical judgments and on the other side there are these "crackers" who steal the credit cards of random people and who even hate the…
You definitely can.
But whether or not you would want to is another thing.
Re: IAmA a malware coder and botnet operator, AMA
#74Earlier quoted context omitted.
They can't store the CVV2 either. Doing so, even encrypted, violates PCI-DSS.
So, if you don't care about violating the terms of PCI-DSS, you can store the CVV2/CVC/whatever. I bet lots of places do. In fact, I worked for a Visa Level-1 merchant that had a card processing system that used an Oracle DB table as a queue for outgoing authorization requests. The table held the CVV2/CVC/whatever for as long as it took to get an authorization or a timeout, whichever came first. We passed the PCI aud…
That company passed PCI-DSS because these were in-flight transactions, if that had been a historical database they would not have passed.
Re: IAmA a malware coder and botnet operator, AMA
#75Earlier quoted context omitted.
Ooohh.. so that's why those websites ask for it. Learn something new every day :S
Also, whether websites do or don't ask for it depends on their (and their merchant banking) risk appetite. Sometimes banks make it mandatory, sometimes not. It's not * required* to make a transaction, it merely offers an (optional) extra level of security.
Re: IAmA a malware coder and botnet operator, AMA
#76Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…
When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?
Re: IAmA a malware coder and botnet operator, AMA
#77Re: IAmA a malware coder and botnet operator, AMA
#78Earlier quoted context omitted.
For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.
He is using Tor, which gets a lot of criticism for not being secure but actually defeats Syrian or Chinese governments. If the US can track a hidden service in Tor, they will probably not waste this trump by catching such a small fish.
Re: IAmA a malware coder and botnet operator, AMA
#79Earlier quoted context omitted.
From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.
Every bit of bragging about himself makes it easier to find him. He has disclosed this information so far: * He tried to apply for a job at Kaspersky during last year. Didn't have enough credentials and still whines about it. * He hangs out on Anonymous IRC. * Uses Liberty Reserve. * Exchanges bitcoins to dollars (periodically I guess). * May be German-speaking. Understands Russian.
Re: IAmA a malware coder and botnet operator, AMA
#80Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.