Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

91–100 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#91
post #87

Earlier quoted context omitted.

He says he is Polish.

Polish nationals studying engineering in Germany should narrow it down quite a bit. Edit: definitely not a Pole. Likely in former Eastern Germany though (lots of people there have a working knowledge of Russian / Polish, people from the Western parts not so much). Universities in former Eastern Germany with an engineering department?

He is very familiar with the differences between C, C++ and C#. Are there any Germans that can comment of what kind of student would have that knowledge? I thought that advanced engineering the degrees in Germany are too academic for students to be familiar with the intimate details of programming, but I might be wrong.

Re: IAmA a malware coder and botnet operator, AMA

#92
post #87

Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.

He says he is Polish.

A commenter on Reddit points out "I'm Polish and that's not how a Pole would spell Russian words. He's German."

Re: IAmA a malware coder and botnet operator, AMA

#93
post #49

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?

Paypal.

Re: IAmA a malware coder and botnet operator, AMA

#94
post #47
post #43

Earlier quoted context omitted.

I'm not familiar with this service. What is the advantage to the consumer in exchange for losing their fraud liability protection?

Nothing. This 'feature' is entirely designed to reduce the banks' liability. It shifts the onus of security onto you (from the banks and the merchants).

It sounds like in principle it might also reduce fraud overall. Thus, maybe 80% of the fraud goes away and 20% remains, but that liability is shifted to the consumer rather than the bank (who otherwise passes it to the merchant anyway). If the merchant has reduced fraud liability, they may be able to offer lower prices. So, in principle there might be a long-term win for the consumer. In practice, who knows.

Re: IAmA a malware coder and botnet operator, AMA

#95
post #63

Earlier quoted context omitted.

You're missing the point entirely. I'm not saying that chip & pin has no value. I'm saying that the value it has is finite (i.e. it saves money equal to the amount of fraud it eliminates) and needs to be weight against the cost of replacing all the card reader infrastructure. And I argue that the fact the US has not upgraded is an existence proof that the upgrade cost[1] outweighs the savings. [1] Really the amortize…

"cost of replacing all the card reader infrastructure" I'm not sure how many PoS are already equipped to deal with chip cards. In the USA/Canada it's hit or miss (most misses), and in Europe it was the standard 10 years ago (but most readers take swipe cards). Replacing cards is cheap and they can be replaced as they expire What would be the upgrade cost for each PoS? $100? Some systems are more integrated than other…

My previous U.S. card had a chip. The very recent replacement came without one.

So they aren't really moving in the direction of issuing cards with chips. I never actually encountered a situation where I was aware I could use the chip, over 5 years or whatever it was.

Re: IAmA a malware coder and botnet operator, AMA

#96
post #8

Magnetic stripes are the most hilarious thing ever, but still work almost everywhere on the globe. I am amazed that magnetic stripes are still the norm for credit cards in the US. Europe has managed to move all but completely to chip-based cards, but the US hasn't. Does the cost of fraud due to magnetic stripes outweigh the cost to upgrade the entire US system, or is the market just too fragmented to coordinate such…

Credit card fraud is actually a fairly small problem in the US. Wikipedia tells me that the total cost of fraud is 0.07% of the transaction value. And I suspect (without evidence) that the bulk of this is made up of remote purchases, not swiped activity. Really, the chip things are an example of security theater. Yes, they're more "secure" in the sense of being harder to defeat. No, they're probably not actually wort…

Try to find the value of all swiped CC transactions. Then take 0.07% of that number. I'm guessing you'll be hard pressed to call the result "fairly small".

Re: IAmA a malware coder and botnet operator, AMA

#97

Earlier quoted context omitted.

Polish nationals studying engineering in Germany should narrow it down quite a bit. Edit: definitely not a Pole. Likely in former Eastern Germany though (lots of people there have a working knowledge of Russian / Polish, people from the Western parts not so much). Universities in former Eastern Germany with an engineering department?

He is very familiar with the differences between C, C++ and C#. Are there any Germans that can comment of what kind of student would have that knowledge? I thought that advanced engineering the degrees in Germany are too academic for students to be familiar with the intimate details of programming, but I might be wrong.

He mentioned he's been learning programming for about a year or so.

Re: IAmA a malware coder and botnet operator, AMA

#98
post #49

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?

I've had certain websites require VbV for purchases. I can only assume the transaction fees are lower for such transactions, or they got some kind of other deal from their merchant bank.

The worst part is the information required for the "I forgot my password" process is often not terribly hard to get hold of (date of birth, that kind of thing).

The best option at this stage is probably to have a "normal" credit card for everyday use which is specifically NOT VbV enabled, and a special VbV credit card that you keep at home for internet purchases from companies that require it. Or just don't buy from those companies.

Re: IAmA a malware coder and botnet operator, AMA

#99
post #49

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?

Use AmEx.

Re: IAmA a malware coder and botnet operator, AMA

#100

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

I've only used VbV once or twice, years ago. Do they still use iframes? I've never understood why they try to make the site more "secure" by using these services, but then use an iframe so the average user can't easily confirm if the login screen is legit or not.
Post reply on HN