Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

121–130 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#121

Earlier quoted context omitted.

yea, the world is a weird place. seeing a lot of angry ethical reactions on reddit, i can't help but think: on one side, there are people like this guy in the comments who left marketing a health product due to false claims, or me refusing to code for certain clients based on "personal" ethical judgments and on the other side there are these "crackers" who steal the credit cards of random people and who even hate the…

What is this I don't even.. It sounds like you're considering a life of crime. Probably thinking about how you could be like that botnet guy on Reddit. Getting money without working is a nice thought, after all. You know, the "ethical reactions" stem from that guy doing evil things. He knows he's being evil but doesn't care. Some people find that appalling. For him, it's just an easy way to make money, and the fact t…

The thing that most people don't realize is that it isn't as easy as most people think or how he makes it sound. It's very similar to building a passive income product. You invest a lot of work up front for an "easy" payout later.

It may only take him an hour or two a day to manage the network but I doubt that's all the time he spends on it. From reading the AMA and my own personal experience I bet this guy spends much of his time researching tools, improving his code, testing AV software, and browsing / contributing to "industry" forums. This isn't even taking into account the time he spent upfront before it made him any money.

It may be something he enjoys but it's not as easy as clicking a few buttons every day and watching the money pile up. It's sad to think that all this time could be spent building a legitimate product instead of something like this.

Re: IAmA a malware coder and botnet operator, AMA

#122
post #5

I don't understand how these people sleep at night. The whole notion I didn't make the game I just play the ball is just hilarious. Furthermore those guys don't understand that eventually they're hurting the web. All that will bring stricter legislation and governments will start enforcing rules like IP identification for just about anyone out there. I can understand organized crime exploiting the cyberspace. But for…

This is a big part of a lot of the talks I give about my criminal past. It's not like you wake up one day and decide to start committing fraud. It's a gradual, slippery slope. Humans can, will, and need to rationalize everything they do. As you slide down the slope the rationalization becomes, well, less rational. But you don't see it that way. If you did you wouldn't be able to do it.

Re: IAmA a malware coder and botnet operator, AMA

#123
post #97

Earlier quoted context omitted.

He is very familiar with the differences between C, C++ and C#. Are there any Germans that can comment of what kind of student would have that knowledge? I thought that advanced engineering the degrees in Germany are too academic for students to be familiar with the intimate details of programming, but I might be wrong.

He mentioned he's been learning programming for about a year or so.

He also stated that he was apparently "self-taught"

Re: IAmA a malware coder and botnet operator, AMA

#124
post #118
post #32

Earlier quoted context omitted.

As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue late…

The only merchant that I've ever seen this used at is Newegg and they make it mandatory for Visa.

does this mean i have more than $50 fraid liability if something goes south with my newegg purchase? if so- thus is a real reason not to risk doing business with them.

Re: IAmA a malware coder and botnet operator, AMA

#126

There's so many legal ways this guy could make just as much money with his skills. I never understood why someone is willing to put his freedom at risk when that is the case. I guess he's just lazy or thinks he's incapable of making as much as easily legally, maybe he likes the thrill and challenge of it all, maybe he thinks he's invincible and there's zero chance of him getting caught. Either way he's very foolish f…

I have read that in many criminal enterprises it is much like business, where grunts at the bottom have lower income and lots of hours, and most of the risk (exposure). I think this guy is a grunt, probably at the same level of structure of a 2 employee business. when i read through his comments i am struck with the impression that he has passivly attempted legit employment that use the skills he has learned but has not been sucessful yet. he probably has his initial goals set to high. if he starts at the bottom somewhere, given his supposed skill level he should be promoted quickly. just need to put in the time. if not patient enough, put that effort into consulting.

given the real return on his enterprise, i agree with your assesment that he can probably make much more with a real legitimate job and just avoid that risk altogether.

Re: IAmA a malware coder and botnet operator, AMA

#127
post #110

Earlier quoted context omitted.

It sounds like in principle it might also reduce fraud overall. Thus, maybe 80% of the fraud goes away and 20% remains, but that liability is shifted to the consumer rather than the bank (who otherwise passes it to the merchant anyway). If the merchant has reduced fraud liability, they may be able to offer lower prices. So, in principle there might be a long-term win for the consumer. In practice, who knows.

I think the idea of a pin at checkout is a good one to reduce fraud. However this is more work for the consumer, and reduces the bank's liability. Most consumers would probably prefer this, as it makes their card more secure and reduces the possibility of fraud hassles, which are annoying regardless of liability. Having something that is more work for the consumer and could save the bank money switch the liability to…

> I think the idea of a pin at checkout is a good one to reduce fraud.

For in-person transactions, merchants can check your signature against the one on the card or alternatively ask to see a photo ID. The process is there, though it's hardly ever done.

Re: IAmA a malware coder and botnet operator, AMA

#128

Earlier quoted context omitted.

What is this I don't even.. It sounds like you're considering a life of crime. Probably thinking about how you could be like that botnet guy on Reddit. Getting money without working is a nice thought, after all. You know, the "ethical reactions" stem from that guy doing evil things. He knows he's being evil but doesn't care. Some people find that appalling. For him, it's just an easy way to make money, and the fact t…

The thing that most people don't realize is that it isn't as easy as most people think or how he makes it sound. It's very similar to building a passive income product. You invest a lot of work up front for an "easy" payout later. It may only take him an hour or two a day to manage the network but I doubt that's all the time he spends on it. From reading the AMA and my own personal experience I bet this guy spends mu…

Wait until he gets those handcuffs on, then we'll talk about how high the investment in time really was.

Next up: I thought I was hot stuff, now I'm a convict, ask me anything.

Re: IAmA a malware coder and botnet operator, AMA

#129
post #124
post #118

Earlier quoted context omitted.

The only merchant that I've ever seen this used at is Newegg and they make it mandatory for Visa.

does this mean i have more than $50 fraid liability if something goes south with my newegg purchase? if so- thus is a real reason not to risk doing business with them.

Kind of sad, the last time I built a PC I had to have the hardware within 2 days. Newegg said the order went through and then the next day I got an e-mail to call and verify my order. I cancelled the order, found everything on Amazon for the same price and had it shipped overnight it.

I don't know how many times now I've gone to an e-commerce site and the stupid Mastercard-Securecode has popped up, or my order has been frozen for verification -- and I immediately go straight to Amazon. Perhaps the real beneficiary here is Amazon. They know my order history and they know when I order a $4000 TV to an address I been shipping $X amount of stuff to without incident.

Re: IAmA a malware coder and botnet operator, AMA

#130
post #3

Well, clearly this guy's moral compass is a bit out of whack, but the IAmA does offer some fascinating insights into this world...

yea, the world is a weird place. seeing a lot of angry ethical reactions on reddit, i can't help but think: on one side, there are people like this guy in the comments who left marketing a health product due to false claims, or me refusing to code for certain clients based on "personal" ethical judgments and on the other side there are these "crackers" who steal the credit cards of random people and who even hate the…

You can't build a (very good) future on crime, but you can build a future on being evil. There is a reason lawyers have a bad reputation.
Post reply on HN