Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

131–140 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#131
post #129
post #124

Earlier quoted context omitted.

does this mean i have more than $50 fraid liability if something goes south with my newegg purchase? if so- thus is a real reason not to risk doing business with them.

Kind of sad, the last time I built a PC I had to have the hardware within 2 days. Newegg said the order went through and then the next day I got an e-mail to call and verify my order. I cancelled the order, found everything on Amazon for the same price and had it shipped overnight it. I don't know how many times now I've gone to an e-commerce site and the stupid Mastercard-Securecode has popped up, or my order has be…

same thing happened to me. on a whim, i wanted a very specific poster. i went to order it from the first place i found it and then had trouble on the order enty. after 10 minites of frustration i decided to check amazon, and found it cheaper and with free shipping, as im on prime. amazon really is the walmart of the web. my last newegg purchase was split as many of the pieces were cheaper on amazon, and i have more trust in them.

Re: IAmA a malware coder and botnet operator, AMA

#132

Earlier quoted context omitted.

The thing that most people don't realize is that it isn't as easy as most people think or how he makes it sound. It's very similar to building a passive income product. You invest a lot of work up front for an "easy" payout later. It may only take him an hour or two a day to manage the network but I doubt that's all the time he spends on it. From reading the AMA and my own personal experience I bet this guy spends mu…

Wait until he gets those handcuffs on, then we'll talk about how high the investment in time really was. Next up: I thought I was hot stuff, now I'm a convict, ask me anything.

I think your faith in the justice system (especially considering the technical nature of this redditor's activities) is unfounded.

Re: IAmA a malware coder and botnet operator, AMA

#133
post #129
post #124

Earlier quoted context omitted.

does this mean i have more than $50 fraid liability if something goes south with my newegg purchase? if so- thus is a real reason not to risk doing business with them.

Kind of sad, the last time I built a PC I had to have the hardware within 2 days. Newegg said the order went through and then the next day I got an e-mail to call and verify my order. I cancelled the order, found everything on Amazon for the same price and had it shipped overnight it. I don't know how many times now I've gone to an e-commerce site and the stupid Mastercard-Securecode has popped up, or my order has be…

I've also shifted all my business from newegg to amazon for that reason and also this one: newegg's packing is horrible. What am I supposed to do with an enormous pile of packing peanuts from the box that's three times larger than it needs to be? If you want to collapse the box, good luck pouring all those peanuts into a garbage bag without getting them everywhere. And if you don't have access to a dumpster, you get to waste a ton of space in your garbage can.

With amazon, you get to stab the air bubbles with a knife and wad them up.

Also, reliable ship times are neat.

Re: IAmA a malware coder and botnet operator, AMA

#134
post #15

* About 20% of the users have good graphic cards, but are not sophisticated enough to install drivers. * 30% of victims are Americans. * 80% have an antivirus installed. * An average income of $40 per day (bitcoin only). May vary up to $1,000.

$40 per day is weak. Less than California minimum wage. And the risks are considerable. Reminds of the work of Sudhir Venkatesh who found that average wage for drug dealing grunt is about $3.30/hr - not far from what we're seeing here, though at least bot herder doesn't risk being shot. He is right that this thing has no future for him.

Re: IAmA a malware coder and botnet operator, AMA

#135

Earlier quoted context omitted.

Verified by Visa is a fucking joke. In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net . If that's not by the book appearance of a phishing site, I don't know what is.

Really? Because SecureServer.net is a domain used in GoDaddy's webmail: https://login.secureserver.net/

I typed it from memory, so it might be off. Regardless though - the URL had "secure" and "server" in it, but no "visa".

Re: IAmA a malware coder and botnet operator, AMA

#136
post #63

Earlier quoted context omitted.

"Really, the chip things are an example of security theater. Yes, they're more "secure" in the sense of being harder to defeat" Absolutely not! In the US fraud may be small (but it's increasing). But magnetic stripes are very unsafe Chip'n'Pin may have some issues, but it's much safer to most common attacks such as - card stripers (very inconspicuous) - physical theft of the card (because it requires a pin) And, as s…

You're missing the point entirely. I'm not saying that chip & pin has no value. I'm saying that the value it has is finite (i.e. it saves money equal to the amount of fraud it eliminates) and needs to be weight against the cost of replacing all the card reader infrastructure. And I argue that the fact the US has not upgraded is an existence proof that the upgrade cost[1] outweighs the savings. [1] Really the amortize…

The fact that the US has not upgraded is not an existence proof, it's simply one piece of supporting evidence. There are other possible reasons why the upgrade hasn't happened even if it makes overall economic sense - perhaps the cost of fraud and the cost of upgrades aren't borne by the same actors; perhaps there's some kind of game theoretic problem like a first mover disadvantage; perhaps the actors aren't acting entirely rationally.

It seems like the upgrade of terminal equipment could be done quite cheaply if it was done as part of the regular cycle of equipment refresh, for example.

Re: IAmA a malware coder and botnet operator, AMA

#137
post #33

Earlier quoted context omitted.

Also, whether websites do or don't ask for it depends on their (and their merchant banking) risk appetite. Sometimes banks make it mandatory, sometimes not. It's not * required* to make a transaction, it merely offers an (optional) extra level of security.

Banks can also charge different amounts to the retailer depending on the level of security they provide.

Yup, correct. 3D Secure falls into this category too.

Also, the banks will offer differing levels of chargeback cover based on these factors.

Re: IAmA a malware coder and botnet operator, AMA

#138

Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.

He also mentioned that he frequents or used to frequent the forums at http://www.opensc.ws/

Re: IAmA a malware coder and botnet operator, AMA

#139

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

Verified by Visa is a fucking joke. In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net . If that's not by the book appearance of a phishing site, I don't know what is.

It's actually https://www.securesuite.net.

I very suspicious of that the first time I was subjected to Verified by Visa.

The other thing that infuriated me about Verified by Visa is that when you are forced to sign up for it, it thanks you for choosing to sign up. The only choice I had was to sign up or not make the transaction!

Re: IAmA a malware coder and botnet operator, AMA

#140
post #48

Earlier quoted context omitted.

> linux won't help ? He says Linux does help.

but he says, only because it is not much common, and different distros are too diverse to justify an "investment"

Surely Linux would be a good target? There are hundreds of thousands of Linux servers out there and they will have a lot of bandwidth / CPU etc.
Post reply on HN