Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

141–150 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#141
post #15

* About 20% of the users have good graphic cards, but are not sophisticated enough to install drivers. * 30% of victims are Americans. * 80% have an antivirus installed. * An average income of $40 per day (bitcoin only). May vary up to $1,000.

> About 20% of the users have good graphic cards, but are not sophisticated enough to install drivers, so my [Bitcoin] miner can't run.

If he has root-level control of the systems, why doesn't he install the needed drivers himself?

Somebody already asked him this question on reddit, but he didn't answer.

Does anyone have any idea why he wouldn't/couldn't/shouldn't install drivers himself?

Re: IAmA a malware coder and botnet operator, AMA

#142
post #110

Earlier quoted context omitted.

I think the idea of a pin at checkout is a good one to reduce fraud. However this is more work for the consumer, and reduces the bank's liability. Most consumers would probably prefer this, as it makes their card more secure and reduces the possibility of fraud hassles, which are annoying regardless of liability. Having something that is more work for the consumer and could save the bank money switch the liability to…

> I think the idea of a pin at checkout is a good one to reduce fraud. For in-person transactions, merchants can check your signature against the one on the card or alternatively ask to see a photo ID. The process is there, though it's hardly ever done.

Given the fact that your signature is on the card, this seem rather ineffective. Approximate signatures are easy to forge and no merchant will deny a transaction based on a different signature.

In fact, that is not the purpose of your signature. The purpose is that you are signing a contract and agreeing to pay. It has nothing to do with security or fraud and merchants are not supposed to check signature matches - only that you signed.

A smiley face is a valid signature, as long as it is you and you agree to the credit card contract.

Re: IAmA a malware coder and botnet operator, AMA

#143
post #34
post #18

Earlier quoted context omitted.

For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.

He is using Tor, which gets a lot of criticism for not being secure but actually defeats Syrian or Chinese governments. If the US can track a hidden service in Tor, they will probably not waste this trump by catching such a small fish.

You don't need to crack Tor for that. Get the list of Germans hanging out on Anonymous IRC. Choose only college students. Remove ones that don't have time to do this stuff due to actually working somewhere. Intersect with HBCI users in banks where there aren't many of those. Remove Mac users and Linux users (he mentions he only uses Windows). Remove families that use credit cards (he mentions his family does not). This would already probably end up in reasonably short list. Now amending this list with various other bits of info he left - such as which sites he frequents, which drinks he prefers, which software he uses, etc. I don't believe it should pose any major challenge for a law enforcement agency, even if part of the info is lies - they are used to legwork and assembling small pieces. But probably with his size nobody would bother unless he does something major (i.e. catching him generates a big press-release) or he just hands himself to law enforcement by doing something stupid like drinking too much and bragging about being elite haxor criminal to a female undercover officer. If he just does it for a year and then stops, he has good chances to get away with it, but not because of mighty Tor, but because the law enforcement would never notice him.

Re: IAmA a malware coder and botnet operator, AMA

#144
post #8

Earlier quoted context omitted.

Credit card fraud is actually a fairly small problem in the US. Wikipedia tells me that the total cost of fraud is 0.07% of the transaction value. And I suspect (without evidence) that the bulk of this is made up of remote purchases, not swiped activity. Really, the chip things are an example of security theater. Yes, they're more "secure" in the sense of being harder to defeat. No, they're probably not actually wort…

It's not fair to just look at it in terms of the cost of fraud vs. profit. Consumers whose CC info is stolen aren't liable for fraudulent charges but it can still be very expensive and time-consuming for them to correct everything, not to mention the affect it can have on a credit score. And obviously, the consumers don't get any say in whether the costs to upgrade the infrastructure are worth it.

> Consumers whose CC info is stolen aren't liable for fraudulent charges

That's only if the credit card company believes or accepts your story.

I once reserved a flight by telephone using a credit card, but at the airport I paid for the flight with cash. Later I found that my credit card was charged for the flight. The airline said that they couldn't find any evidence that I had paid in cash, and even though their policy was to get a signature when paying by credit card, they could not produce my signature. But they still insisted that I had paid by credit card.

I complained to the credit card issuer, but they took the airline's word (United Airlines, by the way) over mine.

It's not enough that charges are fraudulent -- if the merchant is mistaken in their belief (or lying), you are on the hook!

Re: IAmA a malware coder and botnet operator, AMA

#145
post #69
post #21

Great nugget: > a US credit card costs 2$ on the black market and a UK starts at 60$, americans are all in debt.

It's because you can't do a charge-back with a UK card and get your money back.

Unless charge-back means something different to what I think it does, of course you can with a UK card. The terms and conditions may be different, but the usual fraud etc. is covered.

Re: IAmA a malware coder and botnet operator, AMA

#146
post #43
post #32

Earlier quoted context omitted.

As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue late…

I'm not familiar with this service. What is the advantage to the consumer in exchange for losing their fraud liability protection?

None really. A) Fraud liability effectively shifts to you, versus the often waived $50 limit, and B) it interjects an authorisation from your issuing bank into the checkout process oftentimes screwing it up.

Re: IAmA a malware coder and botnet operator, AMA

#147
post #110

Earlier quoted context omitted.

It sounds like in principle it might also reduce fraud overall. Thus, maybe 80% of the fraud goes away and 20% remains, but that liability is shifted to the consumer rather than the bank (who otherwise passes it to the merchant anyway). If the merchant has reduced fraud liability, they may be able to offer lower prices. So, in principle there might be a long-term win for the consumer. In practice, who knows.

I think the idea of a pin at checkout is a good one to reduce fraud. However this is more work for the consumer, and reduces the bank's liability. Most consumers would probably prefer this, as it makes their card more secure and reduces the possibility of fraud hassles, which are annoying regardless of liability. Having something that is more work for the consumer and could save the bank money switch the liability to…

There is now Chip and pin fraud. With chip and pin the liability is now on the consumer to prove it wasn't their transaction. Customers have had to take the banks to court in the UK to get fraud losses removed. In these cases it has been proven that Chip and pin is infallible. Same applies online with 3-D secure.

Re: IAmA a malware coder and botnet operator, AMA

#148

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

VBV (or 3D secure as it is called today) is part of a move by the credit card companies and the banks to push the risk to the most vulnerable party, the consumer. The idea is that this absolutely crack proof scheme requires you to authenticate yourself to your bank in a fairly complex three way handshake. In the old (read pre-VBV) days the card companies and issuing banks would saddle the merchants with any charges t…

> VBV is supposedly hack-proof

Something very strange I noticed with Verified by Visa and with Mastercard Secure Code is that both sometimes forget that you have already enrolled and make you re-enroll (i.e., answer their weak "security questions", like date of birth, and then choose a password).

It happened once with Verified by Visa and twice with Mastercard Secure Code so far. (No, my card numbers had not changed.)

These systems can't be trusted to even reliably remember my previous password.

Re: IAmA a malware coder and botnet operator, AMA

#149
post #15

* About 20% of the users have good graphic cards, but are not sophisticated enough to install drivers. * 30% of victims are Americans. * 80% have an antivirus installed. * An average income of $40 per day (bitcoin only). May vary up to $1,000.

> About 20% of the users have good graphic cards, but are not sophisticated enough to install drivers, so my [Bitcoin] miner can't run. If he has root-level control of the systems, why doesn't he install the needed drivers himself? Somebody already asked him this question on reddit, but he didn't answer. Does anyone have any idea why he wouldn't/couldn't/shouldn't install drivers himself?

Also, why not mine litecoins (cpu's are good at doing that, so no drivers needed and he can mine bitcoins at the same time) and sell them for bitcoins? They are worth enough that his profits would go up noticeably much.

Re: IAmA a malware coder and botnet operator, AMA

#150
post #79

Earlier quoted context omitted.

Every bit of bragging about himself makes it easier to find him. He has disclosed this information so far: * He tried to apply for a job at Kaspersky during last year. Didn't have enough credentials and still whines about it. * He hangs out on Anonymous IRC. * Uses Liberty Reserve. * Exchanges bitcoins to dollars (periodically I guess). * May be German-speaking. Understands Russian.

Not to mention, his block count on btcguild at a specified date.

Well, we can suppose all that is transmitted thru TOR and he never used any personal emails/old passwords/etc when signing up there, so that wont help us
Post reply on HN