Earlier quoted context omitted.
He is using Tor, which gets a lot of criticism for not being secure but actually defeats Syrian or Chinese governments. If the US can track a hidden service in Tor, they will probably not waste this trump by catching such a small fish.
You don't need to crack Tor for that. Get the list of Germans hanging out on Anonymous IRC. Choose only college students. Remove ones that don't have time to do this stuff due to actually working somewhere. Intersect with HBCI users in banks where there aren't many of those. Remove Mac users and Linux users (he mentions he only uses Windows). Remove families that use credit cards (he mentions his family does not). Th…
IAmA a malware coder and botnet operator, AMA
151–160 of 203 posts
Re: IAmA a malware coder and botnet operator, AMA
#152Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.
oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…
Re: IAmA a malware coder and botnet operator, AMA
#153Earlier quoted context omitted.
> I think the idea of a pin at checkout is a good one to reduce fraud. For in-person transactions, merchants can check your signature against the one on the card or alternatively ask to see a photo ID. The process is there, though it's hardly ever done.
Given the fact that your signature is on the card, this seem rather ineffective. Approximate signatures are easy to forge and no merchant will deny a transaction based on a different signature. In fact, that is not the purpose of your signature. The purpose is that you are signing a contract and agreeing to pay. It has nothing to do with security or fraud and merchants are not supposed to check signature matches - on…
My point in bringing up the signature line on the back of the card is that, while it might not meet your personal standard of effectiveness, it is an example of "a pin at checkout is a good one to reduce fraud. However it is more work for the consumer, and reduces the bank's liability." Signature verification is an old-fashioned, and perhaps imperfect, nonetheless established method of security.
If you have ever used traveler's checks, you will know that they also use signature-matching as the method of security/verification.
[1] http://www.npr.org/templates/story/story.php?storyId=9227832... [2] http://minnesota.cbslocal.com/2012/02/14/good-question-why-d...
Re: IAmA a malware coder and botnet operator, AMA
#154Earlier quoted context omitted.
yea, the world is a weird place. seeing a lot of angry ethical reactions on reddit, i can't help but think: on one side, there are people like this guy in the comments who left marketing a health product due to false claims, or me refusing to code for certain clients based on "personal" ethical judgments and on the other side there are these "crackers" who steal the credit cards of random people and who even hate the…
What is this I don't even.. It sounds like you're considering a life of crime. Probably thinking about how you could be like that botnet guy on Reddit. Getting money without working is a nice thought, after all. You know, the "ethical reactions" stem from that guy doing evil things. He knows he's being evil but doesn't care. Some people find that appalling. For him, it's just an easy way to make money, and the fact t…
In the past I've left well paid positions out of moral issues, in different industries. For instance, when my algorithms were getting patented, or I was increasingly made to work in .NET.
People have different views. However, stealing CCs and massively screwing over random people... you cannot possibly put that in the same breadth.
Re: IAmA a malware coder and botnet operator, AMA
#155Earlier quoted context omitted.
Wait until he gets those handcuffs on, then we'll talk about how high the investment in time really was. Next up: I thought I was hot stuff, now I'm a convict, ask me anything.
I think your faith in the justice system (especially considering the technical nature of this redditor's activities) is unfounded.
Re: IAmA a malware coder and botnet operator, AMA
#156Earlier quoted context omitted.
oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…
Most German banks have been providing HBCI for over a decade, so that doesn't really narrow it down.
He's probably lying too.
Re: IAmA a malware coder and botnet operator, AMA
#157Earlier quoted context omitted.
What is this I don't even.. It sounds like you're considering a life of crime. Probably thinking about how you could be like that botnet guy on Reddit. Getting money without working is a nice thought, after all. You know, the "ethical reactions" stem from that guy doing evil things. He knows he's being evil but doesn't care. Some people find that appalling. For him, it's just an easy way to make money, and the fact t…
I work in the financial industry and I'm very convinced that my work is not harmful by any stretch of the imagination. In the past I've left well paid positions out of moral issues, in different industries. For instance, when my algorithms were getting patented, or I was increasingly made to work in .NET. People have different views. However, stealing CCs and massively screwing over random people... you cannot possib…
Well duh? Of course you are. It's you working for the financial industry, after all.
We could debate this all day without getting anywhere. It's easy for you to blow smoke up everyone's ass, pretending your work is beneficial because it provides "liquidity" or whatever. You can confuse us laymen with fancy terms we don't understand.
But in case you're being sincere, here's something to peruse: http://maxkeiser.com/ and http://zerohedge.com
You work for an industry whose raison d'être is making money with money. This is vastly different from producing something of value.
Re: IAmA a malware coder and botnet operator, AMA
#158Earlier quoted context omitted.
I think your faith in the justice system (especially considering the technical nature of this redditor's activities) is unfounded.
This guy is begging to get caught with the amount of attention he draws. It's a matter of time.
Re: IAmA a malware coder and botnet operator, AMA
#159Earlier quoted context omitted.
That's not really true. The user is liable if the card is stolen, and it is used to conduct fraud using the PIN code. If the card is stolen, and the fraudster simply uses it online, or via some place that doesn't ask for a PIN, then you are not liable for that fraud. I'm sure there are rare edge cases, but my experience with Barclays has always been very good in this regard.
The problem is that there is no way of knowing that the criminal even knows the user's PIN, due to flaws in the chip-and-PIN protocol. See http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...
1. Writing the PIN on a post-it note and sticking it to the back of the card.
2. Writing the PIN on some paper and keeping it in the same place the card is kept.
3. Giving the card to someone else (partner, kids, relatives, etc.), along with the PIN, to run an errand for them.
4. Saying the PIN out loud as they type it in.
5. Asking the customer assistant/whoever is dealing with the transaction to enter the PIN for them.
Chip&Pin, while claiming to be more secure, enabled and made convenient basic forms of fraud, such as that in points 3 and 5.
I'd actually argue that the shifting of liability from the card issuer/merchant to the card holder/customer in the UK is a direct consequence of C&P allowing careless people to be more lax with the security of their card.
Re: IAmA a malware coder and botnet operator, AMA
#160Earlier quoted context omitted.
Given the fact that your signature is on the card, this seem rather ineffective. Approximate signatures are easy to forge and no merchant will deny a transaction based on a different signature. In fact, that is not the purpose of your signature. The purpose is that you are signing a contract and agreeing to pay. It has nothing to do with security or fraud and merchants are not supposed to check signature matches - on…
Actually, signing the receipt has everything to do with fraud. If you use a credit card in a transaction you are required to pay regardless of whether you sign an agreement saying so. The difference is, if the merchant does not collect your signature, they are liable for any chargebacks AKA reports of fraud whereas the bank would be if the merchant did collect the signature. [1][2] My point in bringing up the signatu…
None of the above is legal advice as IANAL, however I do believe it is correct.
Do you really think a merchant can verify those electronic scribbles on a tiny, crappy pen input device? No. Any mark made by you with the intent to sign is a legal signature.
Read more here:
http://www.npr.org/templates/story/story.php?storyId=9227832...