Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

171–180 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#171
post #49

Earlier quoted context omitted.

When a website asks me to use one of these, and I don't want to, how do I decline but still make the purchase? It always seems like my options are take-it-and-like-it or don't complete the transaction. Is there a third option?

I've had certain websites require VbV for purchases. I can only assume the transaction fees are lower for such transactions, or they got some kind of other deal from their merchant bank. The worst part is the information required for the "I forgot my password" process is often not terribly hard to get hold of (date of birth, that kind of thing). The best option at this stage is probably to have a "normal" credit card…

> I've had certain websites require VbV for purchases. I can only assume the transaction fees are lower for such transactions, or they got some kind of other deal from their merchant bank.

Transaction fees are not the problem, putting a stop to consumer fraud and charge-backs are the net win for the merchant.

Re: IAmA a malware coder and botnet operator, AMA

#172

Earlier quoted context omitted.

The problem is that there is no way of knowing that the criminal even knows the user's PIN, due to flaws in the chip-and-PIN protocol. See http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...

And, from many years of personal experience, quite a lot of people don't treat their card and PIN securely. This might be in the form of (and these are genuine examples): 1. Writing the PIN on a post-it note and sticking it to the back of the card. 2. Writing the PIN on some paper and keeping it in the same place the card is kept. 3. Giving the card to someone else (partner, kids, relatives, etc.), along with the PIN…

The worst thing is the chip+pin machines that do not have any shield to hide you punching the pin in, and then to just add insult to injury, they're the kind of buttons that you have to forcefully press with all your might to get them to register. So it's blatantly obvious to anyone taking notice which buttons you pressed.

Re: IAmA a malware coder and botnet operator, AMA

#173
post #118
post #32

Earlier quoted context omitted.

As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue late…

The only merchant that I've ever seen this used at is Newegg and they make it mandatory for Visa.

Although the mandatory sign-up for VBV on Newegg is old news (~3 years ago now?), any time you get a "you are now being redirected to your credit card's website for a mandatory additional agreement," that should be a huge red flag.

You can cancel the "mandatory" VBV page by pressing the back button. At first, the VBV page did have a tiny link that let you opt-out, but it disappeared some time in 2009.

I was quite surprised when I had finally given up and was ready to empty the Newegg shopping cart, only to find the order was accepted when I used the back button to escape VBV.

Re: IAmA a malware coder and botnet operator, AMA

#174
post #143

Earlier quoted context omitted.

You don't need to crack Tor for that. Get the list of Germans hanging out on Anonymous IRC. Choose only college students. Remove ones that don't have time to do this stuff due to actually working somewhere. Intersect with HBCI users in banks where there aren't many of those. Remove Mac users and Linux users (he mentions he only uses Windows). Remove families that use credit cards (he mentions his family does not). Th…

Is something like a reddit thread enough to arrest someone then? Even the person behind the AMA is tracked down, is that evidence enough to get him in jail?

As evidence - of course not. But as means to fin out who that is - sure, why not. Once the person is identified, it is a question of good old survelliance, and they are professionals at that, so chances are the guy will make a mistake, and sooner rather than later, and the hard evidence will be there. Look what happened to LulzSec - once the person is known, if he continues to do what he does, he will lose. Even professional spies can not pull it off if identified, what to say about some college students?

Re: IAmA a malware coder and botnet operator, AMA

#175
post #165

Earlier quoted context omitted.

> I work in the financial industry and I'm very convinced that my work is not harmful by any stretch of the imagination. Well duh? Of course you are. It's you working for the financial industry, after all. We could debate this all day without getting anywhere. It's easy for you to blow smoke up everyone's ass, pretending your work is beneficial because it provides "liquidity" or whatever. You can confuse us laymen wi…

> Well duh? Of course you are. It's you working for the financial industry, after all. Not-so-obviously, if I had qualms about my job I wouldn't be doing it. Some people are for sale, I'm not. > But in case you're being sincere, here's something to peruse: http://maxkeiser.com/ and http://zerohedge.com I know these sites. They're rather juvenile but sometimes there's stuff of real value there. There are crooks in fin…

We're already well on our way to getting nowhere with this.

> Not-so-obviously, if I had qualms about my job I wouldn't be doing it. Some people are for sale, I'm not.

So participating in the financial industry driving the Western world's economy off a cliff is fine, but having to work with .NET is where you draw the line?

> I know these sites. They're rather juvenile

These sites discuss (the economic) Reality, and what's going on in it. Trying to discredit them is logical, of course, for someone working for the financial industry.

Here's someone with a more somber take on things, in case it helps: http://globaleconomicanalysis.blogspot.com/ - he's on the same page with the aforementioned two, though.

> There is nothing bad about making money from financial services.

No? Well, what good is there about it? How does it benefit the real economy, where people use their time and skills to produce something of value, which they then exchange for goods and services as necessary?

What is it that grounds the financial industry into the real economy? In other words, in what ways is it not about making money with money?

> If you stretch it a bit, you can call it "making money with money" the same as you can argue that the sole reason for any imaginable job is making money. It's not.

Huh? A job is an arrangement where an employer pays someone a salary in exchange for using his time/skills in a way that benefits the employer (in a monetary sense, ultimately).

For both parties involved, it is about making money. Otherwise we're talking about some kind of charitable operation.

Re: IAmA a malware coder and botnet operator, AMA

#176
post #165

Earlier quoted context omitted.

> Well duh? Of course you are. It's you working for the financial industry, after all. Not-so-obviously, if I had qualms about my job I wouldn't be doing it. Some people are for sale, I'm not. > But in case you're being sincere, here's something to peruse: http://maxkeiser.com/ and http://zerohedge.com I know these sites. They're rather juvenile but sometimes there's stuff of real value there. There are crooks in fin…

We're already well on our way to getting nowhere with this. > Not-so-obviously, if I had qualms about my job I wouldn't be doing it. Some people are for sale, I'm not. So participating in the financial industry driving the Western world's economy off a cliff is fine, but having to work with .NET is where you draw the line? > I know these sites. They're rather juvenile These sites discuss (the economic) Reality, and w…

I consider my job not only not to be bad, but GOOD for society. My job helps making a level field and removes the need of extra people working in trying to scalp away from market fluctuations.

I consider my job to be good in the sense that the alternative to be worse. Quite like a free market I consider it to be good, because it's the MUCH better alternative to a CAPTIVE market. Because that's in fact the only alternative. Some manipulative politicians trying to justify their job would tell you the alternative is a "regulated market" - it honestly is not about more or less regulation, it's about better or worse regulation. The freest market is not the least nor the most regulated, it's the best regulated.

> These sites discuss (the economic) Reality, and what's going on in it. Trying to discredit them is logical, of course, for someone working for the financial industry.

You've very conveniently cherry-picked my criticism about them. I like these sites and they're rather good. However, their style is indeed juvenile. That's the way they're redacted, the public they cater to the most and very likely the personality of the main contributors.

They also seem to be quite libertarian-leaning. Like myself. Which is totally besides the point, anyway.

> For both parties involved, it is about making money. Otherwise we're talking about some kind of charitable operation.

But you're missing the point that it's not ONLY about that. Thankfully, most of us don't work just for mere subsistence and are in the position to choose one work over another based in more than pay.

This point is related to the post because I'd actually take this job over most other jobs taking a significant pay cut. I've worked in telecom, microchip design, even videogames, and this is my favourite job so far. I'd take it over any of my previous jobs on equal pay and they weren't bad jobs for the most part. I'd even take a pay cut. That's how much I like my job and how positive for society I think it is. My sister is a doctor, I think my job is more positive for society than even that, it affects way more people.

Re: IAmA a malware coder and botnet operator, AMA

#177
post #168

Earlier quoted context omitted.

User: rawrr69, on Reddit: "His writing style, long and nested sentences and use of commas are another hint. Plus he likes to laugh about and feel superior to other people and rectify their "mistakes" - 100% definitely German."

> Plus he likes to laugh about and feel superior to other people and rectify their "mistakes" - 100% definitely German." well, as a German, I'd like to point out that this might have something to do with the fact that he is kind of an asshole. There are nice and well-mannered people here too.

I seriously hope you're joking right now (due to meta-ness, not because I hate Germans)

Re: IAmA a malware coder and botnet operator, AMA

#178

Earlier quoted context omitted.

I really hope I never make enemies with anyone around here.

I think Hackernews has 220000 registered users. You are one of them. You have 17 bits left. Use them wisely.

This is fallicious. Anyone can register for an account. Knowing someone is on HN only gives enough information, that said person is in the 'HN demographic'. Just because he happened to register for an account, vs someone similar who didn't, does not give us the amount of entropy removal you implied.

Re: IAmA a malware coder and botnet operator, AMA

#179

"Protip against driveby infections (the ones in the browsers): Disable addons in your browser and only activate the ones you need. Chromium and Chrome for example let you disable all additional content like flash, html5, pdf and java in the options, you will see a grey box instead of the content and can manually run it using right-click -> Run. Chrome options -> Content options -> Plug-Ins -> Disable all or Click-to-…

I've actually stopped using Firefox because it re-enables plugins that I've disabled (maybe it's more accurate to say it allows 3rd-party software updates to re-enable them).

This was fixed in Firefox 8, unless 3rd-party programs have gotten much more clever:

https://blog.mozilla.org/addons/2011/08/11/strengthening-use...

Re: IAmA a malware coder and botnet operator, AMA

#180

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

Somewhere in the thread he says that he started coding around operation payback. That is december 2010. I would assume that either he is truely a genius or that his abilities to program properly are limited.
Post reply on HN