Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

181–190 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#181
post #178

Earlier quoted context omitted.

I think Hackernews has 220000 registered users. You are one of them. You have 17 bits left. Use them wisely.

This is fallicious. Anyone can register for an account. Knowing someone is on HN only gives enough information, that said person is in the 'HN demographic'. Just because he happened to register for an account, vs someone similar who didn't, does not give us the amount of entropy removal you implied.

Since the GGP is easily googleable he actually has 0 bits left, but you are correct about the math.

Re: IAmA a malware coder and botnet operator, AMA

#182

Earlier quoted context omitted.

And, from many years of personal experience, quite a lot of people don't treat their card and PIN securely. This might be in the form of (and these are genuine examples): 1. Writing the PIN on a post-it note and sticking it to the back of the card. 2. Writing the PIN on some paper and keeping it in the same place the card is kept. 3. Giving the card to someone else (partner, kids, relatives, etc.), along with the PIN…

The worst thing is the chip+pin machines that do not have any shield to hide you punching the pin in, and then to just add insult to injury, they're the kind of buttons that you have to forcefully press with all your might to get them to register. So it's blatantly obvious to anyone taking notice which buttons you pressed.

Here's how I do it

Cover the pad with one hand (and maybe your wallet) and type it with the other

You can do it quite naturally. Of course it helps if you type the pin fast as well (by fast I mean not taking 1s per digit)

Re: IAmA a malware coder and botnet operator, AMA

#183
post #82

Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.

oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…

he removed that maybe you should too

Re: IAmA a malware coder and botnet operator, AMA

#185
He says he has no respect for the security industry and AV companies. He makes compellling arguments against them.

Then when asked about his future, he says he plans to work for an AV company!

WTF?!

He can see what's wrong, but he can't do what's right.

And that, my friends, is the problem.

Re: IAmA a malware coder and botnet operator, AMA

#186
post #160

Earlier quoted context omitted.

Actually, signing the receipt has everything to do with fraud. If you use a credit card in a transaction you are required to pay regardless of whether you sign an agreement saying so. The difference is, if the merchant does not collect your signature, they are liable for any chargebacks AKA reports of fraud whereas the bank would be if the merchant did collect the signature. [1][2] My point in bringing up the signatu…

Because if you did not sign, there is no written contract for that transaction, so there is far less of a case that the charge is valid. Regardless of what the signature looks like, you are liable if it was you (or someone you authorized) who signed and you are not liable otherwise. You are even liable if you charged for the transaction but did not sign - there is just no written, signed contract, so you are presumed…

Did you think I was arguing a smiley face is not a valid signature?

Re: IAmA a malware coder and botnet operator, AMA

#187

Earlier quoted context omitted.

but he says, only because it is not much common, and different distros are too diverse to justify an "investment"

Surely Linux would be a good target? There are hundreds of thousands of Linux servers out there and they will have a lot of bandwidth / CPU etc.

But how do you get the malware on the servers? Most malware spread by tricking unsophisticated users into install them. It is much harder to trick a system administrator to so. Exploiting a vulnerable public facing service is the alternative. However, that option is out of reach to all but the most dedicated attackers, assuming you keep the system updated.

Re: IAmA a malware coder and botnet operator, AMA

#188

He says he has no respect for the security industry and AV companies. He makes compellling arguments against them. Then when asked about his future, he says he plans to work for an AV company! WTF?! He can see what's wrong, but he can't do what's right. And that, my friends, is the problem.

If you want to do this for the rest of your life you have no choice than working for a security firm (AV included) or being a criminal.

The problem is why he didn't get that job at Kaspersky. He is obviously skilled so what happened?

Re: IAmA a malware coder and botnet operator, AMA

#189
post #14

Earlier quoted context omitted.

From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.

Every bit of bragging about himself makes it easier to find him. He has disclosed this information so far: * He tried to apply for a job at Kaspersky during last year. Didn't have enough credentials and still whines about it. * He hangs out on Anonymous IRC. * Uses Liberty Reserve. * Exchanges bitcoins to dollars (periodically I guess). * May be German-speaking. Understands Russian.

well, how do you know which of those 'facts' are real and not just false tracks? the guy really had to be dumb to not put some false hints.

Re: IAmA a malware coder and botnet operator, AMA

#190
post #21

Great nugget: > a US credit card costs 2$ on the black market and a UK starts at 60$, americans are all in debt.

Well this could be because US credit cards are magnetic and UK ones are (much more secure) chip-and-pin cards.

I know that the criminals probably haven't caught up and this technology may not be widespread (so your argument holds) but...

chip and pin is definitely broken (defcon presentation) http://www.youtube.com/watch?v=JABJlvrZWbY

Post reply on HN