Live data from Hacker News

“NASDAQ is owned.” Five men charged in largest financial hack ever

arstechnica.com

11–20 of 143 posts

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#11
post #2

I've seen this story (NASDAQ being hacked) reported in a couple of places, but it isn't clear to me what damage was done. It's not really possible for them to have messed with the actual trading without anyone noticing. Everyone connecting to an exchange is reconciling the orders they send in against the trade confirmations they receive. You basically design your technology assuming the exchange is going to fuck some…

The matching engine and the ring of servers around it are not accessible via internet. You can only connect to them if you have a server collocated in Carteret, and even then the NASDAQ machines only expose the ports relevant to order entry and feed data.

They could have hacked a customer (say, citigroup) and entered that way, but all they really could do is incur losses for the customer.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#12
post #8
post #4

Was most of this done by SQL injection?

Looks like they used SQL injection to get passwords and then used those passwords to access the servers.

Yeah, and that's from the application layer down to the DB layer. I wonder how they were able to pass through the other layers of the stack. I heck of a work, no wonder they'd spent "months" on it.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#13

Their actions might have been illegal but they for sure are good at breaking things and their skills should be used instead of throwing them in jail for 20 years. Counsel them and give them a change to reform themselves.

There are still too many computer illiterate people, it's a matter of how people view things.

Blaming the existing systems instead of blaming the hackers, it's like being an astronomer in the middle age. Deciders and business owners will scream and tell their systems are fine, and that the ones who think differently and prove otherwise are at fault.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#14
post #2

I've seen this story (NASDAQ being hacked) reported in a couple of places, but it isn't clear to me what damage was done. It's not really possible for them to have messed with the actual trading without anyone noticing. Everyone connecting to an exchange is reconciling the orders they send in against the trade confirmations they receive. You basically design your technology assuming the exchange is going to fuck some…

You couldn't create or delete orders for other people without them noticing, but frontrunning could maybe stay under the radar.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#15
post #8

Earlier quoted context omitted.

Looks like they used SQL injection to get passwords and then used those passwords to access the servers.

Yeah, and that's from the application layer down to the DB layer. I wonder how they were able to pass through the other layers of the stack. I heck of a work, no wonder they'd spent "months" on it.

...crazy.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#17

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

They can't easily get jobs that pay them well, the way most programmers in the West can. People really good at security in the US just get a job making a great salary.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#18

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

Raw hacking ability I believe is defined loosely by a very strict early mathmetical education.

I'm slavic but I was raised in Sweden, visits with family in the balkans always leave me surprised at the strict education children go through.

Of course, my only perspective is from small country villages, not cities.

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#19

I honestly believe eastern Europe and possibly Israel are years ahead of the United States when it comes to the Internet - not with regard to adaptivity, but with regard to raw hacking ability. I have yet to understand why and I only have anecdotal evidence (including living in Ukraine), but there's something to those places that make them breed hackers.

I've always figured (at least for former soviet states) that it's a combination of:

+ a rigorous STEM curriculum

+ limited conventional job prospects

+ a social/business environment in which exploit-selling is a respectable profession

Re: “NASDAQ is owned.” Five men charged in largest financial hack ever

#20
post #13

Their actions might have been illegal but they for sure are good at breaking things and their skills should be used instead of throwing them in jail for 20 years. Counsel them and give them a change to reform themselves.

There are still too many computer illiterate people, it's a matter of how people view things. Blaming the existing systems instead of blaming the hackers, it's like being an astronomer in the middle age. Deciders and business owners will scream and tell their systems are fine, and that the ones who think differently and prove otherwise are at fault.

No it isn't. These people weren't publishing white papers about the lack of security at Nasdaq and other companies, they were using their knowledge to steal money, and the costs were passed back to you, the (presumably) law-abiding customer/credit card user.

Suppose you went out and came home to find your window smashed and your most valuable possessions gone. Would you be happy to have received an unscheduled visit from a private security consultant who decided to pay himself a handsome fee in the form of your stuff? No, you'd call the police to report a burglary.

Just because these guys were using computers and you also use computers does not mean they're basically the same as you and would be your good friends if only those mean old suits would get out of the way and let you run everything.

Post reply on HN