Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

101–110 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#101
post #63

Earlier quoted context omitted.

You're missing the point entirely. I'm not saying that chip & pin has no value. I'm saying that the value it has is finite (i.e. it saves money equal to the amount of fraud it eliminates) and needs to be weight against the cost of replacing all the card reader infrastructure. And I argue that the fact the US has not upgraded is an existence proof that the upgrade cost[1] outweighs the savings. [1] Really the amortize…

"cost of replacing all the card reader infrastructure" I'm not sure how many PoS are already equipped to deal with chip cards. In the USA/Canada it's hit or miss (most misses), and in Europe it was the standard 10 years ago (but most readers take swipe cards). Replacing cards is cheap and they can be replaced as they expire What would be the upgrade cost for each PoS? $100? Some systems are more integrated than other…

I've found that most Canadian retailers seem to support chip cards now.

Re: IAmA a malware coder and botnet operator, AMA

#102
post #82

Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.

oh I was doing that while reading the AMA. the giveaway is being the 4th customer of a bank that provides HBCI: > My bank had around 20,000 customers using smsTAN and 3 (I was the 4th lol) using HBCI. He is German, of college age and an early customer at one of 2 or 3 banks that provide HBCI. Consider him nailed. I also bet he has published security related work under his real name at some point, especially since he…

Most German banks have been providing HBCI for over a decade, so that doesn't really narrow it down.

Re: IAmA a malware coder and botnet operator, AMA

#103

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

I've only used VbV once or twice, years ago. Do they still use iframes? I've never understood why they try to make the site more "secure" by using these services, but then use an iframe so the average user can't easily confirm if the login screen is legit or not.

In the UK I see it occasionally. Oddly enough it's mainly when I order food online.

It really peeves me that they are training people to accept entering sensitive information into something it would be so very easy to fake. There's nothing to prove that it is actually what it says it is. On top of that, if you forget your phrase the security question (the usual researchable ones) and answer sequence happens within the iframe without recourse to any external site or emails.

As other comments have said, none of this is for the customers benefit.

Re: IAmA a malware coder and botnet operator, AMA

#104
post #51
post #13

Earlier quoted context omitted.

They can't store the CVV2 either. Doing so, even encrypted, violates PCI-DSS.

You'd be surprised how many vendors and merchants simply do not care. I was employed with an e-commerce vendor that indefinitely stored CVV2 in plaintext (among other numbers).

[deleted]

Re: IAmA a malware coder and botnet operator, AMA

#105

Let's play 33 bits on this guy, my guess is that he's German, Austrian or Swiss based on the settings for his IRC client, that should knock about 6 bits off, 27 to go.

Yep, also he likes to use conditional tense (would) in 'if' clauses, which is a typical language trap for German native speakers.

Re: IAmA a malware coder and botnet operator, AMA

#106

Magnetic stripes are the most hilarious thing ever, but still work almost everywhere on the globe. I am amazed that magnetic stripes are still the norm for credit cards in the US. Europe has managed to move all but completely to chip-based cards, but the US hasn't. Does the cost of fraud due to magnetic stripes outweigh the cost to upgrade the entire US system, or is the market just too fragmented to coordinate such…

The US still uses checks, can't expect much...

Re: IAmA a malware coder and botnet operator, AMA

#107

Earlier quoted context omitted.

I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.

That's not really true. The user is liable if the card is stolen, and it is used to conduct fraud using the PIN code. If the card is stolen, and the fraudster simply uses it online, or via some place that doesn't ask for a PIN, then you are not liable for that fraud. I'm sure there are rare edge cases, but my experience with Barclays has always been very good in this regard.

The problem is that there is no way of knowing that the criminal even knows the user's PIN, due to flaws in the chip-and-PIN protocol. See http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...

Re: IAmA a malware coder and botnet operator, AMA

#108

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

Verified by Visa is a fucking joke.

In Canada it pops up a browser window that prompts for various personal information and its URL points at ... drumroll ... https://secureserver.net. If that's not by the book appearance of a phishing site, I don't know what is.

Re: IAmA a malware coder and botnet operator, AMA

#109
post #21

Great nugget: > a US credit card costs 2$ on the black market and a UK starts at 60$, americans are all in debt.

I assume that's because in the US responsibility for the fraudulent purchase is on the merchant, while in UK customer is more likely to hold the bag.

Re: IAmA a malware coder and botnet operator, AMA

#110
post #47

Earlier quoted context omitted.

Nothing. This 'feature' is entirely designed to reduce the banks' liability. It shifts the onus of security onto you (from the banks and the merchants).

It sounds like in principle it might also reduce fraud overall. Thus, maybe 80% of the fraud goes away and 20% remains, but that liability is shifted to the consumer rather than the bank (who otherwise passes it to the merchant anyway). If the merchant has reduced fraud liability, they may be able to offer lower prices. So, in principle there might be a long-term win for the consumer. In practice, who knows.

I think the idea of a pin at checkout is a good one to reduce fraud. However this is more work for the consumer, and reduces the bank's liability. Most consumers would probably prefer this, as it makes their card more secure and reduces the possibility of fraud hassles, which are annoying regardless of liability. Having something that is more work for the consumer and could save the bank money switch the liability to the consumer is just obnoxious.
Post reply on HN