Live data from Hacker News

International Revenue Share Fraud (IRSF)

knock-knock.net

21–24 of 24 posts

Re: International Revenue Share Fraud (IRSF)

#21
post #6

Earlier quoted context omitted.

A question: why are you writing this with an LLM? Can you not write with your own words, at least on HN?

As mentioned above, wrote the blog post myself and had AI proofread and edit. As for the honeypot itself, I'm a greybeard computer scientist, and I architected the system very deliberately myself, using AI as a coding accelerator. Earlier in my career, moving from Assembly to C, I certainly appreciated the convenience of a higher level language. Same from C to C++ to Java/Lisp/Python to LLM. It's always a march to hi…

From the rules:

> Don't post generated text or AI-edited text. HN is for conversation between humans.

This is why your comment has been removed.

Re: International Revenue Share Fraud (IRSF)

#22
post #20

Could they be residential proxies or does that not work in SIP? P.S. this is one reason that "pay for email" doesn't work to stop spam.

Good question. You can certainly proxy SIP. But what’s notable here is that the traffic comes directly from organizations that should be secure: banks, infrastructure, governments. For a proxy to explain it, the proxy exit node would have to be running inside those institutions, on their networks. So from a security standpoint it doesn’t really matter whether a botnet is running inside the company or the company is being used as a proxy hop. Either way, a machine on their network has been compromised.

(And your P.S. is spot on. The attacker bears none of the cost; the clean IP reputation and the blame land on the compromised third party.)

Re: International Revenue Share Fraud (IRSF)

#23
post #20

Could they be residential proxies or does that not work in SIP? P.S. this is one reason that "pay for email" doesn't work to stop spam.

Good question. You can certainly proxy SIP. But what’s notable here is that the traffic comes directly from organizations that should be secure: banks, infrastructure, governments. For a proxy to explain it, the proxy exit node would have to be running inside those institutions, on their networks. So from a security standpoint it doesn’t really matter whether a botnet is running inside the company or the company is b…

Are you ChatGPT or Claude?

Re: International Revenue Share Fraud (IRSF)

#24
post #23

Earlier quoted context omitted.

Good question. You can certainly proxy SIP. But what’s notable here is that the traffic comes directly from organizations that should be secure: banks, infrastructure, governments. For a proxy to explain it, the proxy exit node would have to be running inside those institutions, on their networks. So from a security standpoint it doesn’t really matter whether a botnet is running inside the company or the company is b…

Are you ChatGPT or Claude?

Crafted that awesome response to your original query myself, and I am very human.
Post reply on HN