Live data from Hacker News

Bank Hackers Steal Millions via Malware

nytimes.com

51–60 of 81 posts

Re: Bank Hackers Steal Millions via Malware

#51
post #49

Earlier quoted context omitted.

A key differentiator for banks vs. many other service providers is that financial transfers can be reversed. Releases of information however cannot be. So where a bank has a risk of an unauthorized financial transaction, there are multiple options to claw that back (or to shift the risk to other parties, notably merchants). A disclosure, though, of account information is a different case, and here the results can be…

> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.

The total amount of cash and the per-withdrawal limits in an ATM limits the loss there. You can't steal millions of dollars from an ATM.

Re: Bank Hackers Steal Millions via Malware

#52
post #51
post #49

Earlier quoted context omitted.

> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.

The total amount of cash and the per-withdrawal limits in an ATM limits the loss there. You can't steal millions of dollars from an ATM.

These guys stole $45 million from ATMs- http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-...

Re: Bank Hackers Steal Millions via Malware

#53
post #36

Earlier quoted context omitted.

Fractional reserve systems mean that private banks can and actively do create money by lending.

That's certainly not what went on here, from the description. Your assertion is truthy, in that, yes, the /practice/ of fractional reserve banking increases the money supply. However, to do the equivalent in the way the example described would have required mocking up a loan (asset) which would be offset by a liability (deposit account balance), and a reserve amount (loss allowance and bank capital) behind it. In tha…

Well, there is horizontal money vs vertical money. Private banks create horizontal money; federal reserve creates vertical money.

Re: Bank Hackers Steal Millions via Malware

#54
post #50

Earlier quoted context omitted.

I'd like to see the sysadmin or programmer that is willing to take the loss if someone hacks the network (or an app) of his employer and steals a few hundred million dollars.

Professional Engineers (mechanical, civil, etc.) are exposed to liability for the buildings, bridges, etc. they approve.

But we are not liable as long as we follow standards, e.g. building codes. And it's easily verifiable by the government, the employer and the engineer himself whether the standards are being complied with.

Until you have similar standards for software development, I cannot see how such liability shift could work. This is one of the reasons I tend to avoid using the phrase software engineering. It's so different from traditional engineering that it feels incorrect to put it in the same category.

Re: Bank Hackers Steal Millions via Malware

#55
post #11

So who ends up footing the bill? Does the bank just write it off as a cost of doing business? Also aren't financial transactions reversible among banks?

This looks the money was stolen from the bank's own account not their customers.

Pretty sure that they just write if off and call it day.

Re: Bank Hackers Steal Millions via Malware

#56

I laugh whenever someone tells me that they never buy anything over the internet. Their reasoning is that they're afraid of hackers going after online transactions. It seems to me that most of the serious security problems reside in the places that keep your money or access to your money, such as banks, credit cards, or even businesses such as Anthem, etc. Another problem that I've seen from banks is that they all us…

Bank tellers used to have "dumb" terminals, VT100s or 3270s or similar. Maybe that's a better idea after all?

Re: Bank Hackers Steal Millions via Malware

#57
post #52
post #51

Earlier quoted context omitted.

The total amount of cash and the per-withdrawal limits in an ATM limits the loss there. You can't steal millions of dollars from an ATM.

These guys stole $45 million from ATMs- http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-...

On Feb. 19, cashing crews were in place at A.T.M.'s across Manhattan and in two dozen other countries ... Starting at 3 p.m., the crews made 36,000 transactions and withdrew about $40 million from machines in the various countries in about 10 hours

I stand corrected. That's quite impressive and amazing that they had that many people involved and nobody tipped it off.

Re: Bank Hackers Steal Millions via Malware

#58
post #49

Earlier quoted context omitted.

A key differentiator for banks vs. many other service providers is that financial transfers can be reversed. Releases of information however cannot be. So where a bank has a risk of an unauthorized financial transaction, there are multiple options to claw that back (or to shift the risk to other parties, notably merchants). A disclosure, though, of account information is a different case, and here the results can be…

> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.

Fair point. As the responses note, the damage here is usually limited -- ATMs carry only so much cash each, and (usually) only dispense up to a few hundred dollars (or equivalents) at a time. There've been some exceptions where an exploit is found and utilized in mass effect at many locations in a short period. That takes a high level of organization though.

Re: Bank Hackers Steal Millions via Malware

#60
While this is an astonishingly large criminal heist, we should look at this from a business perspective. The largest take from a single bank sounds to be around $10M. The first russian bank I could find in Wikipedia, Alfa-Bank, had a net income in 2010 of $550M, meaning that if they were the ones hacked they would have lost about 2% of their annual PROFIT. What would be the capital, operational, and efficiency cost of a major security overhaul be? Probably more than $10M. Moving to a new system like qubes or even a more standard desktop Linux variant could very well terrorize me more than the losses from hacking.

Lots of industries just live with a certain degree of loss- retail in particular sees about 1.8% of inventory lost due to "shrinkage", the polite term for shoplifting and employee theft. While stores will take steps to reduce their loss, they can't be extravagant or they will lose customers (I stopped shopping at a drug store that put deodorant behind plexiglass) or cost more than the problem (rfid trackers on every candybar.)

Given that perspective I think we as technical professionals need to be a little more restrained in our recommendations. Enterprise decision makers are very receptive right now to projects involving security due to hacks like this and Sony, but we as technical professionals still have to speak to the whole of their concerns.

Post reply on HN