Earlier quoted context omitted.
A key differentiator for banks vs. many other service providers is that financial transfers can be reversed. Releases of information however cannot be. So where a bank has a risk of an unauthorized financial transaction, there are multiple options to claw that back (or to shift the risk to other parties, notably merchants). A disclosure, though, of account information is a different case, and here the results can be…
> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.
Bank Hackers Steal Millions via Malware
51–60 of 81 posts
Re: Bank Hackers Steal Millions via Malware
#52Earlier quoted context omitted.
> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.
The total amount of cash and the per-withdrawal limits in an ATM limits the loss there. You can't steal millions of dollars from an ATM.
Re: Bank Hackers Steal Millions via Malware
#53Earlier quoted context omitted.
Fractional reserve systems mean that private banks can and actively do create money by lending.
That's certainly not what went on here, from the description. Your assertion is truthy, in that, yes, the /practice/ of fractional reserve banking increases the money supply. However, to do the equivalent in the way the example described would have required mocking up a loan (asset) which would be offset by a liability (deposit account balance), and a reserve amount (loss allowance and bank capital) behind it. In tha…
Re: Bank Hackers Steal Millions via Malware
#54Earlier quoted context omitted.
I'd like to see the sysadmin or programmer that is willing to take the loss if someone hacks the network (or an app) of his employer and steals a few hundred million dollars.
Professional Engineers (mechanical, civil, etc.) are exposed to liability for the buildings, bridges, etc. they approve.
Until you have similar standards for software development, I cannot see how such liability shift could work. This is one of the reasons I tend to avoid using the phrase software engineering. It's so different from traditional engineering that it feels incorrect to put it in the same category.
Re: Bank Hackers Steal Millions via Malware
#55So who ends up footing the bill? Does the bank just write it off as a cost of doing business? Also aren't financial transactions reversible among banks?
Pretty sure that they just write if off and call it day.
Re: Bank Hackers Steal Millions via Malware
#56I laugh whenever someone tells me that they never buy anything over the internet. Their reasoning is that they're afraid of hackers going after online transactions. It seems to me that most of the serious security problems reside in the places that keep your money or access to your money, such as banks, credit cards, or even businesses such as Anthem, etc. Another problem that I've seen from banks is that they all us…
Re: Bank Hackers Steal Millions via Malware
#57Earlier quoted context omitted.
The total amount of cash and the per-withdrawal limits in an ATM limits the loss there. You can't steal millions of dollars from an ATM.
These guys stole $45 million from ATMs- http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-...
I stand corrected. That's quite impressive and amazing that they had that many people involved and nobody tipped it off.
Re: Bank Hackers Steal Millions via Malware
#58Earlier quoted context omitted.
A key differentiator for banks vs. many other service providers is that financial transfers can be reversed. Releases of information however cannot be. So where a bank has a risk of an unauthorized financial transaction, there are multiple options to claw that back (or to shift the risk to other parties, notably merchants). A disclosure, though, of account information is a different case, and here the results can be…
> financial transfers can be reversed. Not this time: hackers withdrew some of the money from ATMs.
Re: Bank Hackers Steal Millions via Malware
#59Re: Bank Hackers Steal Millions via Malware
#60Lots of industries just live with a certain degree of loss- retail in particular sees about 1.8% of inventory lost due to "shrinkage", the polite term for shoplifting and employee theft. While stores will take steps to reduce their loss, they can't be extravagant or they will lose customers (I stopped shopping at a drug store that put deodorant behind plexiglass) or cost more than the problem (rfid trackers on every candybar.)
Given that perspective I think we as technical professionals need to be a little more restrained in our recommendations. Enterprise decision makers are very receptive right now to projects involving security due to hacks like this and Sony, but we as technical professionals still have to speak to the whole of their concerns.