Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

71–80 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#71

One interesting bit is the "laundering through a bitcoin warehouse he bought in China". I suspect this is actually a Bitcoin mining farm: In goes dirty money, to buy mining hardware in bulk. Out comes fresh, never-transacted-with Bitcoin block rewards. It is fairly hard for authorities to trace the wash: in Bitcoin land, block rewards are the least-tainted kind of coins.

But I thought Bitcoin mining hardware was all online-only sales?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#72
post #66

Earlier quoted context omitted.

> Like the Silk Road guy, "how could he possibly ask on stack overflow using his real name". I always had the impression that Ross suffered from the fatal flaw that he didn't think what he was doing was wrong. He was an evangelical libertarian, and I think he didn't see "not getting caught" as the #1 priority the way a profit oriented criminal would.

If that was the flaw, then why did he try so hard to remain anonymous?

Does posting under your real name about drugs and bitcoins constitute "trying hard?" :)

Re: The Biggest Digital Heist in History Isn’t Over Yet

#73
post #71

One interesting bit is the "laundering through a bitcoin warehouse he bought in China". I suspect this is actually a Bitcoin mining farm: In goes dirty money, to buy mining hardware in bulk. Out comes fresh, never-transacted-with Bitcoin block rewards. It is fairly hard for authorities to trace the wash: in Bitcoin land, block rewards are the least-tainted kind of coins.

But I thought Bitcoin mining hardware was all online-only sales?

We're not talking about buying a couple of miner machines here, but financing a whole warehouse filled with them.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#74
post #47
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

It's valid concern, but I'm not so sure in this case. Spear phishing is a skilled art, and requires relatively significant knowledge of the target and their domain. Sure the rest is a essentially a stackoverflow post away, but it requires real determination to research this kind of attack and real skill to carry it out and see it through to millions in cash popping from ATMs in foreign countries. Just the people mana…

People management is a challenge, but spear-fishing? It's one of the easiest methods of penetrating a company.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#75
post #71

Earlier quoted context omitted.

But I thought Bitcoin mining hardware was all online-only sales?

We're not talking about buying a couple of miner machines here, but financing a whole warehouse filled with them.

Which would make it harder to conceal the dubious origin of the money.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#76
post #75

Earlier quoted context omitted.

We're not talking about buying a couple of miner machines here, but financing a whole warehouse filled with them.

Which would make it harder to conceal the dubious origin of the money.

Unless you're buying crates of stolen GPUs off the black market with heaps of cash.

I am betting these guys have some connections.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#77
post #35
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

It is and it is (sorta). I worked in the bank industry for many years and I could have stolen money a hundred different ways without getting caught. The problem is that in the end the money has to go somewhere or be spent (why else steal it?). Also to live a legal life (house,car,boat) you have to have a source of income/spending that does not set off red flags. If you are a high paid bank employee why even bother? M…

> Unless you live in a country like Russia where stealing money from the US is basically legal. Then go for it.

I've also heard that about China. Just be sure not to target fellow nationals. I recall reading that Zeus botnet software did not include any Russian templates, for example.

But wasn't there a time when Russia cooperated more with the USA and EU? During the 00s, maybe?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#78
post #30

Earlier quoted context omitted.

Better security is not letting them get the cash at all.

Cost of dealing with a dead teller is probably higher than the amount of cash that will satisfy most traditional robbers. If that robber-satisfying amount can be recovered with a certain degree of reliability, the security model is effective in deterring attacks, minimizing attack damage, and ensuring physical safety of team members.

Yet Fort Knox gets on just fine having zero robberies. I'm not saying every bank should be FK, but I do think we're unwise to at least admit that security is a spectrum and the most secure places do not get robbed or bugged.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#79
post #68
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Sounds like Jack Henry. My bank uses them for their client web portal. Up until last year, they had an 8 character max limit on your password, and you couldn't use any special characters or spaces. But at least they make you verify your "personal photo" every time you log in. Which is more than useless since…

Pffft, a major Canadian bank (they’re all big since we never had a crash), has only 6 numerical digit passwords.

You can have a 6 (not less or more) alphanumeric password, but any letters get mapped to numerical digits.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#80
post #49

Earlier quoted context omitted.

The door code for one of the US's top banks' offices used to be 0000. I wonder if they finally changed it? EA QAs their games better than a lot of financial institutions as well

EA is largely hosted and managed by rackspace, who, for years, had default passwords on their iLOs - with public IPs. ;)

FYI to those like me:

> Integrated Lights-Out, or iLO, is a proprietary embedded server management technology by Hewlett-Packard which provides out-of-band management facilities. The physical connection is an Ethernet port that can be found on most Proliant servers and microservers[1] of the 300 and above series.

Post reply on HN