Live data from Hacker News

The Biggest Digital Heist in History Isn’t Over Yet

bloomberg.com

81–90 of 92 posts

Re: The Biggest Digital Heist in History Isn’t Over Yet

#81
post #40

>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…

>> Why do we still tolerate this? This is the real question. The thieves are just a symptom of the real infection: terrible, insecure client software. I'm not sure what the solution is but I am pretty sure it involves Microsoft having skin in the game somehow.

I'm sure it doesn't have anything to do with Microsoft's willingness to roll over to the US government (PRISM, NSAKEY).

Re: The Biggest Digital Heist in History Isn’t Over Yet

#82
post #49

Earlier quoted context omitted.

EA is largely hosted and managed by rackspace, who, for years, had default passwords on their iLOs - with public IPs. ;)

FYI to those like me: > Integrated Lights-Out, or iLO, is a proprietary embedded server management technology by Hewlett-Packard which provides out-of-band management facilities. The physical connection is an Ethernet port that can be found on most Proliant servers and microservers[1] of the 300 and above series.

Yeah - it's basically a PCIe KVM over ethernet.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#83
post #30

Earlier quoted context omitted.

Cost of dealing with a dead teller is probably higher than the amount of cash that will satisfy most traditional robbers. If that robber-satisfying amount can be recovered with a certain degree of reliability, the security model is effective in deterring attacks, minimizing attack damage, and ensuring physical safety of team members.

Yet Fort Knox gets on just fine having zero robberies. I'm not saying every bank should be FK, but I do think we're unwise to at least admit that security is a spectrum and the most secure places do not get robbed or bugged.

I don't think that Fort Knox is open to the public. Which makes it a much harder problem than to stick up a bank (which is a hellishly stupid form of crime to begin with).

Re: The Biggest Digital Heist in History Isn’t Over Yet

#84
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> Asynchronous requests were made by changing the src attribute of a 1px .

And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#85
post #75

Earlier quoted context omitted.

We're not talking about buying a couple of miner machines here, but financing a whole warehouse filled with them.

Which would make it harder to conceal the dubious origin of the money.

Not really.

From the p.o.v of the seller of mining hardware, he's just selling hardware in exchange for money, and he has no KYC/AML requirement, he's not a bank, he's just a regular business.

And any other company involved in building the mining operation are the same way.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#86
post #15
post #8

I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

Easy to get in, but hard not to get caught has always been the case. Anyone with a lack of morals can go execute tellers and pull money out of cash drawers. But they’ll be in jail by the end of the day.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#87
post #84
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.

That's really interesting. How does it however wait to vote until you press the up or down arrow?

Re: The Biggest Digital Heist in History Isn’t Over Yet

#88
post #75

Earlier quoted context omitted.

Which would make it harder to conceal the dubious origin of the money.

Not really. From the p.o.v of the seller of mining hardware, he's just selling hardware in exchange for money, and he has no KYC/AML requirement, he's not a bank, he's just a regular business. And any other company involved in building the mining operation are the same way.

Right but the point of laundering is that you have cash you want to legitimize, so it must "re-enter" as cash. But hardware mining sales are all online, not cash, hence my original comment!

Re: The Biggest Digital Heist in History Isn’t Over Yet

#89
post #87
post #84

Earlier quoted context omitted.

> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.

That's really interesting. How does it however wait to vote until you press the up or down arrow?

Oh, Javascript creates the tag when you click the arrow, it's not present beforehand.

Re: The Biggest Digital Heist in History Isn’t Over Yet

#90
post #84
post #15

Earlier quoted context omitted.

Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…

> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.

That's interesting, but Hackernews doesn't exactly handle top-security data.

I've always been surprised/charmed by how old-school this site is. In some ways it's nice - it's blazingly lightweight - but it seems ironic that a tech incubator wouldn't have updated their website in ~12 years.

Post reply on HN