>> Someone had sent emails to the bank’s employees with Microsoft Word attachments, purporting to be from suppliers such as ATM manufacturers. It was a classic spear-phishing gambit. Microsoft Windows + Outlook Email + Attached word document = the Drake equation for internet security. No matter how secure each of these things are individually, when added together infection becomes inevitable. Why does outlook have to…
>> Why do we still tolerate this? This is the real question. The thieves are just a symptom of the real infection: terrible, insecure client software. I'm not sure what the solution is but I am pretty sure it involves Microsoft having skin in the game somehow.
The Biggest Digital Heist in History Isn’t Over Yet
81–90 of 92 posts
Re: The Biggest Digital Heist in History Isn’t Over Yet
#82Earlier quoted context omitted.
EA is largely hosted and managed by rackspace, who, for years, had default passwords on their iLOs - with public IPs. ;)
FYI to those like me: > Integrated Lights-Out, or iLO, is a proprietary embedded server management technology by Hewlett-Packard which provides out-of-band management facilities. The physical connection is an Ethernet port that can be found on most Proliant servers and microservers[1] of the 300 and above series.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#83Earlier quoted context omitted.
Cost of dealing with a dead teller is probably higher than the amount of cash that will satisfy most traditional robbers. If that robber-satisfying amount can be recovered with a certain degree of reliability, the security model is effective in deterring attacks, minimizing attack damage, and ensuring physical safety of team members.
Yet Fort Knox gets on just fine having zero robberies. I'm not saying every bank should be FK, but I do think we're unwise to at least admit that security is a spectrum and the most secure places do not get robbed or bugged.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#84I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#85Earlier quoted context omitted.
We're not talking about buying a couple of miner machines here, but financing a whole warehouse filled with them.
Which would make it harder to conceal the dubious origin of the money.
From the p.o.v of the seller of mining hardware, he's just selling hardware in exchange for money, and he has no KYC/AML requirement, he's not a bank, he's just a regular business.
And any other company involved in building the mining operation are the same way.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#86I've learned to be skeptical when I see law enforcement praising the l337 skillz of their targets. > “This guy is in another league, he’s like Rafa Nadal > playing tennis,” Yuste says. “There are few people in > the world capable of doing what he did.” It sounds really cool (and budget-justifying) to be chasing some mastermind, and a journalist is likely to pump up that aspect of the story too. Because they know we'r…
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
Re: The Biggest Digital Heist in History Isn’t Over Yet
#87Earlier quoted context omitted.
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#88Earlier quoted context omitted.
Which would make it harder to conceal the dubious origin of the money.
Not really. From the p.o.v of the seller of mining hardware, he's just selling hardware in exchange for money, and he has no KYC/AML requirement, he's not a bank, he's just a regular business. And any other company involved in building the mining operation are the same way.
Re: The Biggest Digital Heist in History Isn’t Over Yet
#89Earlier quoted context omitted.
> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.
That's really interesting. How does it however wait to vote until you press the up or down arrow?
Re: The Biggest Digital Heist in History Isn’t Over Yet
#90Earlier quoted context omitted.
Yeah; I also have the general impression (admittedly without much data to support it) that IT security at banks and other gargantuan, long-lived institutions is pretty crappy? I would think it's easy to get in, and hard to not get caught. Anecdotally, I have a friend who briefly worked at a company which exclusively makes software for financial institutions. Their product was a web app that only worked in a version o…
> Asynchronous requests were made by changing the src attribute of a 1px . And you're posting on a site that still does it that way - voting on HN works by creating an and setting the src attribute to the vote url.
I've always been surprised/charmed by how old-school this site is. In some ways it's nice - it's blazingly lightweight - but it seems ironic that a tech incubator wouldn't have updated their website in ~12 years.