HN user

from

1,272 karma
Posts23
Comments480
View on HN
www.spiegel.de 3y ago

The Case of Sergei Magnitsky: Anti-Corruption Champion or Corrupt Anti-Hero?

from
1pts0
grandjurytarget.com 3y ago

It’s Not What You Say, It’s How You Say It: Encrypted Messaging as a DOJ Weapon

from
63pts37
commsrisk.com 3y ago

FCC threatens to disconnect Twilio for illegal robocalls

from
574pts216
www.keytrac.net 3y ago

Identify Users via Keystroke Patterns

from
2pts0
phantel.com 3y ago

Phantel – Encrypted Phone Calls

from
2pts0
github.com 4y ago

Show HN: Hulu Raw Video Downloader

from
9pts3
en.wikipedia.org 4y ago

Hank Asher

from
2pts0
github.com 5y ago

A Brief Survey of Code Obfuscation Techniques

from
1pts0
fitzgeraldnick.com 5y ago

Synthesizing Loop-Free Programs with Rust and Z3

from
2pts0
github.com 5y ago

Reversing the Old Widevine Content Decryption Module

from
1pts0
www.winton.com 5y ago

Shining a Light on Currency Black Markets

from
3pts0
adtechmadness.wordpress.com 5y ago

All your input are belong to me – 3rd party web security

from
2pts0
www.justice.gov 5y ago

First Enforcement for Violations of the Better Online Ticket Sales (Bots) Act

from
2pts0
0xnobody.github.io 5y ago

A Tale of Static Devirtualization Vol. I: The Lift

from
3pts1
arstechnica.com 5y ago

Apple's “benign dictatorship” of the App Store leaves users the dark (2012)

from
2pts0
www.nytimes.com 5y ago

Making a Fortune by Wagering That Drug Prices Tend to Rise (2005)

from
1pts0
en.wikipedia.org 5y ago

1964 New York World's Fair

from
1pts1
en.wikipedia.org 5y ago

Fido (Dog)

from
3pts0
alistapart.com 5y ago

Why IE5/Mac Matters (2000)

from
3pts0
chris124567.github.io 5y ago

Analysis of a Commercial Browser Fingerprinting Service

from
6pts0
chris124567.github.io 6y ago

Understanding Distil Networks Anti-Bot Code

from
6pts0
www.oreilly.com 6y ago

The Tanenbaum-Torvalds Debate (1992)

from
3pts0
gigablast.com 6y ago

Gigablast – An Alternative Web Search Engine

from
4pts0

Except Binance didn't make out too bad in the end anyways. CZ still has billions of dollars and is looking at a pretty good sentence given the allegations. Monitorship does not entail unlimited government access to records, it mostly means a bunch of adult hall-monitors reading off compliance checklists, making sure they are being followed, then writing to the government every quarter about the remaining items on the checklists.

Yes, there's the SAR lookback, but no one reads those anyways and probably won't give the government much because criminals routinely use accounts registered with fake or stolen IDs. Binance still accepts customers from countries like Venezuela, Nigeria, Zimbabwe, etc that "respected" financial institutions wouldn't touch with a 39.5 foot pole. There are still people making $50,000 USDT -> cash transactions every day with Binance P2P.

It is if you have friends in the central bank. In Venezuela the official rate was like 10x the black market rate at one point so if you had the connections you could go say 60000 bolivars -> (official rate) 10000 USD -> (black market rate) 600000 bolivars -> (official rate) 100000 USD.

The massive profitability of this scam resulted in a number of Miami condo sales.

Reading the article:

A substantial number of debit card holders had been using cards to make bulk purchases, often in the United Arab Emirates, of gold, mobile telephones and other products to take advantage of the Egyptian pound's low official exchange rate.

Looks like a similar arbitrage was going on here. I predict they will introduce more capital controls to stop bleeding forex reserves, which won't work and then they will eventually be forced to float the currency, resulting in massive inflation that will stabilize in a year or two. Or they'll just continue on like Argentina and let their economy languish because they refuse to recognize economic reality.

There is generally no criminal prosecution for paying ransoms. There might be if the ransomware group is sanctioned but that would true regardless of payment method. If a public company paid a ransom via cash or by buying a bunch of bitcoin through an exchange they would still have to make the same 8-K filings and accounting changes etc.

Yes, I am aware. I just think people here overestimate the reversibility and traceability of the traditional system. If you're a business and you're defrauded/hacked and don't realize within a week (usually even less time), five will get you ten that money's never coming back. It went to a mule who withdrew it as cash or wired it overseas. And there's no Reg E for businesses so your bank isn't going to help either.

There's something called "business email compromise" with annual losses about 10x that of ransomware. It relies on tricking companies into paying invoices to an attacker controlled bank account instead of their actual vendors' bank account. Google lost over a hundred million dollars to some Latvian guy who was able to pull this off by pretending to be Quanta Computer. There's also just bank fraud in the Zeus style where they transfer $200000 out of your account to some company in China or Bulgaria.

These scams are all still incredibly profitable despite relying entirely on the regular financial system. There is no reason to think ransomware would stop in the absence of cryptocurrency given that extensive infrastructure has existed and currently exists to "cashout" proceeds of fraud. And in the ransomware case it's even easier because the victim is willingly making the payment, and the attacker can just not give the decryption key if the victim trys to stop the payment in any way.

And yes, this scales. If you ever looked at the promoted stories on Snapchat a few years ago, you may have seen a user with the name "The Billionaire Gucci Master" living a very opulent lifestyle. That was all paid for with business email compromise money.

You are aware that Milošević and Tuđman both agreed to carve up Bosnia, right? And there was Varivode, "Operation Storm" where the Krajina Serbs who didn't flee quick enough were raped and pillaged, and a whole bunch of other cases. Milošević, the JNA, Srpska, or the Serb "volunteer guard" may have been the worst but there are plenty of contenders for second place. Not to mention the Bosnian mujahideen.

Yes, it lowers criminal margins by 10-20%. So what? For it to make a meaningful difference that number would have to be a lot higher. And it's unlikely that the current approach to AML will result in that number changing substantially because criminals only need one weak link in the financial system to undermine the whole AML apparatus.

Most economically driven crime has very high margins. Wholesale drugs in the Netherlands cost ~10 times what they do in Colombia, and I don't think "only" 8xing your money on a drug shipment instead of 10xing it is a very good deterrent.

Edit: And you can look at threat intelligence company reports to find that Russians already sometimes pay in excess of 40% to "cashout" business email compromise or investment fraud wire transfers. They happily pay this because even getting half of $80000 when all it took you was sending a few emails with forged From headers is a great deal if you are already morally bankrupt enough to stomatch stealing.

7% of GTO reports identified individuals or entities connected to ongoing FBI cases

So... 93% of people had their privacy violated for no reason. And that was with the current highly targeted measure. When it is applied to all real estate purchases it'll be more like 99.9%. But sure, we should be willing to give anything to satisfy a handful of "transparency activists" who don't do anything besides complain all day (read about the scandals at Transparency International and you'll find that perhaps these people are not the saintly do-gooders they are reported to be).

The FTC's incredibly low win rate in federal court should be a source of agency-wide embarrassment. The only place they reliably win is their kangaroo "administrative courts" in which they act as the judge, jury and executioner but those are probably on their way out. But it doesn't even matter anyways because the new strategy is going to be outsourcing enforcement to Europe.

Myanmar has had multiple ongoing civil wars since 1947. Kachin conflict, various disputes in Shan State, Karen conflict, Rohingya conflict, etc. It's way more complicated than just Facebook. The ethnic tension was always there because the majority Bamar oppressed the minority groups. The fact that these regions have jade, gold and timber hasn't helped either. These lawsuits are nothing but another front in the "shake down tech companies" war.

They are likely referring to Homeland Security Investigations, a division within ICE which is basically like a parallel FBI that handles white collar/CSAM/high level drug stuff. Usually not immigration related unless its related to migrant smuggling or visa fraud.

It also is just a misleading set of complaints by a bunch of activists.

CASSARA: ... overseas doing training, talking about the importance of cracking down on money laundering. And I would invariably have a student or a colleague come up to me and say, “Yeah, Mr. John, I hear you, but we’re conducting a money laundering investigation in my country, and it goes to your country, it goes to the state of Delaware. We can’t get any information about this company. Can you help us?” There was nothing I could do, and I was just embarrassed. Just embarrassed.

If these overseas people really did trace money to Delaware then they would not have a problem getting the beneficial owners because banks are required to store it under the customer due dilligence rule. If you say "well they may have given the banks misleading information" then there's no reason to think they would have given the government the correct beneficial ownership information either (courts in some circuits have held giving fake KYC data is bank fraud [punishable by up to 30 years in prison] whereas the penalty for deliberately submitting false information under the Corporate Transparency Act will be 3 years).

WEITZMAN: ... Why would we set up a bifurcated system like that? Only because Delaware doesn’t want to add another question to its form, “Who are you?” And then ask its registering agents to verify that you are who you say you are.

CASSARA: The bottom line is it comes down to money, okay?

Half the reason the registry was established was so that it would be *unified*. If states (plus the various territories of the US) were storing ID information all on their own special systems it would delay the implementation of the registry by decades. So they made one federal government registry. Yes, there's a trade off, but the alternative is no registry.

The sad reality is that Paypal doesn't serve these territories because they are "high risk" and also low income which means the amount of compliance officers they would have to employ to watch people in these territories and the regulatory penalties for accidentally letting a Hamas transaction slip through (these aren't easy to detect either as the government emphasizes that "terrorist financing" can be as little as a few hundred dollars at a time, in fact most terrorist financing prosecutions involve amounts < $10000) probably does not exceed the amount of fees they would earn.

Of course all the countries mentioned in the article are all the kind of country where 10-20% of the people on the government payroll don't even exist ("ghosts"), no bid contracts are routinely handed out to friends of the government (and sometimes even current employees of the government!), spend ridiculous proportions of the budget subsidizing gasoline to buy votes, etc. Why are these countries any more deserving of forgiveness than countries that act responsibly?

Is there any reason to think that this Kılıçdaroğlu guy is immune to the environment and all the pressures that create people like Erdogan? There are a million other examples of what I described above. Maybe he'll be different but I don't think there's any reason to assume he's anything special.

Anybody else tired of hearing about the woes of the "opposition" in all these 2nd/3rd world countries? They're always framed by journalists as these heroic freedom fighters, uncorruptible, etc but in reality it seems like they just want the proceeds of looting to go to themselves and their party instead of the current people in power. Barrow may be a better than Jammeh in the Gambia but not by very much, Aung San Suu Kyi let the Rohingya genocide happen, Alpha Conde was supposed to bring "democracy" to Guinea but ignored term limits and killed a bunch of protestors, etc. Just a different cast of thieving fools.

Now that the complaint is unsealed this guy is probably never going to leave except at gunpoint. Plus he "only" made 18 million (who knows how much of which has already been spent) which is a lot but probably nothing compared to cardholder losses and other people in the stolen card chain. Why didn't they try to shut down Joker's Stash earlier before they walked away with 9 figures and why did they let Russia take down UniCC/Ferum which means none of the actual victims will get any restitution? Disrupting a marketplace that benefits from network effects and reputation is vastly preferable to some inexpensive service that most people here could probably create in a weekend.