Career Choice Tip: Cybercrime Is Mostly Boring
krebsonsecurity.com
krebsonsecurity.com
But also, I have just known lots of computer people that liked to work on their interests late into the night in a dark room.
You might say Cyberpunk styles are a source. https://en.wikipedia.org/wiki/Cyberpunk
To be honest it’s as old as capes, we’ve just lost the cape.
Do people really think it’s exciting?
First, that most jobs in cybercrime involve selling services to end users and whenever you sell services you not only have to provide customer support which sucks but your customers will have reliability and usability expectations which become annoying to fulfill when you have to maintain your infrastructure in a clandestine way.
Second, most of the positions in criminal orgs involve low skill bitch work because if you had the skills to do the real programming / security / ops work required to do more creative cybercrime then you could easily go get a legitimate job with great pay or go do your own thing.
"Digital Marketing is the hot new thing. It allows people to buy and sell through the internet". Have you been asleep for last twenty years?
Jesting aside, I think these terms are added to differentiate from things occurring in other spaces or channels. Fraud exists, sure, but it is varied. Email fraud might share some patterns with mail fraud, but I suppose there are differences dictated by the vectors being different, even for cases like email/mail where one word signifies the other nowadays.
The reality of course is much more mundane and the majority of cybercrime is lots of grunt work and a major dose of luck, there is no “silver bullet” skill or hack that will allow you to breach into any system and do anything, it all depends on how lucky you get with unpatched hosts or users being stupid. For every high-profile hack being reported there are hundreds of thousands more “hackers“ banging their heads against the wall not being able to make any progress beyond basic spamming.
I get that impression too. I do some cybersecurity type stuff as a hobby and was hoping to make a business out of it somehow but it doesn't seem to be a easy market to crack.
There are 2600 companies in the space and they almost all do one small thing (and lots of them don't do it terribly well).
It turns out what every company wants is more of a comprehensive turnkey solution than exists, or at least a highly modular framework that can accept modules from other vendors. Companies generally don't understand that security is an attribute of everything, it isn't an end product. Hence executives would rather pay for a blinky box than remember to incorporate security planning into every other expense. Also most companies aren't willing to pay much to a cybersecurity vendor because cybersecurity is largely seen as a cost center and not a profit center (because that's accurate most of the time).
I got into bug bounties for a little while, but the work is tough. Selecting a program which pays out enough and doesn't have all of the low-hanging fruit picked is difficult. It's the kind of work where very well organized bounty hunters will take the lion's share of the winnings, which doesn't lend itself well to developers who can make a healthy salary elsewhere.
Source: I work for a cybersecurity startup.
The payoff is always fantastic though. Whitehat or blackhat, knowing that all that hard work and grunt pays off is a wonderful feeling. I tend to veer towards whitehat stuff though because of the old saying: 'If you can't do the time, don't do the crime'.
No thanks. I met a girl from Harvard and discovered that I actually liked talking to a smart human about real things. There was no comparison.
Fighting cybercrime must also be mostly boring then, as it is also done through pay-for-service offerings.
So the cybercriminal side is much easier.
That said, you do have to know the defensive side well, even if you don't implement it yourself.
That's rarely a problem with authorised white hat work.
Yeah dumb people will focus on hacking but once you think it through you see there isn't a good exit strategy.
Authorities follow Bitcoin transactions and ask questions which points them right to you.
This is what these investigators do all day... track money as people try to move it around. They are good at their jobs
You pay a few percents of fees, and it's not "the NSA will not be able to find you", but it was more than good enough for my mildly paranoid ass.
Chainalysis says that Coinjoin introduces taint: https://go.chainalysis.com/rs/503-FAP-074/images/Advanced-Ob...
I believe that if someone uses something that's private by default, then its okay. However if someone uses someyhing that isn't private by default, but goes through efforts to try to hide the source of the funds, then it's suspicious.
I'm interested in facts, not rumors.
Become an artist, sell albums, people buy and gift your albums using iTunes gift cards?
I'm not sure if either are still viable as it seems like money laundering is a treadmill where the older techniques become liabilities and require constant refreshing of tactics.
I withdrew about $13,000 a few months ago, and my (national) credit union didn't hesitate or ask me anything (except for an additional piece of identification).
https://finance.zacks.com/federal-banking-rules-withdrawing-...
The teller asked for identification which exactly what the law requires, so it doesn't sound like they screwed up.
People make one-time withdrawls of large amounts of cash all the time.
Lesson: when you legitimately need $30K cash, just withdraw it in one transaction. Never ever withdraw $5K every week for six weeks. For every SAR, there are 100 CTRs filed.
I'm aware of structuring, but I don't think most people are. I've heard about it only once in the news where a store owner had his money seized because he was trying to avoid depositing more than $10,000 at a time, over a long time period.
IIRC, this was the case: https://www.forbes.com/sites/instituteforjustice/2015/05/05/...