Wirecard hired actors to fool auditors
manager-magazin.de
manager-magazin.de
He became a 5% investor in our company through an entity called Max Madhouse GMBH with an option to buy a much larger share. The day after the deal was signed he turned around and tried to screw us - the founders - out of our own company through a minority shareholder lawsuit.
Eventually we got rid of him, but this cost us a lot of time, money and momentum. Two years later Bauer was one of the founding members of what eventually became Wirecard.
So I've always seen Wirecard as a bunch of crooks.
At the same time I have some sympathy for the BaFin people, there are way too few of them and the opposition was very well versed in showing one face whilst actually being something completely different, the length to which these characters would go to show a good face was beyond anything that I would have normally imagined. I'm still a touch paranoid because of it, and I'm sure the same goes for the rest of the former Camarades.com/ww.com team.
I don't know what happened to him, he seems to have disappeared as well, but I do know that anything that he's ever touched was rotten at some level.
So managers were running Powerpoints on Apple while engineers were running Python, aws-cli on Windows. Perfectly reasonable according to them. I could only estimate the amount of productivity lost on this. Of course WSL was not allowed because corporate security classified it insecure.
I only saw good machines in companies where only software was their business(mostly web shops) so management there knew the value of providing good laptops and monitors.
Still, that's yet another version of the beancounters perspective.
My biggest Zoom gripe is being unable to control how much bandwidth it uses. 360p is fine for the others and I on the call when we’re not sharing screens.
If it weren’t for that, I could télé-work from the cabin a lot more... stupid Canadian mobile providers...
Even Jira is not too far off these days unfortunately despite being a relatively simple tool (but they needed to justify hiring tons of JavaScript developers).
if you want teams to go through a proxy, they basically say "open all ports tcp and udp to microsoft.com + even more" I think it might be like 52.0.0.0/8 or something
There is no way most company issue laptops can run two programs that resource heavy at once, without Windows 10 randomly closing other applications or flashing a black screen at you.
I opened up the api recently to discover that every story I edited had close to 100 custom fields on them, most duplicative (presumably) and hidden.
The only time I see MacBook are when we get the consultants visiting us. They are always decked out in the latest Apple gear.
Switching everyone to laptops is the biggest productivity loss in engineering departments.
I only had to deal with one situation like this in my life, and the person responsible is now no longer welcome in my county, so we sorted it out.
Another Bauer story; prior to the investment: he had fear of flying, and was an asshole to the people that he perceived as lower on the social ladder than himself. So when he was nasty to the stewardess on a very small airplane (10 seater, twin prop) flying from Los Angeles to San Luis Obispo and the pilots caught on to his fear they got their revenge on him by doing all kinds of borderline legal aerobatics with the plane.
Bauer and I were the only passengers, I had a great time but made sure to sit where it was safe. He was as white as a sheet when we landed, and made a great point of being polite to the stewardess on the way back.
One asshole deflated, props to those pilots (pun intended) for standing up for their colleague.
so, someone was socially rude, so some pilots decided to risk the lives of everybody on board to teach a lesson.
Aerobatics , even if 'borderline-legal', are still more stressful on the plane and components.
Stress still causes early failure, even if the stress was produced with legal maneuvers.
Hopping curbs in a passenger car is not usually illegal, it'll just destroy the car prematurely.
Spontaneous aerobatics still risk injury from gravity-flung objects in the cabin.
So, i'm glad the person you dislike had a lesson taught. I'm less glad that the crew acted unprofessionally.
I'm very glad that no incidents occurred as a result. The sky isn't the place for revenge and vengeance, especially on passenger flights.
I really hope that the crew has matured since then. There are plenty of ways companies and professionals can refuse service without risking collateral damage like that.
GGP made an assumption and then reacted to that assumption as though it was a fact. We weren't doing loopings or Immelmans, just a couple of nice steep banks and a pretty steep ascent/descent. If the plane would have not been able to handle that it shouldn't have been flying in the first place. I've been through lots worse in single engine GA planes in rural Canada.
Not legally, morally.
I tend to think so, given that creating a thrill-ride is outside the scope and purview of being a private pilot.
A professional, acting outside the scope of his profession, who seems to be acting with malice or disregard creates a situation that could quite literally kill a person who has certain conditions (even unknowingly).
>Noone's life was at risk.
I can't do the mental acrobatics that are necessary to see that as a zero risk situation.
It's not just the airframe that the pilot is tasked with worrying about, the safety of the occupants comes first.
This goes beyond your comment: but sometimes it feels like there is a growing tendency to value safety - or perceived safety - over the rest of our humanity.
Does that second paragraph make sense?
The result? Just look at how effective militant French protests have been in keeping neoliberal attacks on worker rights at bay, and how unsuccessful German protests have been.
It is sad that there are cultures where that's different.
It's funny to see how in many Western governments the (legitimate!) protest of the people in Hongkong is cheered upon, but BLM, Yellow Vests other domestic protests are discarded...
Saying "violence is unacceptable" is something one can only say as a member of the privileged majority. For minorities, for marginalized people, for poor people though... the lines are way more blurry than blanket black-and-white statements.
And for the record: I'm not a friend of pointless militant acts but I will not dare to judge over anyone not as privileged as I am to come to a different opinion.
P.S.: You have no idea about my gender, skin color, sexual orientation or social class. Please don't just assume things.
Don't know if this makes me an asshole or a human.
I assume the GP was just abbreviating a more complex phrase that it's easy to guess, isn't it?
The state, perhaps through the police or military, can exercise violence often without consequence. You can legally be violent in self-defence, to varying extents.
Some states will even let you carry firearms around in case you need to apply violence in self defense.
None are more hopelessly enslaved than those who falsely believe they are free. - Goethe
It's useful to have additional conversational tools to engage positively, such as:
'oh yes, that is an improvement on what I said', or
'I appreciate what you said but I was trying to make a different point, which is:', or
'That's a useful way of capturing what I was trying to say', or even
'Yes, I see that what I said was not quite right, thank you'.
But also, US gun laws insofar as they pertain to the use of guns for self-defense aren't as anomalous as many people think they are. There are a few other countries in which it's possible for a regular citizen to get a permit to carry a handgun openly or concealed - Czechia, for example.
None of this is in any way a defense of the monstrous collateral damage of the U.S occupation or of the U.S government's reasons for that war, but now that it's happened, the country is better off than it was under Saddam himself.
To transfer several trillion dollars of US wealth into the military and oil industries?
Sometimes actions don't need to be acceptable, they just need to be impactful.
- Carl von Clausewitz
- Asimov
Sometimes it's better to punch someone in the nose Monday to avoid a shootout on Friday.
When it comes to clear cut cases of survival, do whatever you have to do.
The problem is when the scenarios are not nearly so clear cut - even if they may seem to be to the people in the scenario at the time.
I never punched anyone, but people who ruin your life as described by the commenter deserve it, maybe they’ll become better people.
That seems like the logic of a supervillain or sociopath. "When they did something bad, it's because they're a bad person that I'm allowed to hurt, but when I'm violent it's because I'm making the world a better place."
There may be times when that works, or it's the least bad option, but my instinct tells me that the sort of person that most deserves a punch is also the sort of person who is most likely to respond to that violence by doubling down and hurting more people (their victims often being those who can't defend themselves).
Why are they making other people’s lives miserable? It’s not fair and the law doesn’t protect you.
This won’t change their opinion, but it might very well stop them from acting out again.
IMHO. I have no psychology background.
I've no doubt violence begets violence in most cases, but it can also improve the situation for both sides in others.
The powers that be use the state to inflect violence on people that don't have rights and power and no one thinks that's illegitimate.
I mean, they weren't versed enough to fool many Wirecard shorts or financial journalists, who had a lot less authority and power to investigate the inner workings of the company. Maybe in the absence of these warnings they could be excused for missing it. But when you get it handed to you on a silver platter?
A lot of these auditors come from a financial background and they treat IT in much the same way, as if there is some kind of checksum they can calculate which will tell them if the company is healthy from an IT perspective or not.
Companies that are certified tend to be very good at process but are sometimes surprisingly bad at the actual IT. But it's all documented perfectly.
That said, all the ISO standards are corporate moonspeak and bullshit themselves and do not bear any practical sense. (All that, for example, looong document on infosec ISO 27001 says is "try to be secure, my friend")
So as a rule we treat an ISO 27001 certificate not so much as a checkbox item meaning we can skip certain parts of our audit, but as a nice-to-have which may help speed up the interview process because we at least know what terminology to use.
In practice there is too little difference between companies with or without such certification to see it as anything other than a marketing tool.
She left after a colleague who apparently spent most of his time asleep in a cupboard got promoted over her....
NB It was financial auditing not IT.
Leaving was the best option that your wife had, in such a case you really don't want to stick around until the house burns down.
To make gov agencies happy? Or investors? -- who are those who care
(And good if they do mostly nothing)
Best plan for everyone is to get out of shady companies like that ASAP.
Ok so that's not how things usually work?
In most? companies internal auditors do real work, would you say? (I'm clueless)
For the individual auditor: if you're a chartered/certified accountant you can get into a lot of hot water, including possible jail time.
With this situation, there is a reasonable expectation for EY to lose clients. Partners will also face some consequence. Most likely they will be let go and removed from accreditation by CPA (in the US). There are several high profile cases where partners get sacked[0].
[0]: https://www.ft.com/content/5179fb94-fd6c-11e8-ac00-57a2a8264...
As for the guy sleeping in cupboards...the staff at those firms reguarly work 80 hour weeks (not the "I work 80 hour weeks counting all kinds of stupid things" but the "I was at the client site or in the home office for 80 hours this week". It was a very common occurence for hard working staff members to take naps at the client (most likely because last night was a 2am night). Promotions at these firms are often very competitive as the organization is an "Up or out" organization designed to chew up fresh college grads.
The peer review is conducted by an independent evaluator, known as a peer reviewer. The AICPA oversees the program, and the review is administered by an entity approved by the AICPA to perform that role. 2. The peer review helps to monitor a CPA firm's accounting and auditing practice (practice monitoring).
That's a big claim for you to make given that you don't know the company, the size of their clients, or even whether or not anyone went to jail over the proceeding decades.
I would also ask myself how far the rot went, because if (for example) this organisation was also supposed to audit the government and yet promoted those who “slept in a cupboard” over those who worked diligently, then I would expect the country to suffer a very large and very surprising economic disaster.
That said - don’t despair! The purpose is NOT to catch purposefully-fraudulent CFOs. That’s the SEC’s job. It’s much more of a forcing mechanism for otherwise-honest CFOs: they know they have to justify what they’re doing somehow, and the auditor knows that if something will inevitably blow up anyway, they can’t sign off. So it just arrests the slippery slope when honest mistakes are made.
What does that mean? Not a native speaker, dictionary not so helpful
While “arrest” normally means a police officer putting someone in handcuffs, it is derived from derived from the French word “arrêt“ meaning 'to stop or stay', and can still be used in that sense.
Thus, “arrest the slippery slope” means “prevent bad behaviour”.
In the end I implemented both my solution and his. Mine worked like a charm, his literally caught on fire (it was power electronics development). Got fired anyway...
Just say "yes", and work on your job-hunting instead.
Makes me slightly wonder if the manager had hidden motivations and didn't want the project to succeed
The manager was one of the company owners, so he was well motivated, but he was an academic with little world experience that though he knew better than the industry.
Audit is really freaking expensive; Domain experts too. While there is a checklist that given to the auditor, the person asking those questions are usually senior or early manager level. The person has little experience in IT but usually has a small BS detector because of previous audits. That checklist is then sent to an internal domain expert to verify. Follow up questions may occur.
Having said that, this is strictly for compliance and “covering your own butt”. This past year a firm was found negligent because they didn’t catch fraud because they simply “checked the box”. Since then, most firms have introduced rudimentary IT training for auditors responsible for said checklist. (All staff have to take the classes, when at level).
TL;DR an auditor cannot have same knowledge as IT person and audit time is expensive. They’re trained to earmark fraud and to verify, to the best of their abilities, they are not signing off on a lie. Shit is hard and no system is perfect.
1. The Public Company being audited isn't going to spend money on a real technical audit and may in the future lose customer info, etc.
2. The financial auditing company doesn't have enough experience to properly asses the situation. They did the best they could but they're no experts.
Code audits and pentesting are a thing you can buy. But yes, they're even more expensive. Turns out security isn't considered valuable enough for most.
They have no proficiency or enough people who know what they're doing. The approach is to meet the lowest common denominator set by the SEC or is expected from investors.
You can fake all of this. But at some point its easier to do the job than to fake it. Well at least this is what I hope...
It is anything but boring to me.
Not sure how reliable that is but it would make some sense, close by and hard to impossible to be extradited from there.
There is no other reasonable explanation as for why he is under the care of GRU.
I guess I’m just having a hard time understanding how a person can get themselves into such a situation. I can’t believe it’s just greed that allows it to happen but perhaps that’s naive of me.
How they might get themselves into such a situation?
Just one sample: The company might have been in financial trouble, not able to fulfill its obligations in the short term, and so a decision was made to pull in some Russian 'cheap' capital for a short term loan.
There is a very large amount of illicit Russian money flowing around and it pops up in the most respectable places.
So it isn't necessarily just greed, it could be that the investor that you are taking on board in turn is a front for that sort of capital (always ask for the source of the capital from your investors, if they are coy about it then better go somewhere else), or that the founders are too naive to realize that they are making deals with people they should stay away from (see comment above for my own personal story).
Given that there are reports that Marsalek tried to put up 15.000 mercenaries to take over Libyan border controls (possibly with a relation to the politics of his homeland Austria and it's anti immigration policy!), it may very well also be that Marsalek knew what he was getting into and went all in out of a search for fame, a real life Austrian 007.
Ugh, one of the former top journalists of "Der Spiegel" has shown they will happily publish anything that fits their readers narrative. It wouldn't be surprising if half of the facts they found were made up to make the story look more epic than it is.
(2) There are undoubtedly links between Marsalek and Russia
(3) It is plausible (no extradition, reasonably close by so family can still visit)
(4) There is circumstantial evidence
(5) Many places where he could go to would actually be far more dangerous to him than Belarus
So obviously, this is not hard proof but it is a lot better than nothing at all, if you can dispute any of the bits they list as facts rather than speculation (which they were surprisingly candid about) then that would change matters.
For now, it is the best that I could find, the list of countries where he could go, live in relative luxury and safety while on the lam for German justice isn't all that long and Belarus features near the top of that list.
A problem with that is that some of their facts are based on "documents they reviewed". I do not have these documents and I cannot find any alternative source for the DA0000051 claim. All I have is past occasions of the Spiegel making stories more exciting and interesting for their readers by making up facts.
Nobody's perfect, but if I get to chose between Der Spiegel and Fox News or Bild I know where I'd put my money.
And of course you don't have the documents, it is pretty rare that a news article would be accompanied by all the evidence the publisher has acquired, if only because that could easily put their sources at risk.
After ignoring complaints for years and threatening one of their journalists for having the gall to question their golden goose. They only came clean about because there was no denying the evidence said journalist gathered and if they let someone else publish it they couldn't put their spin on it. Their world class fact checking team at least turned out to be a group of glorified spell checkers.
(sorry, didn't really want to take this further OT, but could not resist)
Belarus. That's certainly an interesting place to be right now, and a place that has more important things to deal with than a high-profile white-collar criminal.
Fooling auditors isn't going to be all that difficult, most auditors get confused if there is too much going on in the room . I've literally seen a publicly traded company pass an audit just by making the audit frustrating and then providing every perk you can imagine outside of the audit room (including attractive men/women). As you can imagine, they didn't do a very thorough audit.
It reminds me somehow of the movie "The Sting"...
[0] https://www.focus.de/finanzen/boerse/wirtschaftsticker/schau...
I guess audit means most of the time just: checking some boxes without actually following through paper trails.
Why are people always so surprised when “disruptive” organisations actually end up doing a bunch of weird shit?
There is a site-wide off switch if you know where to look, but I doubt most people would find it.
Not that this option makes it any less user-hostile.