The author implies that the whaops hackers had their own malware, written in Delphi, to do the on-lan redirection.
Yeah, and on rereading the original article, the hack was just guessing the passwords to admin AIM accounts. I hope it wasn’t mine! From my perspective that is “works as designed”. I don’t think the TFA was ever put into AIM login, but it was all a while ago. But anyways, nice to seem one of the dumb names I came up with in the press. I also wrote wam (web authentication module), Hermes (messenger of the Gods - like buddy list but where users could add data sources to the list, with filters or alarms), Ewoks (“external web Oscar knowledge server”, an http server that allowed for easy integration into the server message framework we used) and re-wrote morf “master Oscar registration facility”. The original was a custom written no-SQL DB and we moved it to Sybase with sharding.). All C. All event loop based. All really solid infrastructure written by people doing it for the third time. Fun times. Had an actual agile process and brought the coolness of the internet to many people for the first time.
Don't forget that PayPal's original idea was a Palm Pilot app that replaced all those pesky hardware tokens.
Presumably PayPal were intending to do an app + hardware module - or was this essentially "LeT's MaNaGe RSA KeYs UsInG NoN MeMoRy PrOtEcTeD CoMmOdItY HaRdWaRe RuNnInG a NoN SaNdBoXeD KeRnEl"?
In retrospect, this would have been at least as good as the real securid dongles.
Also by then, the super genius software folks started getting replaced by MBAs who would rather developers be idle than work on stuff that wasn’t prioritized.
And I don't know if these things had protections against being opened anyway.
Waiting for the code to roll to get through a couple jumphosts is pretty excruciating.