Researchers hijack botnet, score 56,000 passwords in an hour
arstechnica.com
arstechnica.com
The Ars summary of the report seems strange (I've not read the whole pdf) in a couple ways:
They talk about percentages of private behavior getting scooped, but not about percentages or numbers of credit card or bank account users/passwords (which they indicate were the primary targets of the botnets).
And weirdly, Ars says, "Torpig controllers may have exploited these credentials for between $83,000 and $8.3 million during that time period..." Funny numbers. ?it just happens that the range is 8.3 x 104 to 8.3 x 106 ? Makes me wonder about overall accuracy of post/report.
Edit: From the pdf
"A report by Symantec [37] indicated (loose) ranges of prices for common goods and, in particular, priced credit cards between $0.10-$25 and bank accounts from $10-$1,000. If these figures are accurate, in ten days of activity, the Torpig controllers may have profited anywhere between $83k and $8.3M."
As an aside, these amounts are a good reason you should you your credit card instead of your debit card.
I am surprised that browser password managers are so insecure. This seems like a place that browsers could improve.
(a) Which global task force does this fall under?
(b) Who pays for the research, prosecution, and housing of inmates?
(c) Who pays for the astronomical travel/M&E costs for traipsing the globe to catch ip addresses?
(d) Is what they are doing actually illegal in the country they live in?
(e) Who pays for the legal teams who have to go to every single ISP and ask for records?
etc, etc, etc