HNHacker News
TopNewBestAskShowJobs

ryanl0l

86 karma · joined April 12, 2016

https://news.ycombinator.com/user?id=ryanlol
submissionscomments
ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
I've been on the phone with PayPal on far too many occasions, and they definitely know how to handle these issues quick.

Although, you wouldn't even really have to call them. You can dispute the charges with like two clicks on your account page. It's just that if you call them, they can instantly settle the dispute in your favor.

ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
Most paypal fraud, like credit card fraud happens at a very small scale. A fraudster pays $50 for 50 accounts and then spends a day with them and maybe walks out with $300.

The guy selling the accounts sells hundreds of thousands of them, and obviously doesn't get involved in the fraud itself.

This is why this whole thing is so strange, there's a bunch of people claiming that someone hacked teamviewer and is now using that access for petty paypal fraud instead of targetting the tens (if not hundreds) of thousands of PoS systems teamviewer is used to manage.

>Are they hoping that a small % of their victims won't notice the fraudulent transactions?

No, they certainly don't care if the payments get charged back or not. If they try to send money to their own account, it'll be suspended before they can actually withdraw it out of PayPal.

Instead in this case they seem to be trying to buy itunes gift cards, undoubtedly with the intent to sell them (on sites such as g2a.com) before they get cancelled.

ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
RDP at home is certainly difficult, but I have to disagree on the performance bit. In fact, RDP is probably by far the best such protocol in use right now.
ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
Why would you care? You can call in and reverse the payment in minutes.
ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
>Of the hundreds of support requests I've responded to post-attack, all except one attack was carried out over TeamViewer.

And my experiences with repeatedly calling these guys had different results, that's fine.

>A tech support scam attacker would have many first-time connections to many other first-time TeamViewer users who are generally seniors instructed to run the TeamViewer app over the phone. While they may use a pool of computers/TeamViewer IDs, and a pool of IPs, there's limits to the cost-effectiveness of scaling that variation, and a pattern should definitely be visible.

And then the scammers will just switch to VMs and socks5 proxies. (They probably already use the socks, considering they're buying them in bulk)

>"Assuming proper rate limiting" seems like a large assumption, given that the possible attack vectors are guessing the random alphanumeric passwords and testing password dumps for account pairs from other services that work with TeamViewer.

The mere fact that this all happens over the network is a plenty of ratelimiting.

>Defaulting to accepting any connection from anywhere seems like a great example of poor security configuration by default.

This specifically isn't the default though.

ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
On paypal or TV? Needs clarification.
ryanl0l··on TeamViewer denies hack after PCs hijacked, PayPal accounts drained
I'm aware. But even tens of thousands of affected people wouldn't qualify as "an extremely wide spread malware".

If you spin up an exploit pack and can't get 50k hits in a day you're clueless and should consider a career outside of cybercrime.

ryanl0l··on Blizzard Exempt from iOS and MacOS Security Sandbox
I can't see how you could possibly describe his behavior as "childish" here. Pangu straight up stole his code and sold it.
ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
I'd imagine it's more about not driving all the domestic companies away.
ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
The citations do not support your original claim.
ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
Subsidiaries in countries with low tax rates certainly aren't against the spirit of the law.
ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
That's not what you said though.

>Actions that are deemed to have been taken solely for their tax effects are clearly and explicitly deemed tax evasion by the IRS

What you said would make almost all tax avoidance into tax evasion. Hell, even claiming deductions would by your logic be tax evasion.

ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
You should reconsider whatever client program you're using if it's causing issues.
ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
>Actions that are deemed to have been taken solely for their tax effects are clearly and explicitly deemed tax evasion by the IRS

This is just not true.

ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
No? Could you expand on that a little please.

Based on my reading there certainly exists such a duty when it's beneficial, obviously tax avoidance isn't explicitly beneficial though. Potential law changes or even bad press could cost more than the amount of money saved.

ryanl0l··on The Perks Are Great, Just Don’t Ask What We Do
I suggest you reread my comments as I never made such a connection.

tax avoidance=/=tax evasion

ryanl0l··on FBI raids dental software researcher who discovered patient data on FTP server
>If your story is true, then you were, as it appears, wrongfully and unlawfully imprisoned. I think you should at least try contacting press and some lawyers -- if what you are saying is a true story.

I was indeed wrongfully imprisoned, but by the Finnish government. I can and will receive compensation from them but at best that's going to be a few thousand euros per month, a nominal sum considering the time lost. It's hardly an irregular thing here, mostly because every single case where a person is taken into investigative custody and not given a prison sentence is treated as such. This has created a situation where these cases are so common that the justice system treats them as acceptable routine.

ryanl0l··on FBI raids dental software researcher who discovered patient data on FTP server
Honestly, going after the FBI for lying to the Finnish police would probably be a pretty hard case to win. Especially considering how blatantly unreasonable the behaviour of the .fi authorities has been.

It's possible that I could win. But that wouldn't really achieve anything, it wouldn't make the .fi authorities stop.

The best option I have available is to keep fighting my charges in Finland, as no matter whether I win or lose it'll be significantly harder for any other country to prosecute me for those same crimes. The courts here are fairly reasonable, while they require ridiculously low standards of proof, you essentially have to kill someone to actually go to prison here. Perhaps that makes it easier to say "guilty" just to play safe, keep the LE and prosecutors happy.

ryanl0l··on FBI raids dental software researcher who discovered patient data on FTP server
Not at all, the key in weevs case was intent.
ryanl0l··on FBI raids dental software researcher who discovered patient data on FTP server
Not necessarily. I've spent the last few years fighting various hacking charges in Finland and will most likely continue to do so for several years to come.

The law enforcement here will consistently take anything the FBI tells them as a fact, even when the information provided by them has been consistently shown to be false or even maliciously fabricated.

I spent 3 months in jail in 2014 because the FBI emailed the Finnish NBI and alleged that I had perpetrated various attacks against large US tech companies, they provided some information vaguely connecting me to the crimes and claimed to have further evidence they'd deliver shortly. They requested that the Finnish police arrest me and seize my equipment, they did so without question.

Based on that single contact from the FBI the Finnish NBI held me in jail for 3 months and banned me from using the phone or in any manner communicating with anyone outside the jail. After the 3 months had passed the FBI had still failed to deliver any evidence, and the Finnish police had failed to discover any. In fact, they had unquestionably discovered heaps of evidence against the aforementioned allegations since the very day they arrested me. Just a few days before Christmas they were forced to very reluctantly release me.

Now it's 2016 and I just recently got a letter stating that most of those charges have been dropped as the FBI has failed to deliver the promised evidence. I've also received letters informing me of various covert surveillance techniques utilized against me after my release. These are supposed to require an even higher standard of proof than keeping someone in investigative custody, but obviously they're hard to contest when you aren't told about them.

Incompetent fucks desperately hoping to score big wins for their careers or with personal vendettas are hardly an US only problem, but at least in the US I could've fought the FBI in court. That's hardly an option here. The only thing that's better here are the sentencing policies.

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
>Or major driver changes, huh? Never ever ever had I a working device driver turn nonfunctional overnight. Before this "upgrade," that is.

Blame your OEM, they're responsible for keeping their drivers functional. Microsoft didn't just go behind OEMs backs and do this.

>Who exactly got an EULA prompt on an unattended, locked workstation with nobody at the sear? As I say, the downgrade was full auto: evening W7, morning W10.

That's certainly strange, are you sure it wasn't just the W10 installer? Or did it really go straight to the login screen?

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
Haha, that's a good idea. But no, the "ryanlol" account has rather restrictive ratelimiting in place.
ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
>Microsoft can disclose, what you keep on your own machine.

Want to expand on that a little? Presumably the above quote is regarding skydrive etc.

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
>Go to "speech, inking & typing" settings. The dialog literally says they will collect your typing history.

And until someone bothers to do a MITM we really don't know what that means.

>The traffic is encrypted, and no one has been able to MITM it yet, as far as I know. But Microsoft has confirmed in the press that yes, they do this.

Are you sure? Unless they're specifically trying to prevent such you should be able to just drop in your own root certificate and MITM it with the tool of your choice.

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
>No, that's explicitly not how MS updates worked: up to now, they were updates to existing OS, not automatic reinstall.

A semantical difference really, previous windows updates just didn't include major UX revamps.

>If I don't want it, I don't get asked if I want it: 19:00 there was a working Win7 box, 07:00 next day, there was a broken steaming pile of something, apparently Windows 10. No prompts, full auto.

surely you got an EULA prompt, no?

>Program files: deleted. Users folder: moved into some other location (both).

I certainly agree that microsofts QA has failed horribly here.

>In other words, FU, astroturfer.

One could easily accuse you of the same.

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
Yeah until the users ISP drops them because of the kaiten sending outgoing DDoS.
ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
Ah, I'm sorry. For some reason I was under the impression that you were ignoring updates altogether.

Installing specific KBs works fine until Microsoft stealth patches something, which isn't exactly unheard of.

ryanl0l··on Microsoft won't back down from Windows 10 nagware 'trick'
If you really feel that way, why do you not file a police report then?
ryanl0l··on Australia’s Offshore Cruelty
Yes, I am. In fact, I couldn't even have posted this reply if I wasn't.
ryanl0l··on Microsoft criticized for changing the pop-up box encouraging users to upgrade
From my previous comment:

>And that is how you end up with another XP fiasco.

Page 1 of 2Next →