11 ms·
I feel like this is a new golden age in being a blackhat. Back 5-10 years ago there was no IOT and all databases were password protected by default. Now we have
by Will_Do 10y ago
I feel like this is a new golden age in being a blackhat. Back 5-10 years ago there was no IOT and all databases were password protected by default. Now we have:
1. IoT with basically no security
2. No(Auth)SQL.
Also, dev time has become so expensive, the InfoSec teams in the companies I've worked at have had shockingly low head counts for all the responsibilities they have.
- bostand 10y ago3. Bitcoin
- 21 10y agoIndeed, bitcoin is the true enabler. But the dangers are pretty high. You never know how ten years from now the digital trail you left comes back to bite you. Cashing large amounts it's not trivial. Sure, you can meet in private locations with local bitcoin buyers, but when you have $1 mil to sell it gets tricky, there aren't that many buyers in any particular area. And then you have the problem of justifying how you suddenly have one million.
- branchless 10y agoWhat actually happens when you try to get out of bitcoin? Let's say I put in $5k a few years back which is now worth $100k. I have to go on the exchange and nominate a bank account then sell then they transfer say USD into my account? At this point is this "capital gains" taxable? Assuming I'm willing to pay the tax if it's due has anyone had trouble with authorities questioning your new cash pile say if before this you had no real money and lucked out on Bitcoin?
- olegkikin 10y agoThe government doesn't give a shit, as long as it's legal and as long as you pay the taxes. Bitcoin isn't the only thing in the world that goes up and down in value, so it isn't new from the tax perspective.
- SomeStupidPoint 10y agoTo be fair, the IRS doesn't care if it's legal, as long as you pay your taxes. There are rules about how you report your illegal gains (and deductions on them).
- yason 10y agoYou have proof of this as the bitcoin transactions are public. The taxman can verify that you bought your coins five years ago and sold them this year. Multiply those by the BTC exchange rate five years ago and now, and it should be obvious that you put in 5k and got out 100k. You could've bought stock, or other currencies, but you bought BTC and it skyrocketed.
- lisper 10y ago> The taxman can verify that you bought your coins five years ago and sold them this year. How? The public block chain only contains records of how coins moved from one wallet to another. It doesn't have any information about who those wallets belonged to, or what the terms of the transaction were. Maybe the coins were sold for fiat currency, or maybe they were compensation for goods and services. There's no way to know just from the information in the blockchain. [EDIT] Let me make this more clear: it is easy to anonymize BTC. It is so easy that the technique even has a name (bitcoin tumbling) and companies that will do it for you as a service (e.g. https://bitlaunder.com https://bitlaunder.com). (I thought this was common knowledge around here.) In the face of these facts, how is the IRS going to enforce the tax code against a someone who tumbles their coins?
- toomuchtodo 10y agoAt some point the wallet will correlate with meat space.
- deleted 10y ago[deleted]
- lisper 10y agoYes, but if you want to enforce the tax code against dishonest actors it is not enough to correlate "at some point". You have to correlate an entire sub-chain and show that all of the intermediate wallets were controlled by the same entity. (See the update to my OP.)
- ra 10y agoJust keep the documentation for purchase and sale, and for any costs incurred while holding / transacting your BTC. Speak to a local tax advisor about CGT. 100k is a significant amount and I would advise you don't intentionally break the law "cashing out".
- leakybit 10y agoOr you could set up a corporate bank account in the Caymens and cash out via btc-e (which is Russian) and not pay any tax.
- LeoPanthera 10y agoA fresh Coinbase account will let you sell $15,000 a week, and I assume that this increases over time.
- nemoniac 10y agoThat depends what country you're in. In my country there is no capital gains tax.
- deleted 10y ago[deleted]
- supergreg 10y agoOr you could, you know, use Bitcoin as money instead of trying to convert it to Dollars all at once.
- golergka 10y agoEarn Bitcoin as blackhat, then use it to order pizza to your real address. Seems like a solid plan.
- goatsi 10y agoGo to Alphabay and purchase some drugs. Buy MDMA at $9-20/g, sell it at $80-100/g. Buy LSD at $1/blotter, sell it at $10 a blotter. Buy Xanax at $0.90/pill, sell it at $2-5/pill. Obviously you need to make some connections for this to work.
- navait 10y agoThe idea is to put yourself at less legal risk, not more. The penalties for drug dealing are pretty harsh in most of the world.
- RangerScience 10y agoI tried tracing Bitcoin transactions once. Not being a security professional in any way, you should take my opinion with a grain of salt, but what I found was that if you send the coins through a mixer, it's probably impossible to figure out where they went afterwards. There's just way to many ways to obfuscate where they ultimately end up, with even a bit of effort. With proper precautions, I would not expect to be tracked down through the coins themselves.
- KON_Air 10y agoAlso anyone who can trace bitcoins just won't let themselves be in such a position to begin with.
- awqrre 10y ago
- prebrov 10y agoGet an airplane ticket, fly to China or Russia or Cayman Islands, cash a gazillion of bitcoins into any currency you want or gold bars or pebbles. Done! Naturally, you'll have to shell out some "transaction fees" to some authorities, but that's just standard laundering thing.
- ycmbntrthrwaway 10y agoBefore bitcoin and even now there are options such as liberty reserve and web money.
- nickjarboe 10y agoThe major plot point of Neal Stephenson's novel Reamde (2011) was people paying off ransomware in a MMORPG with in-game gold which was easily changed for real money. One of the characters makes the comment that ransomware was not possible until anonymous payment online could happen. It would be interesting to know when Stephenson became aware of bitcoin.
- peterwwillis 10y agoIt's been the golden age for script kiddies ever since fuzzing and injection became the most effective blind attacks. Who needs a database password when you have %27 ? It used to be you had to actually break into a system to exfiltrate all its data. Now you just make an HTTP query. Owning a big system was really important because bandwidth and server space was expensive. Now you rent some VPS space with bitcoin you made from spam or DDoS-for-hire using someone else's botnet that had been sitting around with a default password, and use it to distribute pirated media like it's text files. Mass-scan for SQL injections, inject some malware you found on a forum, and amass a botnet to play with. What a time to be a script kiddie. I'm not sure about the modern age, but to me the golden age of blackhats was pre-2003, when nobody was really watching their networks or systems and advanced techniques were everywhere with zero defenses. Metasploit and the age of shitty webapps and packaged malware ushered in the dumbing-down of blackhats as a general concept. (Get off my lawn!)
- matt4077 10y agoI'm not sure if security didn't actually improve dramatically. Web frameworks seem to have SQL injection and cross-site scripting more or less under control these days. Cloud setups and containerisation should also help (servers are more easily rebuild and therefore more likely to be fully patched, infrastructure-as-code is easier to review, most servers/containers are only running one service etc.)
- peterwwillis 10y agoPatching is not easier now, and wasn't difficult before. There's more steps now, it's not easier to review. Look at it from the blackhat perspective. I don't care what the hell loops you're going through on the backend. If there's a 0day, i'm going to use it and it's going to work, because you don't even know about it yet, much less have a patch built into a binary pushed to mirrors that your Docker image building box needs to update to before you can rebuild your image and push it to your servers and do a maintenance window to switch to the new services. It doesn't matter if you are running in a VPS in a container in a virtual machine in an emulator, because I can still use an SQL call to dump everyone's passwords, or get voting records and account details for one of your political parties. If I execute code you're still going to get owned because you don't have security patches in your kernels and you don't use signed binaries (none of which are new technologies, btw). I would even go so far as to say you would never in a million years find exploited code in one of your systems because you somehow believe container apps are immune to basic vulnerabilities. Containers are just fancy chroots.
- simonjgreen 10y agoIt reminds me of the days of everyone running open WiFi or even wep
- paganel 10y agoI run open WiFi at my home, I still pretend to live in a world where sharing your Internet connection is just basic human decency. I inspect my router's logs from time to time to check for huge blobs of traffic not coming from my devices, and that's about it.
- madgar 10y agoI'm guessing you live in an actual house. If you don't mind my asking, how big is your lot? My parents retired to a house on a quarter-acre and they pick up a couple neighbors' networks with good signal.
- paganel 10y agoNo, actually I live in a block of flats/apartments. Up until a year ago I used to live in a block consisting only of studio apartments, so I had lots of neighbors, since then I've moved to a "fancier" area and to a one-bedroom apartment and I only have two other neighbors on my floor. I don't think I've ever seen a non-encrypted wifi connection among my neighbors for at least 3-4 years now.
- sudojudo 10y agoIt's really nice that you share, and encourage an open community, people like you have certainly helped me out in the past. Open wireless routers were far more common 10-15 years ago, when ISPs first started pushing them. Most people hadn't warmed up to the technology yet, and security was barely on the radar; similar to what we're currently seeing with IoT. Maybe you have no enemies and trust your neighbors, that's awesome. But, anecdotes aside, someone could cause some very ugly problems with your open wifi, without much skill or effort -maybe just for the lulz. I feel like cheering you on for giving people free internet, but at the same time, I want to pull you aside and say "hey crazy person, please put a password on your WAP." Because, it's a bummer when bad things happen to good people.
- chaotic-good 10y ago>> No(Auth)SQL. Absence or presence of auth is irrelevant. You're database servers, message queues and other infrastructure shouldn't be accessible from the internet. No auth protocol can protect you from this.
- cm2187 10y agoIf the default settings are dangerous, then the product is to blame, not the user.
- spacemanmatt 10y agoThe stakeholder who blames just one layer of security for a breach is gonna have a bad time. Truth is, the same reason why people don't change the default (no security) also explains why the server ends up too close to the border. They're cheap and/or ignorant.
- cm2187 10y agoEveryone is ignorant of a product until they build experience with it. No baby is born with innate knowledge of how to configure properly a Mango DB! If a product is misconfigured by default and it takes expertise in the product to not leak data, then the product is unfit for purpose, it will burn anyone who wants to learn it. What if you learned that Linux had a massive security vulnerability that leaves the OS open for remote code execution. What would you say if a Torvalds would laugh at its users, saying that if they didn't change that low level kernel security setting, the users were ignorants and deserved their troubles? I think no one can pretend he understands all of the settings in the hardware, firmwares, drivers, kernels, many other OS layers, database, etc. We rely on having safe and secure default settings, and it is the only way an insanely complex machine like a modern server can be usable.
- majewsky 10y ago> What would you say if a Torvalds would laugh at its users, saying that if they didn't change that low level kernel security setting, the users were ignorants and deserved their troubles? That choice of example is particularly weak, given that Linux developers are explicitly working on hardening the kernel's internal security: https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pr...