3 ms·
> Furthermore, when I installed and ran a VNC server, I didn't detect any difference in site behavior - so why is it looking for it? Not an eBay employee, but
by splonk 6y ago
> Furthermore, when I installed and ran a VNC server, I didn't detect any difference in site behavior - so why is it looking for it?
Not an eBay employee, but used to work in fraud detection. Two very obvious related guesses from my experience:
1. Fingerprinting a user to help identify account takeover (ATO). Open port signatures is probably a pretty good signal for that kind of thing (and it doesn't seem to be measured in https://panopticlick.eff.org/ https://panopticlick.eff.org/).
> However it is also a valid tool used by administrators for remote access to machines, or by some end user support software, so the presence of VNC is a poor indicator of malware.
2. In a Bayesian sense, this probably isn't right. I don't know what eBay's traffic looks like but I'm willing to bet that all other things being equal, traffic coming from a machine with an open VNC port is riskier. Fraud detection is a game of probabilities, so the existence of a valid user showing a particular characteristic doesn't mean that the characteristic isn't useful in a fraud model. The example I always give is that when I was doing this (quite some time ago), we could have had a 99% accuracy rate for a simple rule banning IPs from Turkey, Ghana, Nigeria, and Vietnam. It's not because there weren't any valid users from those countries, it's just that the fraudsters where overwhelmingly likely to be using IPs from those countries.
- gfxgirl 6y agopanopticlick is specifically about browser fingerprints. It doesn't include your IP address for example.
- loa_in_ 6y agoCan you say what were the final false positive rates? Was this part of your research?
- thejynxed 6y agoThose four are still considered untrustworthy, and I've had to add India, Ukraine, and Brazil to the list of nations I filter entirely.