6 ms·
This is suppose to help with fraud? Lets be serious for a moment. The only thing that this is going to change is that the supposedly hacked computers will no lo
by crypt1d 6y ago
This is suppose to help with fraud? Lets be serious for a moment. The only thing that this is going to change is that the supposedly hacked computers will no longer run VNC on standard ports.
I think what we might be seeing here is the outcome of some overpaid consultant's claim that they can protect ebay from fraud with 'sophisticated' malware detection.
- zu03776 6y agoHas anyone investigated how this protection works? That is, deliberately create an eBay account, log into eBay using a remote tool, and trigger the fraud detection? My curiosity is piqued, but I don't have an account to offer up. I'm wondering if eBay displays a fraud warning, or pretends to allow the transaction to occur (shadow bidding?), or just hellbans the account being used. For shill-bidding farms, the obvious counter is to move remote screen access to non-standard ports, or move to headless browser operation via other scripting methods.
- phire 6y agoIt probably does nothing directly. It will just feed the data-point into an anti-fraud/anti-spam system along with everything else. And the anti-fraud/anti-spam system is probably a machine learning black box. It will learn if this data-point is actually correlated with naughty behaviour, and what other factors are usually correlated.
- tinus_hn 6y agoIt might be some kind of system that tries to determine if the client is a ‘normal’ browser.
- badrabbit 6y agoIt helps but there are projects like censys.io and shadowserver ebay can use instead of a direct scan. Bad guys do use compromised seevers and devices,often it's bind() shell (like a webshell) that can easily be detected. I think it helps when they use compromised hosts as proxies to avoid IP restrictions.
- faizshah 6y agoYou greatly overestimate the people who run these remote access scams. They struggle to edit html in devtools and a simple overlay element takes them >15 minutes and calling a supervisor to delete. Check out some of this guys videos: https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw
- anon102010 6y agoLet's be serious for a moment. A computer that is hacked and running remote access programs poses a MUCH higher risk of account hi-jacking for ebay and paypal purposes than another computer. Feed that into a system that monitors lots of other inputs, and you start to build improved fraud detection systems. Most of these systems benefit significantly from long tail / long history monitoring - all the other providers of systems in this space try to get beacons onto virtually all the pages you visit, monitor all mouse and other movements you carry out etc. Why not this pretty simple and straightforward explanation vs something complicated about overpaid consultants? Amazon does $80B of sales or something per year. Each 1% of fraud on this platform is worth $800 million. How overpaid must a consultant be who can knock this down? I'm curious how someone with crypt in their name would ignore obvious remote access trojan installs as a threat vector?
- crypt1d 6y agoI'm not ignoring anything. I'm simply stating that this is not an effective prevention method. I'm even going to argue that this can potentially _hurt_ whatever fraud system they have in place, as it could create a lot of false-negatives. Once the fraudsters pick up on this they'll change the ports. From then on, this script is useless. At best, the result of the data points created by this script is going to create a temporary drop in fraud, which can be used by the aforementioned 'consultant' to claim (premature) victory. Give it a month or two, and the fraud numbers are going to go back to their previous levels.
- anon102010 6y agoDo you deal with fraud issues. My guess is not. "The fraudsters may adapt" is a complaint with almost all fraud fighting approaches - and yet many even older methods STILL have value even if fraudsters could work around them. Many fraudsters are using scripts and tools they don't even know how to modify but that circulate and are used. In person use has geo checks, so easy to avoid by using cards in a local area - but fraud prevention STILL picks up out of billing zip attempts at use. So you'll be wrong here. And even a 6 month decline in fraud is highly valuable to any of these large scale players.
- cornishpixels 6y agoYou're assuming that the 'bad guys' pay attention and look closely enough to even see that this detection exists and figure out how to bypass it.
- Libeste 6y agoThe ones who made the software probably are. The rest just need to notice they're no longer making money and being 1337, will get updated h4xx0r t00lz once the first group releases them.
- cornishpixels 6y agoYeah... that's very rare.