AOL Employee Arrested in Spam Scheme
LostCluster writes "The AP, Reuters, and AOL's own CNN/Money are all reporting that AOL employee Jason Smathers has been arrested and accused of taking a list of 92 million screennames from the internal AOL system, and selling it to another man, who allegedly used it 'to promote his own Internet gambling business and also sold the list to other spammers for $52,000'. Not surprisingly, Smathers has been fired."
Aren't we supposed to wait for someone to be found guilty before punishing them?
Now imagine how much personal info is being sold overseas from outsourced companies.
You would think there would be limitations on HOW an employee could access such a large database. I mean, does AOL throw out CDs with conveniently formatted lists of all the screen names of its customers?
All they did was just fire him?!?!?!? He should have sent to prison for 25 years too!
Red Bull gave me wings and I flew into the ceiling fan.
..didn't a bunch of airlines admit to (basically) the same thing? no arrests there..
--BlueLines "The cost of living hasn't affected it's popularity." -anonymous
with large, easily searched and copied databases of highly consolidated private data.
The primary issue to be feared is not that someone who isn't trusted with the data will get ahold of it, but that someone who is trusted with the data will turn out to be untrustworthy.
The same goes for backdoors. I'm not half so worried about some script kiddie hacking my router as I am some employee/former employee of Cisco simply walking right in.
KFG
What worries me is that there could easily be many more employees doing this - not just at AOL, but at other ISPs as well. However, I'm willing to bet that AOL isn't going to hunt for any other people like this doing it. Unless they're made aware of other inside jobs of this, they'll probably stay happily oblivious to anyone else wanting to make a fast buck.
And tomorrow the stock exchange will be the human race
An interesting way to look at this is consider the age of the people involved. The engineer was 24 and the Casino guy was 21. IT, notorious for age discrimination in favor of young, brighteyed types, may actually be introducing a greater security risk with the practice.
I remember when I was in my early 20s and lets just say I didn't have a lot to lose... and everything to gain from taking a chance here and there. By placing less mature workers into places where personal ethics and great responsibility collide, you're asking for issues just like this.
I don't mean in indict all younger workers. Certainly most are good employees; I've hired many younger people without trouble. But as a percentage of population, the younger I expect to make more 'mistakes' both simple errors and errors in judgment.
My two bits...
SCB
This AOL employee only made $0.0005652174 per e-mail address he sold. Is that anywhere near the fair market list for e-mail lists? Seems a bit low, but then again IANAS (I am not a spammer).
"There is no spoon." - The Matrix
And there are no closed union shops in Virginia - you want to work somewhere, the company wants to hire you - no one can force to you join a union. Heck, even on the Washington Redskins - which is legally a Virginia company - players tend not to pay NFLPA union dues....
About the only useful info a cracker would find in /etc/password is usernames, and if he can see that file to begin with, he's already got a login.
Yeah, and a huge list of email addresses. In the case of the grandparent, about 183,000.
92 million verified AOL email addresses, well, that's pure gold. You know if they're an AOL subscriber, they're a sucker anyway...
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
You'd be surprised how many people don't even know that's an option. Remember these people are using AOL, they think it IS the internet.
If you build it, nerds will come. Soylentnews.org
In the context of mails previously received to/from AOL accounts..
prey explain how's this different from their previous slogan.
for the last time people, I am "frodo from middle eaRTH", not "middle eaST".
Dictionary attacks become exponentially harder as your user name becomes longer, assuming that is constructed of random characters.
The likelihood of a dictionary attack hitting a n character random string of characters and numbers is miniscule for n larger than 15 or so, even if the dictionary attacker is trying 1 million combinations a second, because there are (at least) 36^n user names in that space.
my rough calculations say that it would take 7 billion years to dictionary attack the space of 15 character random numbers of and letters, even if you could do so at a rate of one million a second.
So if your 15 character random user name gets spammed immediately after creation without ever being used, it's an inside job.
But I wouldn't be surprised if it was buried in the Hotmail terms of service that they can sell your addresses.
Every situation is unique, and sometimes different situations require different actions. You see the simularities between two situations, and your opinion is that differences are nonconsequential, but that doesn't mean the other person thinks they same way. They might think that the differences are very important and the simularities are nonconsequential. That doesn't mean that they have a double standard or are hypocritical, it just means that they put different value on the various aspects of the situations than you.
:)
It's just like the Kerry is a waffler fallacy. Votes for PATRIOT act, then when he actually gets to read it, changes his mind. Does not vote for iraq funding, but latter does when the source of the funding is changed. To a conservative pundit, there is not concievable reason not to support things go towards "national security", but Kerry disagreed. The same way a libertarian can't think of any reason to give up privacy, but the conservatives think that that it is sometimes necesarry. That does not mean that they are hypocrites, it means they see things differently than you.
Even if they are wrong
here in san jose I spend 100% of my pay check on rent, car insurance (good driver), car payment (commuter), phone bill (rarely talk on it), and food (ramen, milk, and eggs).
If you offered me $52,000 for a list of emails or names and info from my work i'd take itin an instance. I may get fired and sued but hay with that I could afford to move out of this shit whole and be over seas with my family tomorrow.
In keeping with the first item with your list, I would advise giving all the money you're spending on consultants who give you three sentence recommendations and give it to the people who actually have to work for a living.
Smathers' spam scheme skimmed screennames? A shocking scam.
Crhis Mattern
But you can be sure that if a major company has your information, many employees that are making very little have access to that information.
::sniff::
At MCI, where I used to work, I would see the personal information including name, address, phone numbers, credit card numbers, birthdays, and email addresses of hundreds of customers a week. Not only that, but every employee was identified in the system by his or her SS#, and your SS# was stamped on every note you placed in the system.
I earned $8.47 (American) per hour, and the call center contractor had a less than rigorous screening process. I did have a pulse, so I was hired. I have more ethics than the company I worked for, and I would never do such a thing.
But you have to ask yourself, if a company is willing to hire employees for next to nothing, and hand these employees access to information that they can sell for 3 times what they earn in a year, how long untill the SS# you give the company is compromised?
Do not give truely sensitive information to companies. If they do not have legal authorization to demand a SS#, they are using it for identification purposes only. Give them a fake one.
On another note: Anyone want to hire an aspiring writer? Seriously, $8.47/hr is still better than the $0/hr I'm making now. Please!
Be strong!
The problem with your "new" way of doing business is (1) it isn't new and (2) it doesn't work now any more than it ever did.
Having an itch to scratch does nothing for the guy who's gambled his way under a mountain of debt and who goes from being completely trustworthy to being willing to steal from his best friend, to say nothing of his employer. That's not a hypothetical case; I'm thinking of a particular person with whom I worked about a decade ago. (Luckily for me, I wasn't one of his friends, so he didn't rip me off.) People change, and someone who's completely trustworthy today may not be five years from now. Worse, people are not always what they seem, and only observation over a very long term reveals them for what they are.
Who watches the watchers? I don't know -- but they need to be there in any org which handles things of value.
First, I am not a lawyer. This is a lay opinion only.
Second, I am not a particularly vengeful person, or at least I don't really want spammers to face the death penalty, castration, or other such suggested punishments.
Jason Smathers has been charged with theft and fired by AOL. I'm assuming the actual charge is something like felony grand theft, and that the amount his co-conspirator got for the lists will be all the proof AOL will need to offer for a grand jury to agree with that charge.
According to the article, he also used another employee's ID in the act. That's probably either a separate charge or at least an aggrevating factor to the first charge. Among lots of other effects, this employee probably has standing to sue both men and a fair chance of winning, regardless of whether AOL does (with "winning" limited by the condition that they must somehow have forfitable assets after their prosecution).
It also looks like there was possibly more than one actual theft, as the article mentions the men either actually obtaining or conspiring to obtain an updated version of the list, which would imply an older version also existed in their posession. One or both men may have made fraudulent promises to a person or persons who bought the list, representing it as legally obtained.
So, Smathers could well be inditeable with three or more felonies (three strikes rules may apply), and it's possible with multiple persons accused that the whole thing could fall under RICO, either of which could easily make the overall sentence 30 years or more. Even with the usual time off for good behavior type clauses, that means serving a good solid 18 years or so.
AOL probably wants the whole thing to go away. Since they can't really get that, the next best thing is to get seriously Neolithic on his ass, and hope it has a deterrent effect.
Who is John Cabal?
Kiwaiti
Member of the Legion Of Microsoft Haters
Clever idea ... but counter-productive in
the long run.
Assuming that the spammer is using a herd of zombie PCs for spam relaying, and each PC can handle multiple mail connections, they are not likely to be slowed down much by this tactic. In addition, spamming PC can be set up to aggressively time out connections to slow mail servers.
On the other hand, people who run legitimate mailing lists may suffer when a list submission triggers spam detection and slow server counter measures. The mailing list server will typically NOT be able to send huge numbers of emails in parallel, and will NOT want to aggressively time out slow mail servers. As a result, if a mailing is (rightly or wrongly) classified as SPAM and triggers counter measures, mailing list delivery suffers.
A few weeks ago I came across about 30 old 5 1/4" floppies.
I hooked up an old drive to see what was up and low and behold it worked and on the disks (that could still be read) was vital stats on about 85,000 people - meaning name, SS#, address, health insurance policy numbers, ect. All good, all verified assuming the individual was still alive and hadn't moved.
This was left over from when I worked at an insurance company in 1992: a migration from a THEN ancient mini to a PC based system. There that data was sitting in my basement for 12 years (and I have moved twice since then!)
Being an honest man, out came the scissors... but the ID theft possibilities were really astounding.
How much old data like this is just sitting around on forgotten tapes and disks?
If I were to set up an huge ID theft ring this is the sort of stuff I would look for. Good data, but old. Not in any current database, absolutely no audit trail, individuals have since moved around and changed employers obliterating any or most chance of establishing a pattern to the thefts. Best of all, not only are there no access logs, but the organization wouldn't even miss the old media and if they do someone could just claim that it was thrown out months ago.
Mildly disturbing - but less so than the thought of a dirty bomb I suppose.
I am very small, utmostly microscopic.
In any case, selling >90 million customer records to spammers is not a minor incident. You'd get fired even if you had been elected the employee of the year just a week before. Unless you could convince your employer of your innocence.
I love C++