Slashdot Mirror


Tech Lessons From the Bad Guys

Chris Lindquist writes "Organized crime, porn peddlers, gambling sites — they all use technology to make a killing. CIO.com has posted several stories that spell out how the seedy side uses IT for profit. From the online techniques of penny stock scammers to innovation lessons from a pair of 'accidental pornographers,' to what you can do to fend off cybercriminals, find out what they do right when they're doing wrong."

25 of 138 comments (clear)

  1. Accidental pornographers? by eviloverlordx · · Score: 5, Funny

    How does one become an accidental pornographer? 'Oops! I took a full color spread of you nude by accident last night'?

    --
    'Loose' is when your pants are three sizes too big. 'Lose' is when you misuse 'loose'.
    1. Re:Accidental pornographers? by Captain+Splendid · · Score: 3, Informative

      Actually the link to the 'accidental pornographer's' story is quiute interesting, not least for the fact that they claim to have a solid way of watermarking digital video content.

      --
      Linux, you magnificent bastard, I read the fucking manual!
    2. Re:Accidental pornographers? by twistedsymphony · · Score: 5, Interesting
      It was very interesting, while I knew that the porn industry was fairly in-tune with technology the article left me with the impression that they drive tech advances more then we realize... The one bit on open source software really caught my eye:

      Another red light best practice is to look for vendors that use open source. Since sites are open 24/7 (late-night hours are extremely profitable on the red light Web), "if we ever run into critical issues we need them solved now, not two hours from now," says Bodog's Ayre, who has learned that if he wants his people to be able to fix something, they need to have access to the source code. "We absolutely could not get a couple of our vendors to address an issue that was crippling us," says Ayre. "Under peak loads, the entire site became nonresponsive. We had no choice but to decompile the systems in question and fix the problem ourselves. This was probably one of the biggest drivers pushing us to adopt open-source solutions for our most critical systems."
      Probably one of the best arguments for a corporate adoption of open source software I've ever heard. I know, at least at my company, we're in constant struggle with our software vendors to fix bugs that are critical to us but maybe not critical to their other clients. This is particularly frustrating when we have the knowledge necessary to fix the problem ourselves... just no access to the source.
    3. Re:Accidental pornographers? by radish · · Score: 3, Insightful

      I'm not sure if the article specifies the platform in question, but I've done exactly that a number of times with Java app servers, the decompiled code is quite readable. C/C++ of course would be a different story, but I'm sure it's possible (and in fact the rapidity with which copy-protection systems are broken suggests it's not _that_ hard).

      --

      ---- Den ene knappen er powerknapp, den andre er Bender voice knapp "Bite My Shiny Metal Ass"

    4. Re:Accidental pornographers? by anticypher · · Score: 3, Interesting

      Do you want a serious answer? Well, I'm going to write one anyways.

      There are basically two kinds of guys in the internet porn industry. The serious pornographers who can convince all the scarily slutty women to get dirty for a small amount of cash, and the webhosting guys who realise they need some higher margin content to pay the bills.

      The pornographers don't particularly have much technical skills, at least not for setting up websites and payment processing schemes. They may have tremendous photoshop skills, because the women they shoot tend to have a heinous amount of scars, tattoos and piercings. The porn producers are always looking for ways to set up web sites to make money, but they tend to not have much money to invest in development.

      The website guys are the ones who have built up a business with a few hundred or thousand web servers, with all kinds of low margin mom-and-pop static websites. They can code in Ruby or PHP, but can't really live off margins of a few euros per month per site or a few thousand euros for web design job. After a year or two, they come to the realisation they're not really earning the big money like founding a new google. That is the point when they put their morals aside and decide they could really make some good money from building porn websites. What they are missing is social skills to convince women to fuck for money in front of a camera.

      Put the two sides together, and you have a fairly good model of the online porn industry today. The "intentional pornographers" make the content, the "accidental pornographers" make and run the sites. The buzzword is "Ecosystem"

      the AC

      --
      Hemos is like...sci-fi fans;he thinks technology is cool, but he hasn't bothered to understand the science it's based on
  2. here's another tip: the print link by smitty97 · · Score: 5, Informative

    money making tip: get slashdot to link to your pop-up ridden pages

    ad free print links:
    http://www.cio.com/article/print/117150
    http://www.cio.com/article/print/117050
    http://www.cio.com/article/print/117201

    --
    mod me funny
    1. Re:here's another tip: the print link by celcxo · · Score: 3, Informative

      Sorry about that. The current popup on the site is only suppose to show on first arrival, but it's coming back for repeat visits on some browser versions. We're looking to fix the issue now. Chris

  3. I'm shocked.... by 8127972 · · Score: 5, Funny

    .... That people actually paid for porn so that these guys could make a buck!

    --
    This is my opinion. To make sure you don't steal it, it's covered by the DMCA.
  4. Value judgment error by Red+Flayer · · Score: 5, Insightful

    Petty stock scams? Organized crime? Sure, I can see that as being 'wrong', though calling "organized crime" wrong is a tautology.

    I, for one, do not believe peddling porn or hosting a gambling site are 'wrong'.

    Sure, some porn is created in a manner that is harmful to the participants (such as taking advantage of drugged/underage/unwilling subjects). And some people cannot handle gambling -- and fixed games, or games where the players are misled as to their chances of winning, are wrong.

    But to generalize that they are all bad? If they are, I don't want to be right.

    --
    "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
    1. Re:Value judgment error by QuantumRiff · · Score: 4, Insightful

      And some people cannot handle gambling

      Hell, some people can't handle creating laws that follow a certain Constitution guaranteeing our rights... Maybe we should outlaw lawmakers.. or make them pass a 8th grade civics test...

      --

      What are we going to do tonight Brain?
  5. Wanted: Linux systems administrator. by Anonymous Coward · · Score: 5, Interesting
    For those of you wondering about the pr0n stuff.

    I was looking for a job and had posted my resume on line (monster.com I think) and got a call from a guy looking for an admin with web server skills. The third or fourth question was if I minded the fact that they would be pr0n servers.

    I had to turn them down, and no I don't remember the company name.

    So, if you have the right skill and are in a big city market, who knows. You might just get a call.

    1. Re:Wanted: Linux systems administrator. by Overzeetop · · Score: 4, Funny

      just trying to bring in the nerdiest guys they could find and then have them interviewed by the porn girls and film it.

      And you had a problem with this because...?

      --
      Is it just my observation, or are there way too many stupid people in the world?
  6. Innovation from the Web's Red-Light District by spamking · · Score: 4, Funny

    Streaming video: YouTube made it famous; adult movies made it economically viable.

    Thank you YouTube?

    Videoconferencing: Businesspeople increasingly use online chat and embedded video rather than conducting face-to-face meetings. Before that, it was used to communicate with Live! Girls! Now!

    Face-to-what?

    Digital rights management: Through their disregard for intellectual property rights, adult sites helped spur the music and film industries to apply DRM to their online content.

    Wait. So we've got the pr0n industry to thank for DRM?

    E-commerce: The content on adult sites was so compelling (to some), it helped people overcome their fear of using a credit card online, according to Frederick Lane, author of Obscene Profits: The Entrepreneurs of Pornography in the Cyber Age.

    First DRM and then identity theft . . .

    I wonder if my boss would go for me doing some cross-training with a pr0n site developer . . . hmmmmmm.

  7. 2 Simple advantages on their side by Opportunist · · Score: 3, Insightful

    First and foremost, user stupidity works for them, not against them. And second, they don't care jack about any rules or regulations, since they're breaking the law already anyway, so why bother with privacy laws or possible damage claims when you're already scamming the stock market or doing a virtual bank robbery?

    You cannot apply that "information" to legal businesses. Or at least, you definitly shouldn't.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  8. Bad guys... Banks? Oil companies? Diamond mines? by xxxJonBoyxxx · · Score: 4, Insightful

    CIO.com has posted several stories that spell out how the seedy side uses IT for profit.


    Bad guys... Banks? Oil companies? Diamond mines? Televised church services? (There are plenty of IT-using "legit" businesses that display questionable moral values too.)
  9. Great! Now we'll get the MAFIAAA by Tatisimo · · Score: 4, Funny
    A random sampling of 400,000 queries on the early peer-to-peer file sharing network Gnutella in 2003 found that 42 percent were looking for porn (compared to only 38 percent looking for music)

    How long till pr0n industries get organized and start pulling off mafia style lawsuits against file sharers? Pornographers Association of Wasted Nudes (PAWN)

    "PAWN accuses 7 year old of browsing porn sites" "PAWN seeks $8 million in damages from dead man (Died of a heart attack while looking at bootleg pornography)"

    --
    Give Kashyyyk back to the Wookies
  10. Here's how it's done by Opportunist · · Score: 5, Interesting

    Do you know that Western Union doesn't require you to legitimate yourself when withdrawing money if it's not more than (IIRC) 6k bucks? So all you gotta do is find some gullible moron, who'll "work" for your "international financing company" by offering you his account for a transfer. You have your target transfer the money to this moron's account and have him transfer the money via WU, and inform you about the transfer code. He can keep, say, 20% of the stolen money, and hey, who'd turn that offer down, about 1k bucks for 2 hours work? Almost too good to be real!

    Then you (or if you're a larger organisation, one of your goons) goes to WU, hands in the transfer code and heads out with the money.

    Of course the "financial agent" gets caught. But that's no loss, you know, there's an idiot born every minute, you'll find others.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  11. And the biggest lesson is probably... by JamesP · · Score: 3, Insightful

    Quote:

    I don't have vendors paying the freight to conferences at swank resorts to convince me to invest in something that's half-developed and overhyped. I never use jargon. I spend zero time doing PowerPoints.

    Makes me wonder why these people are so much more smart than the average CIO that only knows how to "deploy" the latest crap that comes from that city in Washington.

    Maybe because it's really their neck on the line, that's what I call responsibility.

    --
    how long until /. fixes commenting on Chrome?
  12. Re:Hard to Feel Pity... by Opportunist · · Score: 5, Insightful

    I've been preaching that for years and the usual response was "you can't require people to study computer science before you allow them on the 'net".

    All I want is people to take responsibility for their actions. When I hand my car keys to a person I don't know and he uses the car for ill, I get sued. When I let a stranger into my house and he knocks me out and robs everything in sight, my insurance would laugh at me. When you note your secret number on the back side of your ATM card, your bank won't cover the loss.

    Just in the computer area, everyone's free to be as careless and irresponsible as he wants to be. It does NOT take a lot of brain power to know that offers that are too good to be true usually are. It doesn't require a lot of computer knowledge to NOT click on an attachment coming from someone identifying himself as "lawyer" (literally "lawyer", not some name). And it for sure does not require a lot of tech study to install some kind of antivirus tools.

    Don't get me wrong. I would not require an average user to hack his windows box to tighten security to the maximum. But why is it still asking too much if I ask people to

    - Use a router and disallow incoming syncs (most routers do that by default, so the "it's too technical" argument doesn't count).
    - Enable Auto-Update on your Windows box (most Linux distributions can that now, too).
    - Install some Anti-Virus tools
    - Keep the brain turned on when opening mails and unknown software.

    What's so problematic and impossible to do about this?

    It's certainly not a 100% secure solution. Granted. But it is "good enough". Just like nobody requires you to have iron bars in front of your windows and steel bolts in your high security door, I wouldn't require people to have 100% "hack proof" boxes. There's no such thing as an unhackable box as soon as it has some kind of connection to another box that can be used by a malicious user (i.e. the standard setup for a box connected to the internet). But at the very least this would thwart almost 100% of the standard trojans currently in circulation.

    What's so impossible about it?

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  13. The Obvious Question by Anonymous Coward · · Score: 4, Funny

    Organized crime, porn peddlers, gambling sites -- they all use technology to make a killing. Are they hiring?
  14. Why are pornographers "the bad guys" by phorm · · Score: 4, Informative

    Unless they're peddling illegal porn, or through dubious methods such as spam or popup-flooding, what makes pornographers bad guys, except that perhaps they don't fall under certain groups' moral or religious views of good.

    The rest: penny-stock scammers, cybercriminals, are just that... criminals. There's no crime in porn, so long as the proper laws are observed.

  15. Go shove your morals and RTFA, kdawson by bADlOGIN · · Score: 4, Informative
    "Tech Lessons From the Bad Guys"

    Excuse me?!?! Hey kdawson, if you don't like porn or gambling, then don't indulge in them. On-line or in the real world. If you had paid attention, you would find there is NO reference in the article to Organized Crime and nowhere does it call anyone or anything "bad". At best, there's links the site shoved in to other articles regarding cybercrime and the mob. Furthermore, the article passes no judgment in terms of depicting porn or gambling as bad (it's a business article- they're just forms of business after all). So the next time you approve an article, how about bothering with at least an accurate assessment? And lay off the criticism of porn. This is /. after all, it's the only lovin' some of the loyal readers get..

    --
    *** Sigs are a stupid waste of bandwidth.
  16. "The bad guys"??? by Caspian · · Score: 4, Informative

    Wait. What about pornographers makes them "bad guys"???

    Porn is fully legal. Assuming the models aren't forced to have sex (which would make it rape, not porn), and they're not, like, 5 years old (or 15, if you buy the whole "teens can't ever have sex without it being coersion" line), it's not unethical. How can you compare "porn pushers" to mobsters?

    I used to work for a porn site, programming on their content and developing HTML and CSS. They're just ordinary people trying to make a living. Porno isn't wrong. For fuck's sake, what is with America's puritanical attitude towards sex anyhow? Hit a 16-year-old, nothing happens. Have consensual sex with a 16-year-old, go to jail and get branded a "sex offender", as if you're some kind of rapist. Show kids a building blowing up, that's okay. Show kids a nipple and OMGOMGOMG JESUS PROTECT THEIR EYES. Seriously, WTF!?

    --
    With spending like this, exactly what are "conservatives" conserving?
  17. An extra thought by Moraelin · · Score: 4, Interesting

    Exactly. Reading the summary left me scratching my head too. You've nailed the moral judgment excellently already, so I won't repeat that.

    But I'll add another thought there: regardless of the moral judgment, exactly what is to learn from porn or gambling sites anyway?

    No, seriously. Spammers, scammers, DDOS extortionists, etc, actually face some technical challenges. They need zero day exploits to maintain their army of zombie machines. They need to circumvent or disable protections. (See the many viruses or trojans that disable the major antiviruses and firewalls.) They need to dodge the law, at _least_ in that they need to transfer the ill gotten money abroad without leaving _too_ many obvious traces. Etc.

    Those are real technical challenges. Antiviruses for example are getting so defensive against being disabled, that it's sometimes hard to fully uninstall them even as the legit owner of the machine.

    You can learn something from that, and (in response to other posts) there _are_ legitimate uses for that knowledge too. E.g., whatever techniques they use to automate looking for buffer overflows, should be mandatory testing techniques for new software.

    But porn and gambling sites? Gimme a break. I dare say most of the porn sites are actually just a plain old normal web site. There's nothing particularly high-tech about them, really. Just some thumbnails linking to a video or larger picture. In really "high tech" cases, they might open a popup via javascript for the page with the embedded movie. But that's about it.

    Exactly what's to learn there.

    Sure, a number of sites use porn as a bait to get one virused. But even then it helps to realize that that's not primarily a porn site, it's primarily a script-kiddie site and the porn is just the bait there. Just because the porn is the bait, doesn't make porn itself some high-tech black-hat thing.

    To use a metaphor, there have been cases where people have been lured in a RL (non-internet, back-of-the-van kind) scam with such promises as a cheap second-hand laptop or whatever other cheap no-questions-asked good. Yet that doesn't make laptops themselves some evil bad-guy kind of scam. It's just the bait, the scam is a completely different half of that incident.

    --
    A polar bear is a cartesian bear after a coordinate transform.
  18. Please repost in engineer friendly terms by Weaselmancer · · Score: 3, Funny

    It's like going to a party and getting so drunk you don't know where you'll be in the morning...or who will be able to have their way with you in the evening.

    I'm sorry, but I'm an engineer and I don't understand this comparison. Could you please rephrase it?

    --
    Weaselmancer
    rediculous.