US Bot Herder Admits Infecting 250K Machines
AceCaseOR writes "In Los Angeles criminal court, security consultant John Schiefer, 26, has admitted infecting the systems of his clients with viruses to form a botnet containing a maximum of 250,000 systems. Schiefer used his zombies to steal users' PayPal usernames and passwords to make unauthorized purchases, as well as to install adware on their computers without their consent. Schiefer agreed to plead guilty to four felony charges of accessing protected computers to commit fraud, disclosing illegally intercepted electronic communications, wire fraud, and bank fraud. He will be sentenced Dec. 3 and faces up to 60 years in prison and a fine of $1.75 million."
"...a system so simple even a grandmother could use it to infect computers..."
As a feminist, and a grandmother, i resent that.
The adware and viruses he installed slowed my system down, so I couldn't get first post.
With time off for good behavior, it will be less than 30 months. He may even be able to get most of that as work release.
According to the article, this jerk got $19,000 for dumping adware on more than 150,000 pcs.
He also encouraged minors to act as go-betweens:
Obviously he had more than one kid "working" for him. He probably agreed to the plea-bargain because otherwise he'd be facing total possible time of several hundred years.
However, he won't be hired by anyone in the computer field after this - what he did was a simple con, no "computer wizardry" required. Hans Reiser would have more chance after a murder conviction.
Kevin Smith on Prince
This is why companies have outside auditors for their accounting departments.
Should not companies now figure out how to audit their IT deparments regularly?
This is NOT that uncommon, after reading some of the stuff written by the forensic snoops hired by private companies (who mostly do not want anyone to know that anything was compromised...shareholders & investors for instance).
is there some kind of accreditation or certification for security consultants? i understand credentials can be forged, but could an agency for security consultant certification help?
"To stop the terrorists."
Would I trust a former black-hat hacker to protect my computers? Possibly. Would I trust someone who has specifically targeted and screwed over his clients in the past- the people who paid him good money to protect them from such behaviour? Would I fuck.
"Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
If he gets a fine this large and jail time for infecting 0.25 million computers, where's the appropriate sentence for Sony for knowingly infecting millions of computers with the rootkit on their CDs?
Please don't insult the thousands of honest security consultants by calling this guy a "security consultant." The title of "con artist" would be far more accurate.
He knowingly, willingly and maliciously did this. It wasn't an accident, a crime of passion or something he did because he was drunk one night, it took real work over many months. He was well aware of what he was doing the whole time he was doing it.
The proverbial book needs to be thrown at people like this. These are precisely the sort of people we should be making an example of.
No sig today...
Well, from what I know what happens, the Prosecution gives a sentencing offer and the defendant will agree to plead guilty in order to accept the sentence. Either that or I watched too much Law and Order.
There's nothing constructive to derive from this post but pointless speculation. Let that take care of the concerns of the trolls and critics right off the bat, nothing to see here, move along.
Anyways, I've been doing a bit of thinking about this issue.
You often hear about 'white collar' criminals being given massive sentences. They could be organisers of international software piracy rings, super electronic fraudsters (like the one mentioned in the original parent article), whatever. The numbers of years they are sentenced to and dollars they are fined just seem to get bigger and bigger each time i hear a new story.
New laws are increasingly being passed to raise the penalties for electronic crimes. These harsher penalties don't seem to be acting as much of a deterrent, however.
The economic damage caused by internet and computer crime is staggering, the number of victims (as seen in the article) in the hundreds of thousands, potentially even millions. Could there come a time where these crimes could incur capital punishment?
disclaimer: i come from a country without the death penalty, and personally don't understand the necessity for it, so don't read this as my supporting the idea. This isn't about my personal philosophy.
Murder is already a capital crime in a number of US states. People are already being executed in many countries for crimes other than murder. Drug trafficking, serious sexual offences, could it be a relatively a small step for internet crimes to escalate into capital territory?
The internet being international as it is and the victims of these crimes often being selected so indiscriminately, could it be a matter of time before an american committing e-fraud is indicted in a country where his crimes are of a capital nature?
Extrapolating ludicrously, could a european citizen not subject to capital punishment be indicted by an america where their internet-based crime warrants the death penalty?
It's controversial enough when a citizen of a country that doesn't have the death penalty is sentenced to death in one that does. Imagine if the crime they committed was something we might look at as being comparatively trivial in nature.
You cant appeal a guilty plea.
3G Communications may also go under because of this guy's actions.
Would you trust them after this?
No sig today...
Wish this was the ancient Greece, where people can be sentenced to death for corrupting the mind of youths.
ELOI, ELOI, LAMA SABACHTHANI!?
Thanks Larry. See you in Minnesota...stall 4.
from the story:....Schiefer said he and his friends spread the bot programs mainly over AOL Instant Messenger (AIM). By using malicious "spreader" programs such as Niteaim and AIM Exploiter, Schiefer and his co-conspirators spammed out messages inviting recipients to click on a link. Anyone who took the bait had a "Trojan horse" program downloaded to their machine, an invader that then tried to fetch the malicious bot program." Read more at this link here.
...because you never know who you're dealing with.
I'm the last person to support insane prison time and fines as a deterrent. It ain't one. It never has been and never will be. Look at the insane punishments we got today for copyright infringement. And I'm not even talking about the civil suits for "damages" (or as I like to call it "the MI's new business model"). We now got 10 years prison time for that as a maximum sentence. For the same penalty, I could rob a bank, hold people hostage for a few hours and wreck a getaway card into a school.
... ok, no thinkofthechildren examples. But you get the idea.
This isn't just a "simple" criminal using malware to steal IDs. He was the guy who was supposed to disallow exactly that. He was the one people trusted to keep them clean from malware. Now, he didn't just fail in his job and allow it despite his attempts, he deliberately and intentionally infected his clients' computers.
That's why I don't think this punishment is overdone. We're talking about the maybe most insidious way of breaking a law: Getting people's trust, getting them to believe you you're going to keep them save from just what you want to do to them. It's like a cop breaking into your home or your babysitter
This is NOT the punishment I'd see as adequate for a "normal" malware attacker (even though I would love to see them dangling from their dangling bits, but that's my personal opinion).
As for those that expect him to get out after 5 years and have a great job then, I can tell you this: I can't say anything about his time, but his job opportunities are going to be slim. The security industry isn't big. People know each other. People like this are going to be not known, they are infamous. And nobody will willingly touch him with a 10 foot pole.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
What kind of fucking lunatic would hire somebody who has PROVEN that he says he's one thing but is actually another?
Oh you'd be surprised. This guy might have a bright future ahead of him in politics.
Both parties are guilty, and yes, I think any software product that stores passwords like that should be held guilty when that facility is exploited. To be sure, I am not including buffer overflows in that category. Human error is different from ignorance of history.
Password saving features, like ActiveX and Javascript are just stupid, stupid insecure features that were known to be insecure by design before they were invented. Stupidity (or greed) on the part of the managers deciding to release those features is no excuse.