Slashdot Mirror


iTunes Gift Card Key System Cracked, Exploited

moonbender writes "Fake but working iTunes gift cards are being sold on Chinese auction sites for a fraction of their value: 'The owner of the Taobao shop told us frankly that the gift card codes are created using key-generators. He also said that he paid money to use the hackers' service. Half a year ago, when they started the business, the price was around 320 RMB [about $47] for [a] $200 card, then more people went into this business and the price went all the way down to 18 RMB [about $2.60] per card, "but we make more money as the amount of customers is growing rapidly."' The people at Chinese market researcher Outdustry have apparently confirmed this by buying a coupon and transferring it into an iTunes account. Oops."

83 of 388 comments (clear)

  1. BitTorrent by MrEricSir · · Score: 5, Insightful

    It's still easier to use BitTorrent.

    --
    There's no -1 for "I don't get it."
    1. Re:BitTorrent by aliquis · · Score: 5, Funny

      No, even more is on bittorrent and the like ...

    2. Re:BitTorrent by Shakrai · · Score: 5, Insightful

      It's still easier to use BitTorrent.

      It's probably safer too. Bittorrent is going to be a civil matter. Exploiting a hole in Apple's POS system to get free stuff probably qualifies as fraud and would bring criminal charges.

      Random thought: Reminds me of the old days when you could create credit card "numbers" that weren't actually valid but passed the checksum test and use them to create AOL accounts. Kind of surprised that Apple wouldn't know better.

      --
      I want peace on earth and goodwill toward man.
      We are the United States Government! We don't do that sort of thing.
    3. Re:BitTorrent by earlymon · · Score: 4, Interesting

      It's still easier to use BitTorrent.

      I have no clue, access to BitTorrent, behind the Great Firewall of China. But from what I've read (horror stories) about net activities being traced and questioned, I'd use an illegal Apple Store access rather than BitTorrent.

      "Yes, Comrade Prosecutor - tell me what I did wrong ripping off the imperialists," sounds like a better defense than, "I promise I wasn't looking at porn."

      Never reward Behavior A and hope for Behavior B.

      --
      Pathological kinda promises Path + Logical - but instead, you get stuck with pathetic.
    4. Re:BitTorrent by tacarat · · Score: 3, Funny

      Random thought: Reminds me of the old days when you could create credit card "numbers" that weren't actually valid but passed the checksum test and use them to create AOL accounts. Kind of surprised that Apple wouldn't know better.

      But the vendor said it was foolproof!

      --
      "Common sense will be the death of us all"
    5. Re:BitTorrent by shemp42 · · Score: 3, Funny

      ANyone translate for me? I need about 20 of these cards.

    6. Re:BitTorrent by Colonel+Korn · · Score: 3, Insightful

      And torrents tend to be of much higher quality than iTunes tracks.

      --
      "I zero-index my hamsters" - Willtor (147206)
    7. Re:BitTorrent by omeomi · · Score: 3, Insightful

      Why do you think Apple users don't use virus scanners or real firewalls?

      Because, for the most part, nobody is really writing viruses for OSX, so protecting against them is largely a waste of time? Then again, if you don't download shady software on Windows, you're not going to have a problem with viruses, either...

    8. Re:BitTorrent by bkgood · · Score: 5, Insightful

      companies like Apple who take massive amounts of GPL code to build their empires and give NOTHING in return.

      ... except the huge advances Apple has given KHTML in the form of WebKit.

    9. Re:BitTorrent by bitrex · · Score: 3, Insightful

      It took the Chinese only about 3 decades to become what U.S. government and corporations have been having wet dreams about for nearly a century - that is a largely autocratic and oligarchic corporate system that can count on socialist support from the federal government when it needs it, which is all the time. In the meantime the economists or the People's Worker's Party or whomever will dispense the priestly blessings of the socialist revolution or laissez-faire capitalism or whatever is in vogue at the time to the citizens, leaving the government and corporate entities to pursue the obvious and efficient solution for economic and national power. Capitalism vs. communism with regard to China is a false dichotomy. The US is probably on the way to whatever China is now, it's just taken us a lot longer to get there because we've had to spend an enormous amount of effort at keeping up the illusion of a representative democracy, while China has been autocratic pretty much all along.

    10. Re:BitTorrent by shmlco · · Score: 2, Informative

      Not even one line??? Golly.

      But if true, then why they have an entire subsite devoted to Open Source, with links to the source for Darwin and the Mach kernel, WebKit, Bonjour, and more???

      http://developer.apple.com/opensource/index.html

      Either you don't know what you're talking about or... you don't know what you're talking about.

      If I were you I'd open my eyes.... (grin)

      --
      Any sect, cult, or religion will legislate its creed into law if it acquires the political power to do so.
    11. Re:BitTorrent by Anonymous Coward · · Score: 2, Informative

      Ever hear of viruses spreading through "Autorun"?

      fixed.

    12. Re:BitTorrent by jcr · · Score: 4, Informative

      Apple has yet to open EVEN ONE LINE of the OS X source

      This turns out not to be the case.

      See here.

      Got any more uninformed bitching to do?

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    13. Re:BitTorrent by jcr · · Score: 4, Insightful

      ...and all the ZeroConf code, the IOKit, LaunchD, all the Firewire library code from Zayante, CoreFoundation, the GCC Objective-C implementation, a lot of additions to SQLite, not to mention all the work they're doing on LLVM (which will finally end the dark ages of GCC).

      -jcr

      --
      The only title of honor that a tyrant can grant is "Enemy of the State."
    14. Re:BitTorrent by omeomi · · Score: 2, Insightful

      The old 'viruses only target popular platforms' meme relies on the assumption that every platform is exactly secure as every other platform, and that is provably false.

      Actually, I didn't say anything about viruses only targeting popular platforms. I said "for the most part, nobody is really writing viruses for OSX", which is true. There are far more viruses being written for Windows. I didn't attempt to explain the reason for that, though. It could be that Windows s more popular, or it could be, as you suggest, that OSX is more secure, and thus virus writers gravitate to the less secure platform. I don't know (or care). I would have to think that it's a mixture of the two, to be honest. There's more software in general for more popular platforms, so it's no huge surprise that there would also be more viruses.

  2. And You Wonder Why Amazon MP3 Only Works in the US by eldavojohn · · Score: 5, Insightful

    "but we make more money as the amount of customers is growing rapidly."

    Brilliant business model there, Taobao. I used to feel bad that Amazon's MP3 Service only worked inside the United States but now it's pretty clear: I doubt Apple will have much luck prosecuting anyone in this case whereas it would have been different had it happened on American soil.

    I'm sure the Chinese government will help protect Apple's ... hahahaha sorry, couldn't quite say that with a straight face. Seriously, we must look like ripe-for-the-picking rubes to places like China. They're sitting there with free copies of Vista, Adobe Suites and now cheap "legal" music. I guess it will forever remain a mystery to them why their nation isn't home to prosperous software & music industries while the status quo is free for the taking with no repurcussions.

    --
    My work here is dung.
  3. hmmm by Em+Emalb · · Score: 2, Funny

    use safari on your iPhone to buy the fake iTunes card.

    It's like curb stomping apple after you kick them in the nuts.

    More seriously, there's a good chance that if Apple does decide to change their key system that a lot of legitimate iTunes cards are gonna be rendered worthless.

    And that would suck.

    --
    Sent from your iPad.
  4. Ouch. by russotto · · Score: 4, Insightful

    I'd be interested to know what algorithm was being used for the keycards. Did Apple use a weak scheme, did someone leak the secret, or (most interestingly) has someone managed to crack a good encryption algorithm.

    (Alas, I'd guess it's probably a weak scheme. As recently as two years ago I noticed a bike products retailer was actually using sequential codes for its gift cards)

    1. Re:Ouch. by teh+moges · · Score: 4, Informative

      I actually didn't think this would be possible.
      In Australia, when you buy mobile phone recharge (extra credit to make calls), you buy a coupon which is only activated after its brought from an authorized dealer. Once the code is used, that code is useless.
      It does mean that each retailer has to have some connectivity to base office, but it stomps out generating new keys as much as you want.

    2. Re:Ouch. by cowscows · · Score: 2, Insightful

      No kidding. The way this is explained makes it sound like if I pulled a stack of iTMS cards off the rack at walmart or whatever and walked out with them in my pocket, they'd all be valid and would work. I have a hard time believing that to be the case. There are hundreds of stores (both online and physical) that sell gift cards at other stores, I have a hard time believing that it doesn't generally work more like you describe, and I also have a hard time believing that Apple would have done it differently.

      Unless maybe the people generating the card numbers has found a way to falsely activate them? Although if that were the case, I'd imagine that'd be a much easier fix.

      --

      One time I threw a brick at a duck.

    3. Re:Ouch. by smellsofbikes · · Score: 4, Informative

      >but it stomps out generating new keys as much as you want.

      Sort of. As the previous poster was alluding to, if the card numbers are generated sequentially and stored on the card, all you need to do is know your number, add about 100, put that number on your card, and wait for it to be activated so you can use it. You don't have to access the main server: you just wait for your number to show up.
      There was a neato scam running a while back where people would steal piles of seemingly useless blank gift cards, record the number off the card into a database, put them back in stores, wait a month, then try and use the number. If the card had been activated but not used (a gift card sitting in a present or a wallet somewhere) they bought what they could as fast as they could.
      I assume companies now sell entirely blank cards, that are programmed at time of sale, rather than pre-enumerated cards merely being scanned for activation.

      --
      Nostalgia's not what it used to be.
    4. Re:Ouch. by Lehk228 · · Score: 2, Informative

      no they still use the pre numbered cards. now they have a foil covered pin on the back but who would notice if it was missing.

      --
      Snowden and Manning are heroes.
    5. Re:Ouch. by bluefoxlucid · · Score: 3, Informative

      They work right off the truck. No activation.

    6. Re:Ouch. by HatofPig · · Score: 2, Informative

      At Loblaw's our President's Choice gift cards need to be peeled out of the frame they are inset into, with backing. There's no way to get anything off of the card until then. Plus the frame holds the little hole so you can hang them on the shelf.

      And phone cards all just have identical barcodes. The POS system then generates their activation code upon confirmation of payment, and prints it on their receipt.

      This is in little ol' Canada, by the way.

      --
      Silicon & Charybdis McLuhan Kildall Papert Kay
  5. Occam's razor by YesIAmAScript · · Score: 5, Interesting

    Possibility 1:
    Apple doesn't use a database for cards, they use a hash even though that would be stupid.
    That hash and algorithm for arranging the data before the hash was cracked even though all the verification is done on the server and thus there is no code out there to reverse-engineer.
    Someone is generating and selling cards using that hash.

    Possibility 2:
    Someone is simply buying the largest email iTMS gift certificate allowed (I checked) with fake or stolen credit card numbers.

    Possibility 1 is possible but unlikely.
    Possibility 2 is very common, very easy and very likely.

    Occam's Razor says people likely people are jumping to an unwarranted conclusion here.

    --
    http://lkml.org/lkml/2005/8/20/95
    1. Re:Occam's razor by weirdcrashingnoises · · Score: 2, Funny
      --
      sigs... don't talk to me about sigs....
    2. Re:Occam's razor by Locke2005 · · Score: 4, Insightful

      They HAVE to keep a database for the cards anyway, to keep track of every code that has already been used (can't have you using the same gift card twice now, can they?) How much harder could it be to keep track of every code that has actually been sold? But even then, there is a window of opportunity: if someone can guess your code between the time it is activated and the time you use it, then they've got your gift certificate and you don't. (This really IS stealing.) My advice to anyone who gets a gift certificate would be to use it as soon as possible. Personally, I feel gift certificates are stupid anyway -- why give somebody the equivalent of cash that can only be used at one store and which becomes worthless if that store declares bankruptcy, when you could just as easily give them cash, or a money order, or a check, or any number of other instruments that could be redeemed anywhere. I once received a gift certificate in a Christmas card that was delivered accidentally to my address, and I was able to go ahead and use it. Couldn't have done that with a check or money order, could I?

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    3. Re:Occam's razor by Anonymous Coward · · Score: 5, Insightful

      I once received a gift certificate in a Christmas card that was delivered accidentally to my address, and I was able to go ahead and use it.

      You just admitted to comitting a Federal crime, son, and a Felony at that. If I were you, I'd shut the hell up and never mention your this "freebie" to anybody.

    4. Re:Occam's razor by joebok · · Score: 3, Funny

      ... I once received a gift certificate in a Christmas card that was delivered accidentally to my address, and I was able to go ahead and use it. ...

      I think that is a crime. If not, it certainly makes you a jerk.

    5. Re:Occam's razor by plover · · Score: 5, Informative

      Well, I personally know that InComm is an authorizer to companies that sell iTunes cards at retail, and that unactivated cards have no value. No algorithm is used for those cards, other than the non-sequential generator (to prevent my_card_number+1 fraud.)

      But I also know that TFA claims that an algorithm is broken allowing for virtually unlimited generation of cards.

      So either TFA is either wrong or deliberately lying (improbable, but not impossible) or both the algorithm and on-line methods are being used by iTunes (neither particularly odd nor improbable.)

      It's not an XOR situation.

      --
      John
    6. Re:Occam's razor by Lehk228 · · Score: 2, Insightful

      200:1 when it's not your 200 is plenty profitable

      --
      Snowden and Manning are heroes.
    7. Re:Occam's razor by YesIAmAScript · · Score: 2, Informative

      Yes, I would imagine that at least some of the gift codes (there are no cards here, just the codes) will be revoked soon.

      As to the "no comment" situation, since when does Apple comment on anything?

      --
      http://lkml.org/lkml/2005/8/20/95
    8. Re:Occam's razor by porcupine8 · · Score: 4, Insightful

      why give somebody the equivalent of cash that can only be used at one store and which becomes worthless if that store declares bankruptcy, when you could just as easily give them cash, or a money order, or a check, or any number of other instruments that could be redeemed anywhere.

      Maybe because they'd prefer to get a gift card? When I get cash, I feel like I need to put it in savings, use it responsibly, etc etc. A gift card to a restaurant or store I like to buy fun stuff in is permission to have fun with it. If you're giving them a gift with the intention of them having fun, a gift card says that clearly. Of course, not everyone feels the same way I do, but part of the point of giving one gift over another is knowing which one the receiver would like most to receive, rather than just which one you'd rather give...

      --
      Warning: Apple/Nintendo fangirl. Likes her electronics cute & cuddly. May be rabid.
    9. Re:Occam's razor by IonOtter · · Score: 2, Funny

      I once received a gift certificate in a Christmas card that was delivered accidentally to my address, and I was able to go ahead and use it.

      Well that explains where my sister's gift card to Victoria's Secret went?

      --
      [End Of Line]
    10. Re:Occam's razor by WhatAmIDoingHere · · Score: 2, Insightful

      You write "return to sender" on it and send it back out the next day.

      --
      Not a Twitter sockpuppet... but I wish I was.
    11. Re:Occam's razor by Sheafification · · Score: 4, Interesting

      I said I was _able_ to go ahead and use it; I didn't say I _did_ go ahead and use it.

      That's irrelevant. Based on the fact that you knew it was a Christmas card with a gift certificate in it the GP inferred that you opened the mail which was not addressed to you. Which is a no no (last paragraph).

    12. Re:Occam's razor by schmiddy · · Score: 5, Funny

      You just admitted to comitting a Federal crime, son, and a Felony at that.

      Mail fraud? Pssh. That's small potatoes. Back in my wilder days, I once kept the NYPD busy with various bomb threats, including a real bomb set off in a subway station near the NY Fed.

      While the police were on a wild goose chase, my team of vaguely Germanic-sounding villains drove a dozen stolen dump trucks into the basement of the bullion repository in the basement of the Federal Reserve, loaded them up, and drove away with over $100 Billion worth of gold. How's that for admitting a felony online?

      --
      http://cltracker.net -- powerful craigslist multi-city search
    13. Re:Occam's razor by denzacar · · Score: 2, Informative

      If you do that, you have to ship the purchased items somewhere.

      There is this strange concept called "rented apartment", I'm not sure if you have heard of it?
      Have all the goods delivered within couple of days, loaded on a truck and then make like a tree and get out of there.

      Also, you could sell stuff directly to other people.
      Open up a store on ebay or amazon for real items - with an attractive discount.

      - People come, pay you real cash over amazon or through paypal,
      - You buy items from somewhere on the internet using your stolen cards and mail them directly to your customers.
      - Wait a bit.
      - Profit!

      --
      Mit der Dummheit kämpfen Götter selbst vergebens
    14. Re:Occam's razor by Anonymous Coward · · Score: 2, Insightful

      When I get cash, I feel like I need to put it in savings

      Too bad the other 99% of the country doesn't think that.

    15. Re:Occam's razor by RivieraKid · · Score: 2, Informative
      Don't be ridiculous. You have six months, and you are required by law to inform the sender. They are obliged to collect it at their expense, but if they haven't within six months, then and only then, is it yours to do with as you please. The fact that it was not addressed to you, regardless of being sent to your address, means that you just committed an act of treason in the UK.

      Please see section 84 of The Postal Services Act 2000 which states:

      128. Subsection (3) makes it an offence for a person, intending to act to a person's detriment and without reasonable excuse, to open a postal packet which he knows or suspects has been incorrectly delivered to him.

      Why would it become your property after 28 days when the sender doesn't even know it didn't get to the intended recipient?

      Even if the phone is duly reported lost or stolen after the 28 days then sorry, UK law permits the sale so it is entirely legal. I just wish they had sent me more phones ;)

      So now you are seriously telling us that it is legal to sell stolen property, so long as the police don't catch you within 28 days?

      You sir, are an ass.

      --
      "Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves
  6. Invalidated by Norsefire · · Score: 5, Insightful

    The other side to this is that when a legitimate customer buys a card that's code has already been found using a keygen their card won't work, I hope Apple has a refund system. The joys of security through obscurity in action.

  7. Heh by Jon.Laslow · · Score: 5, Funny

    No, kicking Apple in the nuts would be buying a fake iTunes card using MyFox on a jailbroken, unlocked iPhone 3G using a different carrier than the one the phone was sold from/for.

    1. Re:Heh by Em+Emalb · · Score: 5, Funny

      Nah, that would be feeding them to pigs after cutting them up with a chainsaw after paper cutting them to death after making them watch Mike Tyson eat their children. :-D

      --
      Sent from your iPad.
    2. Re:Heh by Mordok-DestroyerOfWo · · Score: 5, Funny

      I can't find the +1 "Dear Lord please don't let me have nightmares about that tonight!" mod.

      --
      "Never let your sense of morals prevent you from doing what is right" - Salvor Hardin
    3. Re:Heh by Henriok · · Score: 3, Insightful

      Apple would probably still make money since you a) bought an iPhone and b) solidified Apple's hold on music distribution online. Apple probably just laughed all the way to the bank, the same way Microsoft, Adobe and Autodesk are laughing all the way to the bank when their software gets distributed mer or less for free in thesemarkets. Some markets are unreachable with western prices, so if you still want to be present on them, adjust your price. Close to free, is good enough.

      --

      - Henrik

      - when the Shadows descend -
    4. Re:Heh by torkus · · Score: 3, Insightful

      Actually the hacked gift cards aren't close to free, they're negative income for Apple.

      Apple still pays a share of the purchase price of each song to the record companies regardless of the payment method. Since they're not getting the income side with hacked gift cards, it's a net loss.

      Furthermore, Apple (or the retailer, perhaps) takes an additional loss if a legitimate purchase winds up with the same card number and the user complains. I know I sure would.

      This is a HUGE problem, I'm not sure what reasonable solution they're going to come up with. Knowing Apple they'll just beat up their fanbase a little more and cancel all the GC's or something. Ok, flamebait a bit but...i could see them doing that and just hoping their market domination in MP3 sales overcomes the bad juju.

      --
      You can get rich if you own a politician, but you have to be rich to buy one in the first place.
  8. Re:And You Wonder Why Amazon MP3 Only Works in the by Anonymous Coward · · Score: 4, Funny

    The real comedy will happen when someone in China actually comes up with some IP that they want to make a buck off of. Hopefully an entire cottage industry will pop up in the rest of the world that's devoted to doing nothing but cranking out copies of whatever it is that China suddenly values, and even more hopefully that cottage industry will be named "Fuck You Chinaman, Inc.!"

  9. Re:And You Wonder Why Amazon MP3 Only Works in the by Anonymous Coward · · Score: 5, Insightful

    Personally, I think that will become the downfall of our county.

    Our main products that we're making here are things that can be easily recreated at no cost. Sure, we've got laws that attempt to stop it, but many places don't.

    We've shipped most of our jobs making actual products overseas. And we wonder why China is becoming so powerful? They're making physical goods, and freely recreating our virtual goods.

  10. The most important thing has been left out.... by Ogre332 · · Score: 2, Funny

    Where can I buy them?

    --
    Shut up brain or I'll stab you with a Q-Tip. - Homer Simpson
  11. Let's consider the crypto solution by jonaskoelker · · Score: 4, Interesting

    Possibility 1: Apple doesn't use a database for cards, they use a hash even though that would be stupid. That hash and algorithm for arranging the data before the hash was cracked even though all the verification is done on the server and thus there is no code out there to reverse-engineer. Someone is generating and selling cards using that hash.

    Let's assume that Apple cryptographers are at least half way competent.

    You could use Brand's eCash scheme in this situation. But, since Apple plays the role of both the Shop and the Bank in this scheme, you can do some simplification. So, what's the specification of this hash?

    • It should be easy for Apple (the holder of some secret key) to generate valid gift certificates, of any amount
    • It should be difficult for anyone else to generate valid certificates (of any amount)
    • It should be easy for anyone to verify the validity of a certificate.

    I think the simple solution is for Apple to generate unique strings (either random, or increasing integers) and sign them using some signature system, concatenating the value onto the plaintext.

    To redeem a certificate, Apple checks that it hasn't been redeemed before, then stores in its database that it has been redeemed. For compactness using increasing integers, store that "all integers less that n have been redeemed".

    Everyone knows Apple's public key and can verify the certificate. Only Apple knows the private key necessary to create certificates. Apple knows its own public key so it can verify certificates. It also knows to only accept each certificate once.

    I'd guess that if I can cook this up in five minutes, Apple can afford hiring someone who can cook it up at least once during their development cycle (I'm not that leet :p).

    (proof of security in the universal composability model is coming straight away; that's called proof by forward reference and it works great in the cookies)

    1. Re:Let's consider the crypto solution by Anonymous Coward · · Score: 2, Informative

      That check won't work for integers - people won't redeem cards sequentially.

  12. What's the point? by Arancaytar · · Score: 3, Insightful

    If they're going to pirate, why do they bother paying $2 to a crook to get music with DRM which they could get for free from BitTorrent? The only advantage iTunes has over piracy is that it is legal - so what's the point of ripping them off with a fake gift card?

    Even ethically, that way they'd at least not be supporting the criminal industry like the RIAA is (in this case accurately) claiming.

  13. Re:And You Wonder Why Amazon MP3 Only Works in the by complete+loony · · Score: 2, Insightful

    Why prosecute? If you can identify the illegitimate cards, you can revoke the license to all the downloaded music. Isn't this what DRM is for?

    --
    09F91102 no, 455FE104 nope, F190A1E8 uh-uh, 7A5F8A09 that's not it, C87294CE no. Ah! 452F6E403CDF10714E41DFAA257D313F.
  14. Re:And You Wonder Why Amazon MP3 Only Works in the by neil-ngc · · Score: 2, Interesting

    I guess it probably depends on how valuable Apple's manufacturing business is to China. I'm willing to bet that iPods, laptops and pretty every other physical item in Apple's line is significant enough for them to pay attention. Some people might get disappeared.

    But really, maybe Apple has learned a lesson here. Don't just validate cards using an algorithm. Keep track of which numbers you've sold, same as a credit card issuer.

  15. Re:what the fuck by mkiwi · · Score: 2, Interesting
  16. don't worry . . . . by Veni+Vidi+Dormi · · Score: 2, Funny

    don't worry . . .they're buying fake Apple products.
    Everyone Chinese wins!

  17. DRM free itunes. by Capt.DrumkenBum · · Score: 2, Insightful

    I believe itunes is DRM free as of Jan 6/09
    http://apple.slashdot.org/article.pl?sid=09/01/06/1840225

    --
    If I were God, wouldn't I protect my churches from acts of me?
    1. Re:DRM free itunes. by commodoresloat · · Score: 4, Funny

      I believe itunes is DRM free as of Jan 6/09

      http://apple.slashdot.org/article.pl?sid=09/01/06/1840225

      Yes but surely with Apple's patented Time Machine technology they can overcome this minor hurdle.

  18. Credit Card Ponzi Scheme by essinger · · Score: 2, Interesting

    I think it may even be simpler. I went to the site and, though I couldn't understand the language, it seemed as though you had to buy the iTMS certificate with a credit card! So all they have to do is use your card (or in the more elaborate scenario a previous idiot's card) to buy your gift certificate. And they buy whatever else they want with it.

    1. Re:Credit Card Ponzi Scheme by oftenwrongsoong · · Score: 2, Informative

      I imagine they're doing a superset of what you say. Mr. Idiot gives them his CC#. They sell Idiot a $50 gift card for $1. Idiot thinks all is well. Meanwhile they wait a month or two. Then they start using Idiot's CC to buy other stuff. Idiot goes WTF?! and reports the fraudulent transactions. Hundreds of similar idiots do the same. Some smart law enforcement people cross reference the transactions and find that all people who bought from a certain vendor ended up with fraudulent activity two months later. This happened before. In one example, a restaurant swiped credit cards twice, once to charge the card and once again in a second machine to record the card info. Weeks or months later they'd use the recorded info to buy stuff, until someone cross referenced and found them out. In the restaurant's case, the customers did no wrongdoing. But in this gift card case, the idiots are in some serious trouble. By reporting the fraudulent activity (which they have no idea is connected to the counterfeit gift card they bought), they will incriminate themselves because the same law enforcement people will figure out that the original, intentional, transaction was for counterfeit gift cards. Meanwhile the people running this scheme are in some other country and probably can't be touched. A bad deal any way you look at it, both for Apple and for the idiots trying to rip Apple off for cheap music.

  19. Re:And You Wonder Why Amazon MP3 Only Works in the by Cajun+Hell · · Score: 2, Interesting

    If you can identify the illegitimate cards

    ..then you can just make them not good for payment, instead of dealing with it at the DRM level.

    "No tunes for you!" is better than "Broken tunes for you!"

    --
    "Believe me!" -- Donald Trump
  20. Re:And You Wonder Why Amazon MP3 Only Works in the by SectoidRandom · · Score: 3, Informative

    When it comes to international copyright it is no surprise to me that across borders people are far less inclined to respect copyright laws of another country.

    It reminds me of something that I read once that stated that back in the 19th century before the US had established it's own home-grown authors and publishing industry, it was common place for Americans to simply copy and republish without consent the work of European authors and publishers. That was of course despite the constant complaints of European publishers and governments.

    Of course eventually the US publishers had grown to a position where they themselves realized that they needed copyright in order to continue growing with the now booming local literature scene, hence the "true" birth of enforced US copyright.

    (History repeating itself. Hmm, now how often does *that* ever happen - sarcasm)

    Unfortunately I have no original sources to this 'tale', I would appreciate if anyone can either confirm or deny this with some evidence, as it is such a compelling story I would like to believe that it is true!

  21. Buy them here but . . . by essinger · · Score: 2, Informative

    I would really think twice about using your credit card!

    http://search1.taobao.com/browse/0/n-g,nf2hk3tfom-------2-------b--40--commend-0-all-0.htm?at_topsearch=1&ssid=e-s1

  22. Re:And You Wonder Why Amazon MP3 Only Works in the by tacarat · · Score: 5, Informative

    You can't identify the illegitimate cards. Each individual card isn't kept track of. The bar code on each of them is more like the answer to a math problem. If you know how to solve the problem, you get in, no questions asked. The only thing they can do is change the math problem and eventually get rid of the old one as a valid question to answer.

    --
    "Common sense will be the death of us all"
  23. Re:And You Wonder Why Amazon MP3 Only Works in the by mean+pun · · Score: 3, Informative

    Isabella Bird, in her book The Englishwoman in America (1856) mention this copying causally, as something everyone knows.

  24. Re:Huh by ledow · · Score: 4, Interesting

    In UK law, at least, which is what 90% of the world base their law systems on:

    Very simple. It's fraud. They are *fake* cards, issued by a forger. Thus, you can be charged with fraud, or similar offences. Possibly even handling stolen/counterfeit goods, *whether you knew they were fake or not*! It's no different to faking a cheque, or a credit card. In the US, crossing state boundaries with such things can be a federal offence, so if you're not in the same state as the Apple store, it gets even worse.

    If you have the *suspicion* that they are fraudulent and / or a reasonable person would suspect them to be fraudulent (by the *court's* definition of reasonable, not yours), you can quite easily be convicted for fraud, or facilitating fraud, or breach of contract (technically a bad cheque is breach of contract and by trying to pass off this card with a retailer, you are saying that it is genuine, hence the sale could be seen as a breach of contract once they find out the money doesn't actually exist - thus they can happily charge you with fraud for the transaction AND breach of contract for failing to pay for the goods another way). It would *not* be as simple as "I just got them from some website." If a reasonable person would have had suspicions, you can *easily* be convicted - it's like saying that this gentleman knocked on the door selling an expensive in-car audio system with the wires cut and dangling, for a pittance. Whether you thought he was genuine or not, you SHOULD have known that he wasn't (just by the price, if nothing else), thus you can be found complicit in the fraud.

    Notification of the breach would certainly work in your favour but isn't an automatic get-out clause. Chances are they would pass it over but ask at which point you became suspicious, where you got it from etc. and expect you to co-operate fully. Don't and those fraud charges pop up but now they know exactly who to aim them at... you.

    Cyber-nothing. It's fraud, plain and simple, no better than making up credit card numbers and using them to buy things on Amazon. You're not the rightful keeper of any funds that you do manage to get authorized, so you're into theft (if someone can prove that *they* were entitled to the number on the card you used), fraud and maybe even counterfeiting if you can't point out where you got them from. Now, considering that Apple are both the issuer AND the recipient of the cards in question, they have a very good reason to prosecute. You've effectively stolen a credit card and then used it to pay your other Visa bill.

  25. China: One big Black Hole by NineNine · · Score: 3, Informative

    If the Chinese government doesn't start some kind of law enforcement, China is going to be a giant Black Hole. Blacklisting IP blocks from Chinese ISPs is the best thing I've ever done in terms of spam and malware control.

  26. Re:And You Wonder Why Amazon MP3 Only Works in the by Zerth · · Score: 2, Interesting

    The US only recognized domestic copyrights until 1891. Prior to that, foreign works were considered public domain. Mark Twain became a US citizen to protect his writings and lobbied for the International Copright Act.

    http://en.wikipedia.org/wiki/International_Copyright_Act_of_1891

  27. Re:And You Wonder Why Amazon MP3 Only Works in the by porges · · Score: 5, Interesting

    Gilbert and Sullivan had a big problem with this; people would come to their London openings, write down as much of the words and music as they could, take the boat to America, and put on knock-off productions. For this reason, The Pirates (!) of Penzance premiered in New York, not London.

  28. Re:And You Wonder Why Amazon MP3 Only Works in the by citizenr · · Score: 2, Interesting

    I guess it will forever remain a mystery to them why their nation isn't home to prosperous software

    WHAT?
    Guess who wrote code that runs on your Digital Picture Frame, your Camcorder, mp3 player, or your big screen LCD TV.
    Maybe you missed the story about 'Shanzai'?
    http://hardware.slashdot.org/article.pl?sid=09/02/27/049245&from=rss

    Wanna know how Chinese are able to go from design on a napkin to working product ready to ship in ONE month? They share, rip, mash-up, copy.
    Here is one of the sites used by Chinese Engineers/Developers to share brainpower
    http://www.pudn.com/

    There is no value in producing IP without a product, IP alone is worth zero. Chinese recognized it long ago.

    --
    Who logs in to gdm? Not I, said the duck.
  29. Too wordy by Anonymous Coward · · Score: 2, Insightful

    "Fake but working iTunes gift cards

    Yes, we have a word for that. The word is counterfeit.

    I'll use it in a sentence for you:

    "The RIAA attempts to convince the public that downloading music is the same as counterfeiting CD's."

  30. Wow! What useful links - full of technical detail! by Anonymous Coward · · Score: 3, Funny

    Well,

    Thanks very much for those links, they're really, really useful! Full of technical detail on the algorithm used.

    For instance, check out these facts in the article Lars T linked to:

    * The following letters and numbers can look very similar:
            The letter A and the letter H
            The letter B and the number 8
    * Apple Gift Cards can be purchased from the Apple Online Store in any amount between $25-$2500
    * To report a lost or stolen Apple Gift Card, please contact Apple at any Apple Retail Store location or by telephone at 1-800-MY-APPLE.

    It's exciting technical comments like yours (without even a whiff of smug self-congratulatory superiority) that make slashdot what it is. Thanks for educating all of us on slashdot!

  31. Re:And You Wonder Why Amazon MP3 Only Works in the by rthille · · Score: 2, Insightful

    Well, given that he _was_ Mark Freaking Twain, he got to choose where he was born!

    --
    Awesome furniture, accessories and cabinetry in Santa Rosa, CA: http://humanity-home.com/
  32. Re:And You Wonder Why Amazon MP3 Only Works in the by History's+Coming+To · · Score: 2, Informative

    Here's a close analogy:

    ISBN numbers are made out of a series of numbers identifying the language, publisher, imprint and title/edition. The last digit is the mod 11 of the sum of the numbers, each multiplied by a weighting digit based on its position in the string. To make a barcode you have three different image patterns for each digit. The last six are all represented by type "R". The first one is not represented, except for defining a pattern of "L" and "G" types for the first six numbers, and encoding itself in the process. Interesting programming exercise in the language of your choice.

    So all you have to do is reverse engineer the method used and you're there..although I suspect Apple's system is somewhat more technically challenging.

    --
    Please consider this account deleted, I just can't be bothered with the spam anymore.
  33. Nigerians in China ? by Anonymous Coward · · Score: 2, Insightful

    How do you know the cards work? Has anyone bought one?

    What if the whole thing is a scam whereby you send your couple of dollars over only to find out the cards really are fake. What will you do? Tell the police you got ripped off trying to buy a $200 card for a couple of dollars?

    If there's enough idiots out there buying into this scam it could generate a tidy sum.

  34. Re: freebie by edman007 · · Score: 4, Informative

    It is a federal crime to open mail shipped through the United states postal service that has not been delivered to the addressee.

    http://www4.law.cornell.edu/uscode/html/uscode18/usc_sec_18_00001702----000-.html

    when the mail man messes up they don't open it (and there are exemptions somewhere to allow them to open it when required). If you receive something not meant for you then you should give it back to the post office, don't open it.

  35. Re:Huh by thuerrsch · · Score: 2, Informative

    In UK law, at least, which is what 90% of the world base their law systems on:

    90 percent? More like 20. But then, 90 percent of all statistics are made up on the spot ...

    --
    most of what follows is true
  36. Re:And You Wonder Why Amazon MP3 Only Works in the by guydmann · · Score: 5, Interesting

    I agree that would be funny. But the real comedy here is that nothing is actually being stolen here. What is really happening is that a new unit of currency is being counterfeited. But that currency is backed by value in digital media, which in and of itself is ephemeral and can be obtained by other means for free. What a bizarre situation.

  37. Re:And You Wonder Why Amazon MP3 Only Works in the by WillyDavidK · · Score: 4, Insightful

    No, there is no currency exchange going on, the 'gift card' tells iTunes to exempt you from paying for the tracks as you have already presumably payed apple for the gift card. Apple is still paying the artist 70% of the cost of the music being downloaded, and they are paying in real currency.

    --
    For lack of a better signature...
  38. Re:And You Wonder Why Amazon MP3 Only Works in the by wvmarle · · Score: 4, Informative

    This comment is not just funny, it is silly and obviously from someone who knows nothing about China.

    For one, the Chinese themselves come up with a lot of IP. This ranges from music productions to technical innovations (yes also that, believe it or not). And yes they are copied big time, even though the Chinese government does try to enforce the protection of this IP. And yes it does so much more vigilantly than the protection of foreign IP. Mind that many US and other overseas patents are not valid in China in the first place, patents after all are limited to the countries/areas where they have been applied for and issued.

    If someone comes with a new product in China and has some success, everyone will jump on the bandwagon and make it as well. Even if there is no protected IP involved. If someone starts making plastic coffee cups for example, and makes a good buck out of it, dozens of other factories will spring up and do the same. They all copy one another.

    If you come up with some innovation in China and you really want to keep it for yourself you will have to keep it a secret. Don't tell anyone how you do it. This is why many Chinese are very reluctant to show you their production lines, and often you won't get access there at all. Taking photos of machines is also something that many Chinese really don't like. At trade shows many booths also have a no-photo-taking policy because otherwise within a few days they will find their newly designed jewellery at half the price all over the place. At their neighbour's booth for example (not joking).

    IP in China is as if there is effectively no IP. Everyone copies from everyone with impunity. There is little enforcement, and what enforcement takes place is largely showing off to the outside world, staged media events making it look like something is being done. China can as such be used as case study for what happens if IP would be abolished. And it is overall not a pretty picture.

  39. Re:And You Wonder Why Amazon MP3 Only Works in the by mgblst · · Score: 4, Insightful

    Except that I am sure Apple has to hand over a certain amount of money to the record labels. So a $200 card, they may have to hand over $180, and they get nothing from the consumer.

    So actually something is being stolen, from Apple to the Music companies. They don't miss out, they would be loving this. All of a sudden, they are getting millions from Apple due to China.

  40. Re:Huh by xtracto · · Score: 2, Informative

    In UK law, at least, which is what 90% of the world base their law systems on:

    Being an English, by majority of the world he meant Southern Ireland, Northern Ireland, Wales, Scotland and America (refering to the USA only)... oh! and also tath small Island how was it called? mmm Astralia or something

    --
    Ubuntu is an African word meaning 'I can't configure Debian'
  41. Re:And You Wonder Why Amazon MP3 Only Works in the by MrAngryForNoReason · · Score: 3, Informative

    I don't know how it works in the US but certainly in the UK iTunes gift cards are activated at the checkout to prevent shoplifting.