Following the Money In Cybercrime
jbrodkin writes "Five dollars for control over 1,000 compromised email accounts. Eight dollars for a distributed denial-of-service attack that takes down a website for an hour. And just a buck to solve 1,000 captchas. Those are the going rates of cybercrime, the amounts criminals pay other criminals for the technical services necessary to launch attacks. This criminal underground was detailed Wednesday in a highly entertaining talk given by researcher Stefan Savage at the annual Usenix technical conference in Portland, Ore. Savage's research into the economics of cybercrime began as lip service to satisfy the terms of a government grant, but it turned out to be the key to stopping computer attacks. Targeted methods — such as using CAPTCHAs — don't stop criminals, but they add to the cost burden and put the inefficient criminal organizations out of business, letting security researchers focus only on the ones that survive."
Now we just need to hope that they don't breed better attackers that are all resistant.
But how do you pay these "companies" when you want to purchase their services? I'm sure not going to give them credit card, or an electronic bank transfer. Do they accept BitCoins? ;-)
At those prices, I can't afford to NOT spam!
I am beginning to think that everyone should be forced to take an economics course in their lifetime. So much of the world is driven by economics that I think you'll understand the world quite a bit better if you understand the dollars and cents behind it. Perhaps its a case of "the more economics you know, the more economics you see."
I don't know if you've read Freakonomics or not but that is basically the premise of the entire book(s). There are economics in everything, people respond to incentives and if you set up your incentives properly you'll get the result you desire. Fail to properly incentivize people and you can get all sorts of interesting results. I particularly like the Israeli Day Care example.
I'll meet you at the intersection of "Should be" and "Reality"
It suggests that CAPTCHAs can narrow the profit margin, but just a few lines above that it says they only cost a dollar to overcome. So these spammers will sell 1000 e-mail accounts for 8 dollars, and adding a dollar to the end cost to compensate for the CAPTCHAs would totally destroy their business model?
Was that supposed to mean that each of the thousand CAPTCHAs adds a dollar in cost to spammers? Because then I could see how that would cause some problems for them.
I wonder what the going rate for stealing credit card numbers that have been saved on a website for returning customers. I know, because I've been the victim on identity theft twice now, and let me tell you, it ain't pretty. Recovering financially takes a year or more through vigorous DIY credit repair strategies and can make you weary of future online purchases. I read in another recent post all the grief that PayPal gives its customers and I can also attest to the fact that they are the most self-serving douche bags on the internet. Their operation is criminal... negligent at best. But seriously, $8 for a denial of service attack is super cheap. Hopefully as people start getting more serious about cybercrime, we can look back in 10-20 years and look at the internet as the Italian mafia with its godfathers being Google, PayPal, Facebook and the rest of the power holders sitting in prisons or at least crashing and burning financially.
Was this talk recorded? If so, does anybody have a url?
Of course you follow the money. There aren't that many spammers; about three years ago, there seemed to be only about ten unique large-scale spammers. Taking one of them down made a significant dent in spam traffic for a month.
Junky spam and junky bogus web sites are obsolete, even in the criminal world. The old mindset was to filter out emails and sites that "looked junky". The old "Web Spam Challenge was based on this. They have a big file of pages which humans have classified, by a quick look, as "spam" or "not spam". Five or ten years ago, that sort of worked, because most of the junk sites were really tacky. Phishing sites used to have blatant misspellings. That's history. Today's crooks have good web site production values.
So you have to dig deeper. On the web spam/bogus web site front, part of the right answer is to find out who's behind the web site and do a background check. (We do that at SiteTruth.com, as I've mentioned before.) Right now, even a superficial check (is there a mailing address on the site? Is it a known phishing site? Do seals of approval check out? Non-junk SSL cert?) is enough to knock out a big fraction of the junk. The deeper checks (is there a business at that address? How long in business? How much revenue last year? What's their business credit rating?) tell us enough to have some confidence about business legitimacy.
The original article mentions "ordering tons of stuff from phishing scams to trace the path of the money." That's what the FBI should be doing more of. Law enforcement can have accounts created, plug into the credit card system, and watch their credit cards being used in real time. It's hard to do that without law enforcement authority.
Busting CAPTCHAs is not a crime. Not usually, anyway. Sure, it may violate a website's terms of service, but US courts so far (quite correctly) say that's not a crime, unless you're "stealing" a for-pay service. And maybe not even then.
It is not valid to label something a "crime" just because it's inconvenient for some people. The lesson to be learned here is that CAPTCHAs are a lazy (and often lousy) way to prevent "unauthorized" access.
Also, while most CAPTCHAs today can be busted with automated tools, as OP says it's often more economical to just hire teams of people from Pakistan or India to do it manually. The going rate on freelancer sites is about $1 per 1000, but sometimes it's even less.
Always think of this comic when i hear the word captcha now.
xkcd
They're nasty SOB's too:
http://www.esecurityplanet.com/trends/article.php/3935941/New-Injection-Attack-30000-Websites.htm
"Now we just need to hope that they don't breed better attackers that are all resistant." - by DanTheStone (1212500) on Thursday June 16, @01:32PM (#36465516)
Break out the "Zithromax" then... looks like we'll need it!
APK
P.S.=> Now - SQLInjection's fairly easy to stop (via Stored Procedures usage, BIND variables usage, & removal of business logic out of front ends in general (if not blocking out redirects as I do to over 1, 444, 345++ known bad sites/servers/domains-hosts as I do via a HOSTS file, or a firewall (or even a TPL for IE, Opera's URLFILTER.INI or FireFox's methods etc.))...
This type though? Quite a bit worse
So - Hate to say "I told you so", but... it furthers the case for my stating to people to LIMIT THEIR USE OF JAVASCRIPT as I have said for YEARS here:
http://www.bing.com/search?q=%22HOW+TO+SECURE+Windows+2000%2FXP%22&go=&form=QBRE
nd a decade before it here:
http://www.neowin.net/news/apk-a-to-z-internet-speedup--security-text
Man - yes, I know: You NEED javascript for some sites (think e-commerce) but... the second I saw scriptable documents in say, Word & Excel docs + their macros being taken advantage of in VB-Script/VBA? I knew that scripting web HTML documents was going to be the same!
So, do take a read, be enlightened folks!
... apk
It is if it's the abbreviation for Indiana (IN).
http://www.usenix.org/events/atc11/stream/savage/index.html
Is what you need to become if you want to do crimes of money these days. If our government was serious, this crap would be toast instantly. See how quick they got the DC Sniper after he gave them no more than a Cayman Island bank account number. Think "what would Harry Harrison do?".
This proves that
A: We're not serious about this.
B: It's probably half the government itself in an attempt to create people believing they need even more power.
Why guess when you can know? Measure!
https://secure.wikimedia.org/wikipedia/en/wiki/Economic_mobility != https://secure.wikimedia.org/wikipedia/en/wiki/Social_mobility
Slashdot = Sarcasm
IN is not an abbrev. IN is a post office obamanation. Ind. is an abbrev. of Indiana. Ft. is an abbrev. for Fort. Class dismsissed.
capitalism will take care of that.