<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: computer whiz vs extortionist</title>
	<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist/</link>
	<description>Comments on MetaFilter post computer whiz vs extortionist</description>
	<pubDate>Tue, 14 Mar 2006 17:37:44 -0800</pubDate>
	<lastBuildDate>Tue, 14 Mar 2006 17:37:44 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>computer whiz vs extortionist</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist</link>	
		<description>&lt;a href="http://www.csoonline.com/read/050105/extortion.html"&gt;How a Bookmaker and a Whiz Kid Took On an Extortionist &#8212; and Won&lt;/a&gt; Facing an online extortion threat, Mickey Richardson bet his Web-based business on a networking whiz from Sacramento who first beat back the bad guys, then helped the cops nab them.</description>
		<guid isPermaLink="false">post:www.metafilter.com,2006:site.50060</guid>
		<pubDate>Tue, 14 Mar 2006 16:51:44 -0800</pubDate>
		<dc:creator>dhruva</dc:creator>		<category>extortion</category>		<category>bookmaker</category>		<category>ddos</category>
	</item>	<item>
		<title>By: kensanway</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245716</link>	
		<description>This was really interesting! There seems to be a typo in the last quote, where it sounds like Lyon impeaches himself?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245716</guid>
		<pubDate>Tue, 14 Mar 2006 17:37:44 -0800</pubDate>
		<dc:creator>kensanway</dc:creator>
	</item>	<item>
		<title>By: russilwvong</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245721</link>	
		<description>That&apos;s awesome.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245721</guid>
		<pubDate>Tue, 14 Mar 2006 17:43:42 -0800</pubDate>
		<dc:creator>russilwvong</dc:creator>
	</item>	<item>
		<title>By: kaemaril</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245723</link>	
		<description>Hmm. Seems vaguely familiar. Looks at timestamp ... Saturday, Nov. 22, 2003?! Oh, come on!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245723</guid>
		<pubDate>Tue, 14 Mar 2006 17:48:14 -0800</pubDate>
		<dc:creator>kaemaril</dc:creator>
	</item>	<item>
		<title>By: solipse</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245727</link>	
		<description>Yeah, I remember reading this years ago....but it is still pretty interesting if you haven&apos;t seen it before.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245727</guid>
		<pubDate>Tue, 14 Mar 2006 17:54:34 -0800</pubDate>
		<dc:creator>solipse</dc:creator>
	</item>	<item>
		<title>By: TravellingDen</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245731</link>	
		<description>This was a long time ago. 

It was not uncommon to see botnets of 30,000 hosts, and to be attacked with well over 1Gbps of traffic. It was amazing.

What was more amazing was despite the sums of money involved, and the resources the attackers had on hand, they did basically no research whatsoever into the infrastructure of the sites they were attacking, or which sites were owned by the same company, or anything like that.  In some respects it was really amazing, in others, it was very uninformed and clumsy. These were not sophisticated hackers or criminals.. they were russian script kiddies with ties to organized crime and a feeling of impunity.

Some interesting followup,  DDOS attacks against online sportsbooks have basically been a non-issue since I believe spring of 2004.  Many operations beefed up their infrastructure, and there were several high profile arrests in Russia and elsewhere, organized by multi-national police cooperation.  The trials are still ongoing to this day.

Nowadays, the books know better than to pay up, the infrastructure is more resilient, and the ISPs are more cooperative in dealing with the issue.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245731</guid>
		<pubDate>Tue, 14 Mar 2006 18:05:58 -0800</pubDate>
		<dc:creator>TravellingDen</dc:creator>
	</item>	<item>
		<title>By: roguescout</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245734</link>	
		<description>They should fill those criminals up with &lt;a href=&quot;http://products3.3m.com/catalog/us/en001/auto_marine_aero/automotive_aftermarket/node_GSJBSGXLK7gs/root_GST1T4S9TCgv/vroot_GSLPLPKL4Xge/bgel_GSS7TMQ9LPbl/gvel_VBF19DZVHXgl/theme_us_aad_3_0/command_AbcPageHandler/output_html&quot;&gt;this&lt;/a&gt; and cause them to have a fatal Denial of Elimination Attack!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245734</guid>
		<pubDate>Tue, 14 Mar 2006 18:09:45 -0800</pubDate>
		<dc:creator>roguescout</dc:creator>
	</item>	<item>
		<title>By: rkent</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245738</link>	
		<description>&lt;i&gt;This was really interesting! There seems to be a typo in the last quote, where it sounds like Lyon impeaches himself?&lt;/i&gt;

I didn&apos;t take it that way; seemed to me he was saying he would had to have cloned himself to be working both sides of this, since he was working so hard just on the one side.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245738</guid>
		<pubDate>Tue, 14 Mar 2006 18:13:07 -0800</pubDate>
		<dc:creator>rkent</dc:creator>
	</item>	<item>
		<title>By: tweak</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245741</link>	
		<description>That&apos;s still a really cool story, and reminded me of &lt;a href=&quot;http://www.amazon.com/exec/obidos/ASIN/0671726889/metafilter-20/ref=nosim/&quot;&gt;Cuckoo&apos;s Egg&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245741</guid>
		<pubDate>Tue, 14 Mar 2006 18:16:36 -0800</pubDate>
		<dc:creator>tweak</dc:creator>
	</item>	<item>
		<title>By: soiled cowboy</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245768</link>	
		<description>Great story.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245768</guid>
		<pubDate>Tue, 14 Mar 2006 19:04:57 -0800</pubDate>
		<dc:creator>soiled cowboy</dc:creator>
	</item>	<item>
		<title>By: rxrfrx</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245778</link>	
		<description>a classic</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245778</guid>
		<pubDate>Tue, 14 Mar 2006 19:23:00 -0800</pubDate>
		<dc:creator>rxrfrx</dc:creator>
	</item>	<item>
		<title>By: arcticwoman</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245781</link>	
		<description>Neat.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245781</guid>
		<pubDate>Tue, 14 Mar 2006 19:27:31 -0800</pubDate>
		<dc:creator>arcticwoman</dc:creator>
	</item>	<item>
		<title>By: alfaspider71</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245782</link>	
		<description>Interesting story, but a bit old.  Definitely worth a read if you haven&apos;t seen it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245782</guid>
		<pubDate>Tue, 14 Mar 2006 19:31:34 -0800</pubDate>
		<dc:creator>alfaspider71</dc:creator>
	</item>	<item>
		<title>By: flabdablet</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245785</link>	
		<description>I like the way the victim ends up $1m + $50k/year out of pocket to a white hat, instead of $40k out of pocket to a black hat.

It seems to me that instead of entering into a never-ending networking arms race, it might be better simply to get an insurer to pay the extortionist off for you.  I&apos;m no actuary, but it seems to me that the premiums would cost less for individual businesses than either consultants&apos; fees or extortion payments; also, the underwriter would end up with way more than $1m to play with, and a direct financial interest in employing investigators to follow money trails and track down miscreants.

This is kind of a similar approach to what the banks take in respect of credit card fraud.  Everybody understands that credit cards are massively insecure, and that some degree of fraud is inevitable; but rather than change card procedures until they&apos;re inconveniently secure, the interest rates are jacked up enough to cover the fraud losses.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245785</guid>
		<pubDate>Tue, 14 Mar 2006 19:44:01 -0800</pubDate>
		<dc:creator>flabdablet</dc:creator>
	</item>	<item>
		<title>By: MrMoonPie</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245794</link>	
		<description>&lt;a href=&quot;http://dictionary.reference.com/search?q=whiz&quot;&gt;Whiz&lt;/a&gt; &lt;a href=&quot;http://images.google.com/images?sourceid=navclient&amp;ie=UTF-8&amp;rls=GGLR,GGLR:2005-46,GGLR:en&amp;q=calvin%20peeing&amp;sa=N&amp;tab=wi&quot;&gt;kid&lt;/a&gt;. &lt;a href=&quot;http://dictionary.reference.com/search?q=wiz&quot;&gt;Wiz&lt;/a&gt; &lt;a href=&quot;http://images.google.com/images?svnum=10&amp;hl=en&amp;lr=&amp;rls=GGLR%2CGGLR%3A2005-46%2CGGLR%3Aen&amp;q=nerd&quot;&gt;kid&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245794</guid>
		<pubDate>Tue, 14 Mar 2006 19:54:46 -0800</pubDate>
		<dc:creator>MrMoonPie</dc:creator>
	</item>	<item>
		<title>By: tweak</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245807</link>	
		<description>flabdablet: and so what happens if you get extorted more than once a year, by more than one botnet owner.

This isn&apos;t like Mafia protection money, that&apos;s the wrong way of looking at it. It&apos;s not like if you pay the Russian script kiddie to stop fucking with you, other script kiddies won&apos;t try the same thing.

It&apos;s more like operating a bank with no lock on the vault; sure, the lock is pretty expensive, but if you don&apos;t invest in it initially, eventually more and more people are going to rob you until you get put out of business.

What will be really interesting to see is when someone who gets seriously fucked with by a hacker or scammer fights back IRL by hiring another criminal to take out the extortionist in an illegal manner.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245807</guid>
		<pubDate>Tue, 14 Mar 2006 20:15:14 -0800</pubDate>
		<dc:creator>tweak</dc:creator>
	</item>	<item>
		<title>By: pruner</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245821</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/mefi/50060#1245723&quot;&gt;kaemaril&lt;/a&gt; - &lt;i&gt;Looks at timestamp ... Saturday, Nov. 22, 2003?! Oh, come on!&lt;/i&gt;

actually, the article is from May 2005. 

that &quot;timestamp&quot; is part of the article.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245821</guid>
		<pubDate>Tue, 14 Mar 2006 20:42:44 -0800</pubDate>
		<dc:creator>pruner</dc:creator>
	</item>	<item>
		<title>By: Mitrovarr</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245824</link>	
		<description>It seems that it&apos;d be more efficient in some of these cases to hire private investigators, instead of beefing the hell out of the infrastructure.  I&apos;m sure it&apos;s hard to track these guys down on the internet, but large amounts of money changing hands usually leaves a nice fat paper trail.  Hire some guys to track that down, get your money back, and make an example out of the extortionists in the local courts.  Much more effective than paying them off, which will only encourage more and more of this.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245824</guid>
		<pubDate>Tue, 14 Mar 2006 20:45:36 -0800</pubDate>
		<dc:creator>Mitrovarr</dc:creator>
	</item>	<item>
		<title>By: rkent</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245830</link>	
		<description>&lt;a href=&quot;http://www.metafilter.com/mefi/50060#1245807&quot;&gt;tweak&lt;/a&gt;: you misunderstood his suggestion.  The point is that you pay the insurance company and they pay &lt;i&gt;all&lt;/i&gt; extortionists; the rate is set such that they make enough revenue to hire some investigators and hunt down some of them as a means of deterrence.

It&apos;s certainly the better option from the business perspective, as long as the rates would actually be affordable.  And I&apos;m not sure what authority the insurance company would really have to do anything to the offenders, regardless of how much incentive they had.  They&apos;re probably judgment-proof and so there would need to be a good deal of state cooperation if this was to work.  An interesting idea though.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245830</guid>
		<pubDate>Tue, 14 Mar 2006 20:56:16 -0800</pubDate>
		<dc:creator>rkent</dc:creator>
	</item>	<item>
		<title>By: Ogre Lawless</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245840</link>	
		<description>Interesting geek intrigue story.  Good link.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245840</guid>
		<pubDate>Tue, 14 Mar 2006 21:22:14 -0800</pubDate>
		<dc:creator>Ogre Lawless</dc:creator>
	</item>	<item>
		<title>By: zardoz</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245842</link>	
		<description>That was very long and I didn&apos;t really understand half of it but it was fascinating nonetheless.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245842</guid>
		<pubDate>Tue, 14 Mar 2006 21:25:06 -0800</pubDate>
		<dc:creator>zardoz</dc:creator>
	</item>	<item>
		<title>By: kensanway</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245851</link>	
		<description>Well, regarding the whole problem of the commons thing, another idea that might make more sense is for the companies to pool their funds to pay a consultant, thus reducing their prices, and then share the software and techniques the consultant produces. Eventually other consultants enter, leading to competition, lowering prices, etc. But apparently, this isn&apos;t a problem anymore?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245851</guid>
		<pubDate>Tue, 14 Mar 2006 21:34:14 -0800</pubDate>
		<dc:creator>kensanway</dc:creator>
	</item>	<item>
		<title>By: hwestiii</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1245990</link>	
		<description>I&apos;ve seen this story in two different places in the last year.  The first was the aticle in the FPP when it was originally published last spring.  &lt;a href=&quot;http://www.wired.com/news/infostructure/0,1377,66358,00.html?tw=wn_tophead_1&quot;&gt;Wired also covered it here.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1245990</guid>
		<pubDate>Wed, 15 Mar 2006 05:30:44 -0800</pubDate>
		<dc:creator>hwestiii</dc:creator>
	</item>	<item>
		<title>By: Jairus</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1246002</link>	
		<description>&lt;i&gt;Richardson considered paying off the extortionists. Now Richardson has a better option. Pay Lyon $50,000 a year and he&apos;s protected. He doesn&apos;t have to worry about paying extortionist&apos;s protection fees.&lt;/i&gt;

Heh heh heh.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1246002</guid>
		<pubDate>Wed, 15 Mar 2006 05:57:58 -0800</pubDate>
		<dc:creator>Jairus</dc:creator>
	</item>	<item>
		<title>By: stratastar</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1246054</link>	
		<description>The New Yorker also wrote up this story, but this one is told much better. Lyon&apos;s other project &lt;a href=&quot;www.opte.org&quot;&gt;opte.org&lt;/a&gt; has very cool &lt;a href=&quot;http://opte.org/maps/&quot;&gt;pictures &lt;/a&gt;of the interconnectedness of the internet.

Ooh and they have a &lt;a href=&quot;http://www.prolexic.com/zr/zombiereportq12.edit.png&quot;&gt;picture &lt;/a&gt;of a DDoS attack.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1246054</guid>
		<pubDate>Wed, 15 Mar 2006 07:14:16 -0800</pubDate>
		<dc:creator>stratastar</dc:creator>
	</item>	<item>
		<title>By: login</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1246057</link>	
		<description>$50000 per year might seem stiff until you realize this is being billed to companies that sell little bits of _nothing_ at a huge markup.

These are the guys that will pay 10 grand for a toasted cheese sandwich, so $50000 for peace of mind is nothing.

(great link. old, but a fun read)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1246057</guid>
		<pubDate>Wed, 15 Mar 2006 07:16:31 -0800</pubDate>
		<dc:creator>login</dc:creator>
	</item>	<item>
		<title>By: Optimus Chyme</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1246095</link>	
		<description>New to me.  Thanks for the read.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1246095</guid>
		<pubDate>Wed, 15 Mar 2006 08:38:53 -0800</pubDate>
		<dc:creator>Optimus Chyme</dc:creator>
	</item>	<item>
		<title>By: russilwvong</title>
		<link>http://www.metafilter.com/50060/computer-whiz-vs-extortionist#1252557</link>	
		<description>A couple articles on volunteer groups which are hunting down botnets, via &lt;a href=&quot;http://it.slashdot.org/article.pl?sid=06/03/21/1752254&quot;&gt;slashdot&lt;/a&gt;:  &lt;a href=&quot;http://www.washingtonpost.com/wp-dyn/content/article/2006/03/21/AR2006032100279.html&quot;&gt;Washington Post&lt;/a&gt;, &lt;a href=&quot;http://www.eweek.com/article2/0,1759,1829347,00.asp&quot;&gt;eWeek&lt;/a&gt;.

After reading a few of these articles, I got paranoid enough that I reinstalled Windows on my home PC.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2006:site.50060-1252557</guid>
		<pubDate>Tue, 21 Mar 2006 13:38:57 -0800</pubDate>
		<dc:creator>russilwvong</dc:creator>
	</item>
	</channel>
</rss>
