<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cyber Crooks Leave Traditional Bank Robbers in the Dust</title>
	<atom:link href="http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 04:43:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Joseph Concannon</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-11601</link>
		<dc:creator>Joseph Concannon</dc:creator>
		<pubDate>Tue, 19 Oct 2010 19:46:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-11601</guid>
		<description>Hi Folks,

Reading with some interest here since we&#039;re trying to develop our focus for our December Financial Services event for InfraGard.  InfraGard is a public/private initiative of the FBI www.infragard.net and the undersigned runs the NY InfraGard Members Office www.nym-infragard.us. 

So, why, why..why?  Well, my considered opinion and years at NYPD and now with the FBI InfraGard Program places me in a position to discuss this and perhaps to add some daylight to the why&#039;s in law enforcement.

First, there is a difference in NYPD Vs FBI focus.  Let&#039;s face it, the NYPD has something like the 6th or 7th largest army in world.  So by size the NYPD dwarfs the FBI in personnel numbers.   The FBI&#039;s largest field office is here in NYC.  It is the number one largest field office in the world.  Some exception with the Headquarters building.  NYPD’s focus is on NYC and how outside ops can impact it so far as safety and security is concerned.

NYPD is looking at the NYS Penal Law.  So examine it and see how it applies to your discussions and go from there.  I&#039;m sure that there are plenty at NYPD who with great delight would pursue addressing crime under NYS law.  In NYS we call 911 for crimes in progress or visit a local detective squad if we have information on a crime.  We do this quietly, politely and with a passion for crime control, safety and due care, not out of an eye for an eye.

The FBI is a totally different animal.  Yes, both are law enforcement agencies.....but you need see and understand the limited bandwidth of the FBI and the 180 or so violations that they are charged with addressing nationally and how it takes them worldwide.  So you have this image of a giant funnel and only so much can fit through the tiny spout at the bottom.  When you begin looking at things with this set of eyes then you can begin to understand how the FBI reacts differently then a local law enforcement agency.  Remember, the FBI has national jurisdiction and when they are challenged to address an issue.....they do so with efficiency, stealth and poise so that the greatest impact can be made.  While it may be true and can be argued that what’s worst a thousand cuts of the knife or a broken limb?  That’s not going to get you anywhere in these discussions.  Its more of the dog casing it tail again and again….oh yes and again.  It really doesn’t resolve things.  So the single one dollar crimes are certainly something to look at, but the big fish is always going to get the attention for national resources to be dedicated.

So what can be done and what should be done?  We hear much of the government should be regulating this and that and protecting all of us from the FUD……fear, uncertainty and doubt - that we hear of every day.  Fraud here, Academic sites compromised for ACT or SAT scores there, another bank with customers hanging out there…..more credit exposures the list just goes on and on.

Well, first safeguard your own PI.  Then work on your family and friends.  Unless you have the depth of Citi Group or Morgan Stanley you can’t write these losses off.  So as independent citizens we need to take personal responsibility for our own PI and use of the internet smartly.  Once we have accomplished this…..a long term strategic goal….then we can talk about national ID, and many other thoughtful and suggested recommendations to tighten things up.  No one is going to protect you from a poor education.  So don’t get behind the wheel of an automobile unless you’ve taken drivers ed, don’t operate machinery without safety equipment on and don’t go on the internet unless you know what you’re getting into and have taken some awareness course (most free) so that you can enjoy your experience.  If you pull just any life saving device off the shelf and don’t examine whether its been inspected, ready for use or is just laying there by mistake because someone put the old broken one on the wrong shelf……well…..you’ve got a problem.  Invest in your internet use and technology use by understanding what you’re bringing into your home/office and then calculate the risk of putting any information out onto the web at all.  In the end this is all going to fall on the shoulders of YOU, the individual.  Corporations pay big bucks to shield themselves from harm.  What has your family invested in to shield its members from harm?  Attend an awareness course in the last ten years?  Ever??  Most likely not, although some most likely got the lecture at work and slept through it.  Otherwise we wouldn’t be focused on it here.

It’s a mistake to think law enforcement will cure the ills of society, internet related or not.  They barely touch the surface of crime as it is and then only based upon citizen reports and chance observation.  Those of you ready to stand up and say I’ve been not so smart and lost X number of dollars with online betting, gambling, girly web sites or some other not too smart things please do let us all know.  Right now very few admit to poor use of the internet and remain quiet victims within the environment of there homes.

With that said, many technology companies could do more to pour security into the early stages of development with Software and Hardware.  But this will not in the end overcome the careless, abusive and sometimes completely irresponsible drive by internet users.

Anti-virus vendors will have to change there approach as signature based AV is a thing of the past since virus writing is now considered an “occupation” for some world-wide.

Facebook is enjoying the enlighten masses digging up contacts from yester year and plowing though the memories of a distant past.  One in fourteen are on Facebook world-wide and guess what so are organized crime and the purveyors of all sorts of fraud.  So what’s so new here….not much.

Lastly before I go too off focus….law enforcement will do what they can with the information that they have.  If you think they are ineffective….try working with them and understand prosecutions, rules of evidence and the criminal procedure law.  You voted and wrote it, so you should be aware of it.  If you don’t like what you and your elected officials wrote….well, that’s another discussion for another day.

All the best,

Joseph Concannon
NY InfraGard Inc.</description>
		<content:encoded><![CDATA[<p>Hi Folks,</p>
<p>Reading with some interest here since we&#8217;re trying to develop our focus for our December Financial Services event for InfraGard.  InfraGard is a public/private initiative of the FBI <a href="http://www.infragard.net" rel="nofollow">http://www.infragard.net</a> and the undersigned runs the NY InfraGard Members Office <a href="http://www.nym-infragard.us" rel="nofollow">http://www.nym-infragard.us</a>. </p>
<p>So, why, why..why?  Well, my considered opinion and years at NYPD and now with the FBI InfraGard Program places me in a position to discuss this and perhaps to add some daylight to the why&#8217;s in law enforcement.</p>
<p>First, there is a difference in NYPD Vs FBI focus.  Let&#8217;s face it, the NYPD has something like the 6th or 7th largest army in world.  So by size the NYPD dwarfs the FBI in personnel numbers.   The FBI&#8217;s largest field office is here in NYC.  It is the number one largest field office in the world.  Some exception with the Headquarters building.  NYPD’s focus is on NYC and how outside ops can impact it so far as safety and security is concerned.</p>
<p>NYPD is looking at the NYS Penal Law.  So examine it and see how it applies to your discussions and go from there.  I&#8217;m sure that there are plenty at NYPD who with great delight would pursue addressing crime under NYS law.  In NYS we call 911 for crimes in progress or visit a local detective squad if we have information on a crime.  We do this quietly, politely and with a passion for crime control, safety and due care, not out of an eye for an eye.</p>
<p>The FBI is a totally different animal.  Yes, both are law enforcement agencies&#8230;..but you need see and understand the limited bandwidth of the FBI and the 180 or so violations that they are charged with addressing nationally and how it takes them worldwide.  So you have this image of a giant funnel and only so much can fit through the tiny spout at the bottom.  When you begin looking at things with this set of eyes then you can begin to understand how the FBI reacts differently then a local law enforcement agency.  Remember, the FBI has national jurisdiction and when they are challenged to address an issue&#8230;..they do so with efficiency, stealth and poise so that the greatest impact can be made.  While it may be true and can be argued that what’s worst a thousand cuts of the knife or a broken limb?  That’s not going to get you anywhere in these discussions.  Its more of the dog casing it tail again and again….oh yes and again.  It really doesn’t resolve things.  So the single one dollar crimes are certainly something to look at, but the big fish is always going to get the attention for national resources to be dedicated.</p>
<p>So what can be done and what should be done?  We hear much of the government should be regulating this and that and protecting all of us from the FUD……fear, uncertainty and doubt &#8211; that we hear of every day.  Fraud here, Academic sites compromised for ACT or SAT scores there, another bank with customers hanging out there…..more credit exposures the list just goes on and on.</p>
<p>Well, first safeguard your own PI.  Then work on your family and friends.  Unless you have the depth of Citi Group or Morgan Stanley you can’t write these losses off.  So as independent citizens we need to take personal responsibility for our own PI and use of the internet smartly.  Once we have accomplished this…..a long term strategic goal….then we can talk about national ID, and many other thoughtful and suggested recommendations to tighten things up.  No one is going to protect you from a poor education.  So don’t get behind the wheel of an automobile unless you’ve taken drivers ed, don’t operate machinery without safety equipment on and don’t go on the internet unless you know what you’re getting into and have taken some awareness course (most free) so that you can enjoy your experience.  If you pull just any life saving device off the shelf and don’t examine whether its been inspected, ready for use or is just laying there by mistake because someone put the old broken one on the wrong shelf……well…..you’ve got a problem.  Invest in your internet use and technology use by understanding what you’re bringing into your home/office and then calculate the risk of putting any information out onto the web at all.  In the end this is all going to fall on the shoulders of YOU, the individual.  Corporations pay big bucks to shield themselves from harm.  What has your family invested in to shield its members from harm?  Attend an awareness course in the last ten years?  Ever??  Most likely not, although some most likely got the lecture at work and slept through it.  Otherwise we wouldn’t be focused on it here.</p>
<p>It’s a mistake to think law enforcement will cure the ills of society, internet related or not.  They barely touch the surface of crime as it is and then only based upon citizen reports and chance observation.  Those of you ready to stand up and say I’ve been not so smart and lost X number of dollars with online betting, gambling, girly web sites or some other not too smart things please do let us all know.  Right now very few admit to poor use of the internet and remain quiet victims within the environment of there homes.</p>
<p>With that said, many technology companies could do more to pour security into the early stages of development with Software and Hardware.  But this will not in the end overcome the careless, abusive and sometimes completely irresponsible drive by internet users.</p>
<p>Anti-virus vendors will have to change there approach as signature based AV is a thing of the past since virus writing is now considered an “occupation” for some world-wide.</p>
<p>Facebook is enjoying the enlighten masses digging up contacts from yester year and plowing though the memories of a distant past.  One in fourteen are on Facebook world-wide and guess what so are organized crime and the purveyors of all sorts of fraud.  So what’s so new here….not much.</p>
<p>Lastly before I go too off focus….law enforcement will do what they can with the information that they have.  If you think they are ineffective….try working with them and understand prosecutions, rules of evidence and the criminal procedure law.  You voted and wrote it, so you should be aware of it.  If you don’t like what you and your elected officials wrote….well, that’s another discussion for another day.</p>
<p>All the best,</p>
<p>Joseph Concannon<br />
NY InfraGard Inc.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-11601" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('11601', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-11601-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-11601" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('11601', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-11601-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: ryo</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-10702</link>
		<dc:creator>ryo</dc:creator>
		<pubDate>Tue, 28 Sep 2010 04:01:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-10702</guid>
		<description>I totally agree they should release the stats.</description>
		<content:encoded><![CDATA[<p>I totally agree they should release the stats.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-10702" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('10702', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-10702-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-10702" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('10702', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-10702-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Cyber-crime figures &#124; Panda Security Insight</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3901</link>
		<dc:creator>Cyber-crime figures &#124; Panda Security Insight</dc:creator>
		<pubDate>Tue, 16 Mar 2010 12:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3901</guid>
		<description>[...] written by Brian Krebs, 9.5 million dollars were stolen from physical banks in the US in the last quarter of 2009, [...]</description>
		<content:encoded><![CDATA[<p>[...] written by Brian Krebs, 9.5 million dollars were stolen from physical banks in the US in the last quarter of 2009, [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3901" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3901', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3901-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3901" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3901', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3901-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: El cybercrimen, en números &#124; Panda Security Insight</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3898</link>
		<dc:creator>El cybercrimen, en números &#124; Panda Security Insight</dc:creator>
		<pubDate>Tue, 16 Mar 2010 10:34:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3898</guid>
		<description>[...] a ataques de phishing y a robo de identidad mediante troyanos bancarios. Tal y como comenta Brian Krebs, el robo de bancos físicos en US en el último trimestre de 2009 fue de 9,5 millones, lo que [...]</description>
		<content:encoded><![CDATA[<p>[...] a ataques de phishing y a robo de identidad mediante troyanos bancarios. Tal y como comenta Brian Krebs, el robo de bancos físicos en US en el último trimestre de 2009 fue de 9,5 millones, lo que [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3898" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3898', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3898-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3898" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3898', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3898-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Dillinger would now rob the Internet. &#124; Cybersecurity and Internet Communications</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3890</link>
		<dc:creator>Dillinger would now rob the Internet. &#124; Cybersecurity and Internet Communications</dc:creator>
		<pubDate>Tue, 16 Mar 2010 04:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3890</guid>
		<description>[...] criminals stole waaay more money from e-banking accounts than they did from brick-and-mortar [...]</description>
		<content:encoded><![CDATA[<p>[...] criminals stole waaay more money from e-banking accounts than they did from brick-and-mortar [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3890" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3890', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3890-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3890" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3890', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3890-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: James R. ("Jim") Woodhill</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3860</link>
		<dc:creator>James R. ("Jim") Woodhill</dc:creator>
		<pubDate>Mon, 15 Mar 2010 15:42:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3860</guid>
		<description>Brian is correct. It was clear during the June, 2003 hearings on the identity theft provisions of the Fair and Accurate Credit Transactions Act (FACTA) that the bank executives at the witness table measured the crime in “dollars”, while the elected representatives of the people at the front of the room measured them in “victims”. To quote the Vivian Ward character in the movie “Pretty Woman”, “Big Mistake. Big, HUGE Mistake!”

$25,000,000 is 250 $100,000 losses, and, as Brian has documented with the sad case of Long Island-based Little &amp; King, a $100,000 loss is enough to *kill* a small company with a thriving business.

A small- and medium-sized enterprise being murdered in over half the congressional districts in America every quarter will draw a political response.  That response will come much quicker if, for some reason, this cause attracts a &quot;lobbyist&quot; willing to work &quot;pro-bono&quot;... </description>
		<content:encoded><![CDATA[<p>Brian is correct. It was clear during the June, 2003 hearings on the identity theft provisions of the Fair and Accurate Credit Transactions Act (FACTA) that the bank executives at the witness table measured the crime in “dollars”, while the elected representatives of the people at the front of the room measured them in “victims”. To quote the Vivian Ward character in the movie “Pretty Woman”, “Big Mistake. Big, HUGE Mistake!”</p>
<p>$25,000,000 is 250 $100,000 losses, and, as Brian has documented with the sad case of Long Island-based Little &amp; King, a $100,000 loss is enough to *kill* a small company with a thriving business.</p>
<p>A small- and medium-sized enterprise being murdered in over half the congressional districts in America every quarter will draw a political response.  That response will come much quicker if, for some reason, this cause attracts a &#8220;lobbyist&#8221; willing to work &#8220;pro-bono&#8221;&#8230; </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3860" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3860', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3860-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3860" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3860', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3860-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: James R. ("Jim") Woodhill</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3859</link>
		<dc:creator>James R. ("Jim") Woodhill</dc:creator>
		<pubDate>Mon, 15 Mar 2010 15:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3859</guid>
		<description>Brian is correct.  It was clear during the June, 2003 hearings on the identity theft provisions of the Fair and Accurate Credit Transactions Act (FACTA) that the bank executives at the witness table measured the crime in &quot;dollars&quot;, while the elected representatives of the people at the front of the room measured them in &quot;victims&quot;.  To quote the Vivian Ward character in the movie &quot;Pretty Woman&quot;, &quot;Big Mistake.  Big, HUGE Mistake!&quot;

$25,000,000 is 250 $100,000 losses, and, as Brian has documented with the sad case of Long Island-based Little &amp; King, a $100,000 loss is enough to *kill* a small company with a thriving business.  

A small- and medium-sized enterprise</description>
		<content:encoded><![CDATA[<p>Brian is correct.  It was clear during the June, 2003 hearings on the identity theft provisions of the Fair and Accurate Credit Transactions Act (FACTA) that the bank executives at the witness table measured the crime in &#8220;dollars&#8221;, while the elected representatives of the people at the front of the room measured them in &#8220;victims&#8221;.  To quote the Vivian Ward character in the movie &#8220;Pretty Woman&#8221;, &#8220;Big Mistake.  Big, HUGE Mistake!&#8221;</p>
<p>$25,000,000 is 250 $100,000 losses, and, as Brian has documented with the sad case of Long Island-based Little &amp; King, a $100,000 loss is enough to *kill* a small company with a thriving business.  </p>
<p>A small- and medium-sized enterprise</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3859" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3859', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3859-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3859" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3859', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3859-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: James R. ("Jim") Woodhill</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3858</link>
		<dc:creator>James R. ("Jim") Woodhill</dc:creator>
		<pubDate>Mon, 15 Mar 2010 15:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3858</guid>
		<description>I think the $120 million figure includes losses (such as those from ATM card skimming) that are covered by Regulation E and therefore the banks have to eat.  The $25 million figure is FDIC&#039;s Dave Nelson&#039;s number for the losses to *commercial* customers that the banks did not reimburse because the government does not (currently) compel them to do so.</description>
		<content:encoded><![CDATA[<p>I think the $120 million figure includes losses (such as those from ATM card skimming) that are covered by Regulation E and therefore the banks have to eat.  The $25 million figure is FDIC&#8217;s Dave Nelson&#8217;s number for the losses to *commercial* customers that the banks did not reimburse because the government does not (currently) compel them to do so.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3858" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3858', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3858-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3858" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3858', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3858-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3739</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Fri, 12 Mar 2010 17:40:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3739</guid>
		<description>@Lynda - I don&#039;t know where SANS got its numbers from. But I believe $120M figure you&#039;re seeing floating around is supposed to represent a cumulative number -- not just one three-month period&#039;s worth).</description>
		<content:encoded><![CDATA[<p>@Lynda &#8211; I don&#8217;t know where SANS got its numbers from. But I believe $120M figure you&#8217;re seeing floating around is supposed to represent a cumulative number &#8212; not just one three-month period&#8217;s worth).</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3739" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3739', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3739-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3739" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3739', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3739-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: John T. Hoffoss</title>
		<link>http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/comment-page-1/#comment-3656</link>
		<dc:creator>John T. Hoffoss</dc:creator>
		<pubDate>Thu, 11 Mar 2010 17:35:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1609#comment-3656</guid>
		<description>Quoting from Brian&#039;s article might help to explain why this gets ignored by the FBI:

&quot;In fact, real-life bank robbers stole a total of just over $30 million in the first three quarters of 2009, just $5 million more than cyber crooks did in the third quarter of last year alone.&quot;

We don&#039;t look at &quot;cyber&quot; crooks as &quot;crooks!&quot; We prepend with a statement like &quot;real-life bank robbers,&quot; when we turn around and refer to what *are* real-life bank robbers.

Steve wrote:

&quot;&gt; It’s probably because it takes a long time for the FBI to
&gt; change direction. Thats how they missed 9/11.

How about something more realistic, and to the point. Sometimes, there isn’t anything that they can do.

You can’t look at every failure, no matter how big, and say &#039;look, they didn’t protect us&#039;. &quot;

I don&#039;t know if the commenter Steve replied to meant the FBI should prevent this, but the investigation, follow-up and prosecution is sorely lacking. Our laws are sufficient but very few attorneys and judges understand that electronic crime isn&#039;t all that different from real-world crime, and even fewer can make the correlation necessary to help others understand that.

A bank robber is someone who steals from banks. But the fact that it isn&#039;t considered robbery if a robber steals from a specific account is ridiculous. That $25 million should be reported and tracked by the FBI just like the &quot;real&quot; robberies are.</description>
		<content:encoded><![CDATA[<p>Quoting from Brian&#8217;s article might help to explain why this gets ignored by the FBI:</p>
<p>&#8220;In fact, real-life bank robbers stole a total of just over $30 million in the first three quarters of 2009, just $5 million more than cyber crooks did in the third quarter of last year alone.&#8221;</p>
<p>We don&#8217;t look at &#8220;cyber&#8221; crooks as &#8220;crooks!&#8221; We prepend with a statement like &#8220;real-life bank robbers,&#8221; when we turn around and refer to what *are* real-life bank robbers.</p>
<p>Steve wrote:</p>
<p>&#8220;&gt; It’s probably because it takes a long time for the FBI to<br />
&gt; change direction. Thats how they missed 9/11.</p>
<p>How about something more realistic, and to the point. Sometimes, there isn’t anything that they can do.</p>
<p>You can’t look at every failure, no matter how big, and say &#8216;look, they didn’t protect us&#8217;. &#8221;</p>
<p>I don&#8217;t know if the commenter Steve replied to meant the FBI should prevent this, but the investigation, follow-up and prosecution is sorely lacking. Our laws are sufficient but very few attorneys and judges understand that electronic crime isn&#8217;t all that different from real-world crime, and even fewer can make the correlation necessary to help others understand that.</p>
<p>A bank robber is someone who steals from banks. But the fact that it isn&#8217;t considered robbery if a robber steals from a specific account is ridiculous. That $25 million should be reported and tracked by the FBI just like the &#8220;real&#8221; robberies are.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-3656" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('3656', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-3656-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-3656" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('3656', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-3656-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 1/23 queries in 0.006 seconds using memcached
Object Caching 951/967 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-23 01:49:46 -->
