Hacking Ring Nabbed By US Authorities
Slatterz writes "The members of a hacking ring responsible for stealing more than 40 million credit and debit card numbers from retail organizations in the US have been caught and charged. The case before the US Department of Justice is believed to be the largest hacking and identity theft case ever prosecuted. The criminals allegedly obtained bank details by hacking into the retailers' computer networks and then installing 'sniffer' programs to capture card numbers and password details as the customers moved through the retailers' credit and debit processing networks."
are security measures going to be changed with this revelation to the public? having seen the inner-workings of various bank and investment facilities, i can safely say that one doesn't need to go through any really complicated work to take financial information from consumers: most wiring closets aren't even locked.
If you felt a little cheated by the lack of info in the 'article' the DOJ site has more.
OMG facts!
I heard that they went around to stores using wireless networks to process purchases at checkout. Basically any store that thought they were being high tech by using wireless registers. Guess they forgot to encrypt the data...anyone have a better link?
hacking (uncountable)
...4b: to gain access to a computer illegally
1. (computing) Unauthorized attempts to bypass the security mechanisms of an information system or network.
Hack
You may prefer to use other definitions yourself, but the usage here is perfectly correct.
Links to the indictments of the top two suspects:
suspect 1
suspect 2
You can bet hackers didn't write those definitions. Those definitions are accurate in the context of mainstream media, but as the GP stated, this is /.
What's the value of information that you don't know?
http://news.bbc.co.uk/2/hi/business/7545212.stm has a much better write-up.
So now we will get even MORE draconian measures to stop the "evil hackers" when in reality, it was a combination of bad intentions, and old-fashioned stupidity. The article specifically mentions looking for "vulnerable" access points. This means that whoever set the network up for these stores did not do a proper job in securing said network. Also, why the HELL were the systems used to process credit card transactions on the same insecure wireless network? There is NO excuse for that. I'm not excusing what these guys did, but once again we have a case where whoever setup the hardware in these places needs to be held for criminal negligence.
"So after all this, you make my case for me. To end this stalemate, you must die..."
I've always wondered how safe you are when paying utility bills over the phone using a tone phone, like if someone finds a connection at the call centre which takes the card number and listens to tones of card numbers/expiry dates/verification numbers flowing through the line. Maybe it's a little more secure than my paranoid mind thinks, maybe someone knows a little detail on what's involved with these systems?
Task Mangler
kick to the chest
Provided that this is still the /. that we all know, this should not be necessary, but one may never be sure about the level of truth...
There used to be a time when you read tech-news first on slashdot. Nowadays I read it in my (Dutch) newspaper first (yep, the paper one that they actually have to print and deliver first) end a few days later it appears in /.
What the hell is wrong?
Troll?
Ouch, looks like I hit a nerve...
The quote the immortal words of our Imam: "Nowadays, it is claimed that the Chinese and even WOMEN are hacking things. Man, am I ever glad I got a chance to experience "the scene" before it degenerated completely. And remember, kids, knowing how to program or wanting really badly to figure out how things work inside doesn't make you a hacker! Hacking boxes makes you a "hacker"! That's right! Write your local representatives at Wikipedia/urbandictionary/OED and let them know that hackers are people that gain unauthorized access/privileges to computerized systems! Linus Torvalds isn't a hacker! Richard Stallman isn't a hacker! Niels Provos isn't a hacker! Fat/ugly, maybe! Hackers, no! And what is up with the use of the term "cracker"? As far as I'm concerned, that term applies to people that bypass copyright protection mechanisms. Vladimir Levin? HACKER. phiber optik? HACKER. Kevin Mitnick? OK, maybe a gay/bad one, but still WAS a "hacker." Hope that's clear."
There are over 36 million lines of COBOL code in the world, and they are all raping children.
;-)
Dear hackers,
You can't own a word. Get over it.
There is such a big difference between people who do it for the fun, and challenge, and those who do it for personal gain. I really wish the media would pick up on these differences. Me personally I enjoy the challenge, and find it to be fun, and I consider myself a hacker. Of course if I went around telling people that they would get this idea that "I'm the bad guy who wants to steal all of your personal information". They really need to do some investigative reporting to see that there are white hat hackers and black hat hackers...of course with media outlets such as fox news, cnn, msnbc, etc...they tend not to seek out the truth.
So, who foots the bill for this? The retailer, the credit card comany / debit card issuer, or the customer?
Don't try to correct the editors. Instead, try to correct yourself. Remember - there is no dupe.
Extreme Programming - Redundant Array of Inexpensive Developers
-- In about 2003, Gonzalez and others found an unencrypted wireless access point at a BJ's Wholesale Club store. BJ's reported a breach of its computer networks in early 2004.
-- In 2004, other members of the ID theft ring compromised an OfficeMax wireless access point in Miami, and they were able to steal credit card data. After law enforcement officials in 2006 identified OfficeMax as the victim of a data breach, the company said it hired an outside auditor to conduct an investigation and found no evidence of a security breach. An OfficeMax spokesman didn't immediately return a message seeking comment.
So either the Secret Service was letting this go on just so they could make one bust, or they had no idea that their own informant was committing major breaches while under their supervision. Also, how stupid is this guy that he didn't even stop breaking the law after getting busted and becoming an informant? Some people are just begging to be sent to prison, and it looks like the prosecuters are going to grant his wish. For the rest of his life if they have their way.
P.S.: The Threat Level post with the info about him being an informant also contains a link to another case about another informant who was stealing social security numbers while working on a computer inside the Secret Service offices.
The usdoj.gov website seems to be down for me at the moment but should come back up eventually.
hacking ring responsible for stealing more than 40 million credit and debit card numbers from retail organizations in the US have been caught and charged.
To which they replied.. "put it on the card"
waiting for ad.doubleclick.net
This was in Wednesdays newspaper!
Kill some trees! Better than Slashdot!
He is just doing 'identity theft' of hackers.
Word to your mom.
She made the willows dance
The price for correcting the Editors is being moderated as a troll, apparently.
Don't fight for your country, if your country does not fight for you.
... or as Bill Gates mother would put it:
"Word to your mom?"
She made the willows dance
I mean, Heart was a bit of a stretch, but Hacking?
If I had a nickel for every time I had a nickel, I'd be richcursive!
ALL of this could be ended if visa and mastercard changed to single use CC numbers. if they gave me a token that created a new CC number with each transaction it might actually justify that annual fee the assholes charge me.
If you mod me down, I will become more powerful than you can imagine....
The NES version, or the Apple ][ version?
No matter where you go... there you are.
Maybe because you are ignorantly trying to say that because they are black hats they should not be called hackers. The term hacker can be appropriately used to describe anyone with above-average knowledge on a subject and a desire to explore and tinker, usually outside the confines of what is expected or desired. Maybe you can educate yourself a little better before complaining on slashdot, Try reading some Kevin Mitnick, Michal Zalewski, or if nothing else Wikipedia.
Trust me, linking to Eric S. Raymond's tiresome ramblings should never be necessary.
Shouldn't that be "boot to the head"?
I am officially gone from
Ceci n'est pas une dupe
My 0.02 cents
But they'll probably just end up going to club fed for 2 years
Shameless plug alert: Game server control panel
Is this something I can buy in World of Whorecraft?
(I hope this isn't about golf hackers...)
now that's just madness
I feel like I read this somewhere before. Oh, that's right, on Tuesday. I think it was plainly obvious that the 11 charged were in a hacking ring whether the verbage was included previously or not. Why don't we start tagging these as repeat news?
The people arrested were in several nations. What is unusual and a bit frightening is that it seems like they were able to get arrest warrants or whatever was needed crossing international lines really quickly. It almost seems like some uber government organization was at work on this affair.
You wouldn't think so from the summary. So much for the presumption of innocence.
hacking comes from german "hacken" which means to chop, so a hacker is actually a lumberjack (and is okay).
"It's such a fine line between stupid and clever" -- David St. Hubbins, Spinal Tap
This really is entirely for show politically. There are too many strategic positions up for grabs in November that just spoke volumes of "We need to look good"... Yea, I'm speaking to some republicans out there! You know who you are. Who's eyes are you trying to pull wool over??
Fact is there is too much of this out there and these guys are not the only fish out there.
All content in this message is copyright (c) 2008. All rights reserved. RIAA is prohibited here.
which they promptly paid by credit card.
there is no dupe.
There is new dope? Where?!
APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
You mean to tell me that the accepted definition in mainstream dictionaries is based upon the usage of the word in the mainstream media and the everyday vernacular? Inconceivable!
Apparently one-time use credit card numbers don't protect you either. I'd been wondering how a thief managed to charge something to my replacement credit card after I'd reported the old one stolen and had it canceled. If a merchant makes a manual (instead of electronic) claim with the credit card vendor, it will go through even if the credit card numbers are expired, the amount is over the limit, or you've been issued a card with new numbers. You can of course dispute the charge, but you have to spot the fraudulent charge first in order to dispute it. The only way to protect yourself from this type of fraud is to close the account, which is the same thing as not having a credit card.
n/t
Six score characters.
Brevity being wit's soul
I have enough space.
They just backdoored the reception system so they didn't just get the card numbers that were being used in that store, but in all of whatever chain of stores.
A month or so ago I heard of a bust of a team that had done a similar "backdoor the server" crack that got the card numbers and PINs of essentially everybody who had used the ATMs at 7-11 nationally for several months.
Does anybody know if that crime and this one are related (other than by compromising the server)?
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
Slightly offtopic, but the most recent word screw-up that's been bugging me:
vegetarian (http://dictionary.reference.com/browse/vegetarian)
1. a person who does not eat or does not believe in eating meat, fish, fowl, or, in some cases, any food derived from animals, as eggs or cheese, but subsists on vegetables, fruits, nuts, grain, etc.
pescetarian (http://dictionary.reference.com/browse/pescetarian)
1. a vegetarian who will eat fish
Defining a pescetarian as a vegetarian who eats fish is like defining a slut as a virgin who fucks.
My time machine must be broken. I think im listening to an argument from 1990....
-- http://www.criticalassets.com
Careful reading of the indictments show that the media, card issuers and Federal Trade Commission over-reacted to the TJX incident. TJX was not as bad as we were led to believe. --Ben http://legal-beagle.typepad.com/wrights_legal_beagle/2008/08/credit-card-iss.html
Benjamin Wright, Dallas, Texas, benjaminwright.us