Hacking Ring Nabbed By US Authorities
Slatterz writes "The members of a hacking ring responsible for stealing more than 40 million credit and debit card numbers from retail organizations in the US have been caught and charged. The case before the US Department of Justice is believed to be the largest hacking and identity theft case ever prosecuted. The criminals allegedly obtained bank details by hacking into the retailers' computer networks and then installing 'sniffer' programs to capture card numbers and password details as the customers moved through the retailers' credit and debit processing networks."
are security measures going to be changed with this revelation to the public? having seen the inner-workings of various bank and investment facilities, i can safely say that one doesn't need to go through any really complicated work to take financial information from consumers: most wiring closets aren't even locked.
If you felt a little cheated by the lack of info in the 'article' the DOJ site has more.
OMG facts!
hacking (uncountable)
...4b: to gain access to a computer illegally
1. (computing) Unauthorized attempts to bypass the security mechanisms of an information system or network.
Hack
You may prefer to use other definitions yourself, but the usage here is perfectly correct.
Links to the indictments of the top two suspects:
suspect 1
suspect 2
You can bet hackers didn't write those definitions. Those definitions are accurate in the context of mainstream media, but as the GP stated, this is /.
What's the value of information that you don't know?
http://news.bbc.co.uk/2/hi/business/7545212.stm has a much better write-up.
So now we will get even MORE draconian measures to stop the "evil hackers" when in reality, it was a combination of bad intentions, and old-fashioned stupidity. The article specifically mentions looking for "vulnerable" access points. This means that whoever set the network up for these stores did not do a proper job in securing said network. Also, why the HELL were the systems used to process credit card transactions on the same insecure wireless network? There is NO excuse for that. I'm not excusing what these guys did, but once again we have a case where whoever setup the hardware in these places needs to be held for criminal negligence.
"So after all this, you make my case for me. To end this stalemate, you must die..."
kick to the chest
Provided that this is still the /. that we all know, this should not be necessary, but one may never be sure about the level of truth...
There used to be a time when you read tech-news first on slashdot. Nowadays I read it in my (Dutch) newspaper first (yep, the paper one that they actually have to print and deliver first) end a few days later it appears in /.
What the hell is wrong?
Well if you can record the call (and phone boxes aren't hard to tap, though I'm not sure how exactly it would work at a call center) then it's easy to convert the DTMF tones into numbers using a tone decoder.
Here's a link to a DIY hardware version: http://www.bobblick.com/techref/projects/tonedec/tonedec.html And a quick search should turn up software solutions, or you could write one yourself since the tones are standard. Wiki lists all the tones: http://en.wikipedia.org/wiki/DTMF#Keypad
;-)
Dear hackers,
You can't own a word. Get over it.
So, who foots the bill for this? The retailer, the credit card comany / debit card issuer, or the customer?
-- In about 2003, Gonzalez and others found an unencrypted wireless access point at a BJ's Wholesale Club store. BJ's reported a breach of its computer networks in early 2004.
-- In 2004, other members of the ID theft ring compromised an OfficeMax wireless access point in Miami, and they were able to steal credit card data. After law enforcement officials in 2006 identified OfficeMax as the victim of a data breach, the company said it hired an outside auditor to conduct an investigation and found no evidence of a security breach. An OfficeMax spokesman didn't immediately return a message seeking comment.
So either the Secret Service was letting this go on just so they could make one bust, or they had no idea that their own informant was committing major breaches while under their supervision. Also, how stupid is this guy that he didn't even stop breaking the law after getting busted and becoming an informant? Some people are just begging to be sent to prison, and it looks like the prosecuters are going to grant his wish. For the rest of his life if they have their way.
P.S.: The Threat Level post with the info about him being an informant also contains a link to another case about another informant who was stealing social security numbers while working on a computer inside the Secret Service offices.
The usdoj.gov website seems to be down for me at the moment but should come back up eventually.
hacking ring responsible for stealing more than 40 million credit and debit card numbers from retail organizations in the US have been caught and charged.
To which they replied.. "put it on the card"
waiting for ad.doubleclick.net
He is just doing 'identity theft' of hackers.
The price for correcting the Editors is being moderated as a troll, apparently.
Don't fight for your country, if your country does not fight for you.
This was in Wednesdays newspaper!
It was also in Tuesday's /.
ALL of this could be ended if visa and mastercard changed to single use CC numbers. if they gave me a token that created a new CC number with each transaction it might actually justify that annual fee the assholes charge me.
If you mod me down, I will become more powerful than you can imagine....
Maybe because you are ignorantly trying to say that because they are black hats they should not be called hackers. The term hacker can be appropriately used to describe anyone with above-average knowledge on a subject and a desire to explore and tinker, usually outside the confines of what is expected or desired. Maybe you can educate yourself a little better before complaining on slashdot, Try reading some Kevin Mitnick, Michal Zalewski, or if nothing else Wikipedia.
But they'll probably just end up going to club fed for 2 years
Shameless plug alert: Game server control panel
The people arrested were in several nations. What is unusual and a bit frightening is that it seems like they were able to get arrest warrants or whatever was needed crossing international lines really quickly. It almost seems like some uber government organization was at work on this affair.
which they promptly paid by credit card.