Wardrivers Target Seattle Businesses 138
angry tapir writes "Seattle police are investigating a group of criminals who they say have been cruising around town in a black Mercedes stealing credit card data by tapping into wireless networks belonging to area businesses. The group has been at it for about five years, according to an affidavit signed by Detective Chris Hansen, a fraud investigator with the Seattle Police Department."
Comment removed (Score:3, Insightful)
Re: (Score:3)
Easier said than done. My neighbor has Windows7, and I tried to get her laptop to connect to her cable companies provided access point using WPA/WPA2 and it simply would not work. It would only work using WEP.
Seems to be a common problem....
http://answers.microsoft.com/en-us/windows/forum/windows_7-networking/windows-7-wireless-network-problem-windows-7-fails/ce399590-1c0d-482e-bc7e-bd4016e154b2 [microsoft.com]
Re: (Score:2)
Re: (Score:2)
Old or cheap, pick one.
Re: (Score:2)
Re: (Score:1)
It's worse than leaving your door unlocked. It's more like leaving your door unlocked and putting a sign out front in blinking lights telling everyone it's unlocked. (Broadcasting.)
Re: (Score:2)
Or watching porn on your TV with no curtains...you are showing it to all...
Re: (Score:2)
Re: (Score:1)
Re: (Score:3)
The fun is sharing the CEO's pr0n stash with the entire company.
Re: (Score:3)
But what do you do when he does it himself?
I once worked for a boss whose porn collection (and we're talking about spank-til-he-bleeds gay BDSM porn) was available on a public file share. How I knew it was his? Guess who was the guy without a mask...
I tried to be discreet about it, approached him, informed him that his rather private info is on the fileshare and promptly got asked whether I like them an invitation to his next party.
It was rather surreal. But then, the whole company was a bit like the role m
Re: (Score:2)
If you leave your car door unlocked, and it is stolen, the insurance company won't pay up for damage when the car is recovered. If there is no sign of forced entry on your house when it is robbed, same thing. In both cases you will have to fight with your insurance company to get them to pay out, as it appears that you allowed the robbery in both cases.
Hi, I'm Chris Hansen from Dateline NBC. (Score:3)
Re: (Score:2)
Seattle Police - Priorities Are Not Job One (Score:2)
It's important to catch guys with laptops in a Mercedes, than gangbangers, murderers, or those guys who drive around in vans offering little girls candy.
Did someone in the Department find a $20 charge on his credit card, or is this just a simple case of "We serve nobody and protect nobody, but if you're using a laptop and an antenna in receipt of lawful radio signals, WE WILL FIND YOU!"?
I have done lots of wardriving. I can't afford a Mercedes tho. Does this put me halfway between the van-driving child-mo
Re: (Score:2, Redundant)
Re: (Score:1)
ICD10-V-F60.2 or maybe F60.8
Re: (Score:1)
ICD10-V-F60.2 or maybe F60.8
George Lucas, is that you?
Re: (Score:1)
I was going to call it benjfowler, 239527.
thank God the internet isn't a human, right?.
Re:Seattle Police - Priorities Are Not Job One (Score:4, Insightful)
I hope you get lots of dollars, but wardriving is NOT a criminal activity. It's not a misdemeanor either. It's not against the law.
Receiving openly broadcast radio signals is one of our rights in the United States. While driving is a privilege, combining these does not make it a criminal activity.
I'm not trying to "justify" one event (not a crime) by comparing it to pedophiles (or paedophiles if you prefer an archaic and no longer correct spelling). There's no real comparison between NON-unlawful reception of open radio signals and molesting children. (Note: not all pedophiles molest children. I specifically referred to molesters because THAT IS criminal activity.
Best regards to you,
E
Re:Seattle Police - Priorities Are Not Job One (Score:4, Insightful)
Re:Seattle Police - Priorities Are Not Job One (Score:5, Insightful)
Using someone else's credit card is criminal. Doesn't matter if they use a megaphone and tell the whole world what it is
While yes using someone else's credit card fraudulently is criminal, I wouldn't say the megaphone bit doesn't matter.
Screaming out their customers credit cards of course does NOT excuse the wardrivers crime in any way shape or form. But the separate act of sending all of their customers credit card information to the world should also be a crime as well.
At the very least I wish the police would post a list of these companies, so the general public knows they can not be trusted with our business.
At most, the companies should be brought up on charges of mishandling customer credit accounts and fraud.
They will just need to schedule that court case for a different day than the wardrivers court date, so everyone can attend.
Re: (Score:2)
Re:Seattle Police - Priorities Are Not Job One (Score:5, Insightful)
These guys were wardriving + the police are after them = cops are after them because they were wardriving
Which is stupid. The cops are after these guys for misusing the information they obtained, not because they were wardriving. If they had been wardriving, and simply retained the information for their own use the cops never could have found them and never would have needed to. Quite frankly his posts are aggressive and irrational, and I was trying to explain to him why the cops are actually after these guys. From the first sentence in the summary:
stealing credit card data
And if you RTFA you learn that the owner of the Mercedes was only discovered after he was busted performing other forms of fraud.
Re: (Score:2)
All I saw in the article was the police saying stolen gift card (not a credit card number) + wardriving setup in his car = he is stealing credit cards. I see no mention of any other evidence here. If the police had evidence that he was in fact stealing credit card numbers he would be in jail. It is pretty obvious that there is no other evidence since they were asking for permission to seize the car, something that would have been done already if they could obtain a warrant.
Re:Seattle Police - Priorities Are Not Job One (Score:4, Insightful)
Did you even bother to read the summary? I get that this is /. and nobody RTFAs, but the summary was pretty clear that this wasn't just a case of wardriving, this was a case of wardriving until they found an unencrypted wifi connection and rummaging for credit card details. The details were then abused.
Trust me, they wouldn't be wasting the money on that around here if it were just stealing a bit of bandwidth.
Re: (Score:2)
Read the article, the police are trying to say that because he has a wardriving setup in the car that he is stealing credit card numbers. They offer no evidence to support their claim.
Re: (Score:2)
While driving is a privilege, combining these does not make it a criminal activity.
Driving is not a privilege. It is a right, under the broad umbrella of the right to travel freely.
If you want to compare it to something that is inarguably a right due to being explicitly enshrined in the Bill of Rights, look at guns.
You need a license to own a gun.
That license can be revoked as a criminal penalty.
Driving is pretty much the same.
Re:Seattle Police - Priorities Are Not Job One (Score:4)
Since when? Around here you don't need a license to own a firearm. In fact if you're a woman capable of claiming to be stalked, you can even get a handgun the same day.
Re: (Score:2)
I'm not a woman (nor do I play one on the Internet), I have never been -- nor have I ever claimed to have been -- stalked, but I was able to buy a handgun in a couple of hours recently.
Re: (Score:3)
Since when? Around here you don't need a license to own a firearm.
Plenty of states do require you to have a license to own a firearm but yes, technically it is up to the individual state's laws. Just like requiring a driver's license is also technically up to the individual state's laws.
Re: (Score:2)
Plenty of states do require you to have a license to own a firearm.
Name one.
Re: (Score:3)
Massachusetts [wikimedia.org].
Re: (Score:2)
Those should be going away soon since the US Supreme Court has ruled that the second amendment does in fact guarantee that individuals have the right to own a firearm. Lots of the draconian firearms laws will be going away in the next 10 years thanks to that ruling.
Re: (Score:2)
Most places you don't need a license to own a car or to drive it on private property. Requiring that you know how to drive (for using public roads) or use a firearm is quite reasonable. I've almost been killed by bad drivers and I've had too many bullets go by my head to think that any person should just be handed a dangerous tool without them having some knowledge about the tool.
Guns and automobiles have one thing in common, a bit of stupidity can kill innocent bystanders very easily.
Re: (Score:3)
I never understood why did something become a privileged just because the state says it is. Rights can be limited or revoked if you break society's laws.
Re: (Score:2)
If driving is a right, and the ADA says you can't restrict rights based on a disability, why are the blind prevented from driving? Wouldn't the blind need to cause a few crashes (each) before their license could be revoked?
Re: (Score:1)
Paedophile was never a correct spelling. Pædophile might have been, though.
Re: (Score:3)
Driving is not a "privilege". The state cannot revoke your license because the governor or one of his officers just feels like it. It can only be taken under due process of law. That is the difference between a right and a privilege. Privileges can be revoked by the executive (doing what they feel like, not following any legislation.)
"The Right of the Citizen to travel upon the public highways and to transport his property thereon, either by horse drawn carriage or by automobile
Re: (Score:1)
A license is permission to do what would otherwise be illegal. If something really is a right, you don't need a license to do it, if you need a license to do it, it's not a right. Also the fact is that these licenses can be revoked by administrative rather than court procedures in certain situations. (Refusing a Breathalyzer test for instance)
Also a lot of statutes read, whoever operates a motor vehicle on the highways of this state whose privilege to do so has been revoked, shall by guilty of... (Most s
Re: (Score:2)
Then how can states make radar detectors illegal?
Re: (Score:1)
an archaic and no longer correct spelling
I always find it amusing to see US linguistic pedantry - from a country where people call a liquid 'gas'
Re: (Score:3)
I hope you get lots of dollars, but wardriving is NOT a criminal activity. It's not a misdemeanor either. It's not against the law.
Receiving openly broadcast radio signals is one of our rights in the United States. While driving is a privilege, combining these does not make it a criminal activity.
Did you read TFA, numbnutz? Breaking someone else's encryption, even if it's as lame as WEP, is a crime.
Re:Seattle Police - Priorities Are Not Job One (Score:5, Interesting)
It was a 1988 Mercedes. The laptop and antenna might have cost more than the car.
Re: (Score:3)
Well, according to the Seattle PI, they are accused of stealing more than $750,000 In computer equipment and other items. So no, these guys did just a little bit more than a $20 charge on some dudes card.
Re: (Score:2)
I, for one, am glad that the Seattle PD is finally going after actual criminals instead of beating the shit out of teenage girls [youtube.com] and punching jaywalkers [youtube.com].
To answer your question, you should fear going to Seattle only if you're a teenage girl. The Seattle cops aren't racist, they just prefer to beat on people who can't defend themselves.
Re: (Score:2)
Just out of curiosity, how do you think a reasonable police officer should handle being assaulted? That woman in the second video is damn lucky she was only punched, the officer could very easily have hit her with pepper spray or shot her under those circumstances.
Re: (Score:2)
Cop had his hand around the neck of the first one when the video started, choking her. That's unreasonable force for someone that was not seriously resisting.
In Canada, if you're arrested illegally, you have the right to resist arrest. So says the Supreme Court.
If a cop tried some shit like this with me for jaywalking, of all things, I would not go peacefully. And if they ever, for any reason, put their hand on my neck like this cop did to the first girl, they'd find some parts of their body mysteriously
Re: (Score:1)
You can kick the shit out of a cop? way to go.
Can you kick the shit out of 6 cops? Cuz that is what round two is going to be.
Better to hold your temper while they are in control of your immediate destiny, remember names, remember faces and unload on them legally, after the fact if you feel compelled.
Re: (Score:2)
Better to hold your temper while they are in control of your immediate destiny, remember names, remember faces and unload on them legally, after the fact if you feel compelled.
Actually, that's exactly what I'm going to be doing, soon. There wasn't any violence involved in my contact with police abuse, but there were at least 6 of them in the first round. It's still ongoing, which is why I'm not going into any more detail, but suffice it to say, they'll regret it eventually...
Re: (Score:2)
I think a reasonable police officer should respond with reasonable force. A seventeen year old girl grabbing the wrist of a trained adult man does not warrant a full-on punch to the face.
And where's your defense of the first video? That girl, only fifteen years old, kicked her shoe off in the direction of the cop -- with an amount of force that a 90 year old cancer patient could shrug off -- and how does he respond? Throws her head first into a wall, grabs her by the hair and yanks her backwards onto the
Re: (Score:2)
I see, so you're an expert on this? On what basis do you assert that it's not reasonable? The review on that incident has been completed and the conclusion was that he was well within both his rights and his training. The girl he hit apologized for assaulting him and has since been sentenced. Can't recall what the terms of it.
As for the second one, that's a straw man argument, it's got precisely nothing to do with anything I said. I never said that officers never abuse their power or make mistakes. I also n
Re: (Score:2)
What the hell do you mean, am I an expert in this? Since when do you need a PhD in knowing that beating up little girls isn't okay?
The reviews of incidents like this are a joke. The cop gets a two week paid vacation while his buddies from work get to decide that, "nah, that bitch was asking for it". Meanwhile, they plant evidence or make up lies to charge the victim with some crime. The victim, desperate to get their life back and by now fully aware of just how corrupt the cops are, gives up and begs fo
Re: (Score:1)
Sorry ,if officer O'Ryan has any testosterone at all he can handle a "female" suspect on his own or face ridicule in the locker room.
Even sister-boy pork is expected to be able to handle basic stuff like a man. I can see some whiney low impact professions using any tech or method to make things easier, but there is an image to protect.
But if that were my daughter in the first video, brat or not, both those officers would fall under deer rifle crosshairs in
Re: (Score:1)
Well if being reasonable means letting corruption by those "meant" to protect the public go to proliferate as acceptable, in turn putting in danger every man, woman and child and falsely calling it ethics then you can join all the ethical dinosaurs and others with no will to survival for yourself or your progeny.
This T-rex, who belives gays have the right to take themselves out of the gene pool while making a spectacle of themselves, will protect himself and his own to the death...candyass.
No gays,trolls,et
Re: (Score:2)
hmm. fuck. "disturbing" isn't the correct word for it (even disturbing is the though that this was way, way more common when cameras were not placed almost everywhere...)
even more disturbing is the small amount of publicity any abuse of power actually gets.
Re: (Score:2)
Oh how I love answers like "Why do they prosecute $some_crime while there are still people doing $much_worse_crime at large?"
The reason is simple: Crimes are not solved serially. You might notice that they are also hunting murderers and gangbangers. It's not like the whole police department dropped everything they were doing, released suspects of murder crimes and are single mindedly hunting down wardrivers now.
What would you suggest? Let's ignore "minor" crimes for now 'til we got all the murderers, rapist
Re: (Score:1)
It's a crime because they're using these credit card numbers to purchase things. It's a crime because, even though WEP is not that secure, it's still basic security. It's a crime because they're accessing data that they should not be accessing.
They're not more important than the criminals you mention, they're not less important. They're criminals, period. Do you also think stopping murderers is more important than catching people who break into homes and steal things?
I'd like to see you come home to a ransa
Re: (Score:1)
It's a bizarre little group of armchair anarchists we have around here.
You know... (Score:1)
If my coworkers and I shared your finacial information by tossing paper planes to one another, you'd think us nuts. Replace paper with electromagnetic waves and all is well.
Re:You know... (Score:4, Informative)
Tossing paper planes would probably be fairly secure.
1)data would remain within your line of sight so any attempt to directly intercept would be obvious
2)with correct folding data could be hidden making remote interception impossible
3)It's not standard enough for no one to have developed a standard attack
Feed 'em false numbers (Score:5, Interesting)
It would be easy to set up a weakly protect access point that did nothing but generate bogus transactions with bad credit card numbers - that could pollute the crook's database, particularly if they don't do a good job of recording of which card number came from which network.
And if the bogus numbers were timestamped and logged then when the bad card numbers are used (and bounced) one could use the bounced transactions to build a map of where the crooks were on any given day.
Re:Feed 'em false numbers (Score:5, Insightful)
Re: (Score:1)
That would require the cops to actually use a computer. or understand how to works
/. doesn't require understand how edits, why cops should understand how to works?
Re: (Score:1)
It would be easy to set up a weakly protect access point that did nothing but generate bogus transactions with bad credit card numbers - that could pollute the crook's database, particularly if they don't do a good job of recording of which card number came from which network.
They could do that, yes, but I would hope that these war drivers understand that nearly all credit card numbers are generated according to the Luhn check. They would run those bad credit card numbers through an algorithm that returns a boolean value denoting whether the credit card is valid or not. If not, they would simply send it to the bit bucket in the sky.
No surprise (Score:5, Interesting)
We discovered that the company below us a few years back (here in Seattle) had not only an open wifi but also had all of their drives shared. We immediately went down stairs and warned them after one of us accidentally connected to their wifi and saw a whole bunch of computers (with official sounding names even) pop up in the file explorer.
Their reaction? "Whatever." They never put a password on it. I was actually surprised by their disinterest in locking down when alerted. Even after we told them that people could just drive by and steal all their company records... so stupid.
Re:No surprise (Score:5, Funny)
Let me guess. It was these guys [facebook.com].
Re: (Score:2)
Re:No surprise (Score:5, Interesting)
That is unfortunately a very common reaction. I don't understand how people could not care either.
Another unfortunately common reaction is, after trying to be nice and warn them about the problem, once someone else actually does exploit the problem, they likely will come back to blame you :/
I do hope for your sake that doesn't happen, but I've had it happen to me before, and was shocked at the multiple layers of stupid their line of thinking was.
These days I don't even bother unless I already know the person. Being accused of a serious crime for only trying to help just isn't worth the chance.
Re:No surprise (Score:5, Interesting)
A company I used to work for was next door to a lawyer and all her drives showed up on our phones using Bluetooth (it was annoying when trying to reconnect your headset because you had to scroll past her 7 drives).
I told her about it and she didn't care! I told her that anyone could read her clients' confidential documents. She told me that she would sue them...<facepalm>
Re: (Score:1)
SMBs should stand up and take notice (Score:1)
Wireless Security is no longer an academic problem; as we can see from the article, it's now going beyond miscreants merely stealing access/internet bandwidth, or possibly pirating/illegal activities using the internet connection.
This goes to more serious crimes that more severely impact the operator of the network connected to the wireless AP.
SMBs can no longer safely dismiss wireless security with excuses such as "only a real expert hacker could break in anyways; there's no harm anyone's actually goi
Re:SMBs should stand up and take notice (Score:5, Funny)
With money to be made breaching networks, practitioners of one of the oldest professions in the world, will be learning to breach insecure WiFi networks
Hookers are taking hacking classes now? Finally some slashdotters are going to meet some women!
Re: (Score:2)
Wireless Security is no longer an academic problem; as we can see from the article
The medium may have changed, but the principles remain the same.
Re: (Score:2)
Re: (Score:2)
"Supposed to" and "are" are two different words.
Besides, it doesn't have to be PCI compliant if it's not customer data. They could be sniffing employees shopping on the web.
Re: (Score:2)
Re: (Score:2)
They could be sniffing employees shopping on the web.
Unlikely. When was the last time you saw a web store that didn't use SSL for submitting the credit card information (or a merchant bank that will do business with a company that doesn't)? If the site uses SSL, then a passive eavesdropper can't intercept the data, they need to perform some kind of MITM attack.
And this is why securing the access point is largely irrelevant. You should be treating the network as insecure, whether it's wired, wireless with WPA2, or carrier pigeons. Encryption should be en
Re: (Score:2)
The banks aren't where people get screwed on PCI compliance, it's the credit card companies. As part of your merchant agreement with them you agree to secure your network to PCI standards AND agree to potential audits by them. You're also supposed to get a quarterly PCI-compliance audit if you have an externally-facing IP address open.
Securing wireless connections is PART of compliance. Check out more detail here:
http://www.pcicomplianceguide.org/pcifaqs.php [pcicomplianceguide.org]
Great (Score:2)
Re: (Score:1)
Now people are going to think that Wardriving is synonymous with stealing credit card numbers, when it's just the act of finding wi-fi from a car.
I think Google has found that what you say is true.
They've faced a barrage of legal hassles for their "war-driving" whilst collecting Street View images. And it's never been shown, that I'm aware of, that they did anything remotely unethical with the data collected.
In fact, they even refused to release the collected info to governments due to "privacy reasons", if I recall correctly.
Wow, that's insanely silly (Score:2)
"a group of criminals who they say have been cruising around town in a black Mercedes stealing credit card data by tapping into wireless networks belonging to area businesses."
If the criminals hadn't been wandering around blabbing about their exploits and saying it for everyone to hear then maybe the police wouldn't have even noticed them.
Re: (Score:3)
Apparently it took five years of screaming at the top of their lungs for the police to notice them. Seattle apparently has rather more Lestrades' than Holmes'.
Criminal negligience (Score:4, Interesting)
Firstly, let's be clear, I want the people stealing the information caught, and locked up. They are criminals.
The business should be fined though if they did nothing to protect their information. This is like leaving a toddler at home alone all day (though not to the same degree.)
Re: (Score:2)
They should be facing private-sector penalties. They're answerable to their banks for compliance with the Payment Card Industry Data Security Standard, under their merchant account contract. The standard emphatically does not permit sending card numbers over open wireless networks.
Stealing information (Score:2)
I want the people stealing the information caught, and locked up. They are criminals.
If the suspects were actually breaking into the business and removing papers from filing cabinets, you could call that "stealing information". What's actually occurring is that these businesses are broadcasting their information in an insecure manner. In a free country, how can it be a crime to pick up on that information?
Now, if they then use that information to commit fraud, that's where the true crime is taking place.
Mix-a-lot (Score:1)
Benzo? check.
Tinted windows? check.
One member of the gang, Larry, an allegedly-funny 'white guy' and 'real estate investor' has struggled in recent years to make payments on his many properties.
I predict the Benzo is an SEL, a 190 or an SEC, and that a search of the Benzo will reveal traces of buttermilk biscuits.
If only we had listened... (Score:3)
Detective Chris Hansen (Score:2)
Black Mercedes? (Score:1)
The real world (Score:2)
"I have a virus on my system popping up stuff all the time and blocking my internet" is a case of calling a technician in.
"I want you to audit my network for security" is a question they wouldn't even know how to ask and whether or not they should ask, and they really wouldn't know
End-to-end encryption? (Score:1)
Re: (Score:1)
Black Mercedes (Score:2)
should be outlawed!
Indeed: (Score:2)
I only wardrive in a grey Ford.