<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cyberthieves Using Bluetooth To Steal Gas Station Credit Card Data</title>
	<atom:link href="http://storefrontbacktalk.com/securityfraud/cyberthieves-using-bluetooth-to-steal-gas-station-credit-card-data/feed/" rel="self" type="application/rss+xml" />
	<link>http://storefrontbacktalk.com/securityfraud/cyberthieves-using-bluetooth-to-steal-gas-station-credit-card-data/</link>
	<description>Techniques, Tools and Tirades about Retail Technology and E-Commerce</description>
	<lastBuildDate>Sun, 20 May 2012 01:49:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Todd Michaud</title>
		<link>http://storefrontbacktalk.com/securityfraud/cyberthieves-using-bluetooth-to-steal-gas-station-credit-card-data/comment-page-1/#comment-67844</link>
		<dc:creator>Todd Michaud</dc:creator>
		<pubDate>Thu, 04 Mar 2010 17:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4906#comment-67844</guid>
		<description>My question is, how did the thieves manage to implement the system in the first place?  That sounds like quite an elaborate install.  Did these locations run outdoor cameras at night?

I would also agree that if this elaborate of a setup was created, I find it highly unlikely there would not be some type of localized storage on the device.  It seems foolish for there not to be one.

It seems interesting that the police investigating this have not used an opportunity to go &quot;fishing for the theives&quot; by taking out one of these devices and setting up one that is still transmitting, just bogus data.  I&#039;m not a bluetooth expert, but there is a pairing process that happens, I would think that they could at least see if the device was paired (and when) and glean some information that way.</description>
		<content:encoded><![CDATA[<p>My question is, how did the thieves manage to implement the system in the first place?  That sounds like quite an elaborate install.  Did these locations run outdoor cameras at night?</p>
<p>I would also agree that if this elaborate of a setup was created, I find it highly unlikely there would not be some type of localized storage on the device.  It seems foolish for there not to be one.</p>
<p>It seems interesting that the police investigating this have not used an opportunity to go &#8220;fishing for the theives&#8221; by taking out one of these devices and setting up one that is still transmitting, just bogus data.  I&#8217;m not a bluetooth expert, but there is a pairing process that happens, I would think that they could at least see if the device was paired (and when) and glean some information that way.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Evan Schuman</title>
		<link>http://storefrontbacktalk.com/securityfraud/cyberthieves-using-bluetooth-to-steal-gas-station-credit-card-data/comment-page-1/#comment-67841</link>
		<dc:creator>Evan Schuman</dc:creator>
		<pubDate>Thu, 04 Mar 2010 17:14:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4906#comment-67841</guid>
		<description>The story also pointed out that a cell connection is dangerous because it can point to the thieves, while Bluetooth, in theory, wouldn&#039;t.</description>
		<content:encoded><![CDATA[<p>The story also pointed out that a cell connection is dangerous because it can point to the thieves, while Bluetooth, in theory, wouldn&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Terry Hare</title>
		<link>http://storefrontbacktalk.com/securityfraud/cyberthieves-using-bluetooth-to-steal-gas-station-credit-card-data/comment-page-1/#comment-67836</link>
		<dc:creator>Terry Hare</dc:creator>
		<pubDate>Thu, 04 Mar 2010 15:44:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.storefrontbacktalk.com/?p=4906#comment-67836</guid>
		<description>Accoding to the story, the thieves need to be very close to the pump to read the data, but I believe that with a throw-away wireless phone collecting and relaying the data, basically just a little more technology, they could collect the card numbers and pins from anywhere in the world.

This sounds like too much effort, expense and project management skills for a common criminal, this is likely a small group, probably with someone inside one of the companies that make, deliver or service the pumps.

What is scarey is that this technology can translate to other card readers and if the perpetrators add local storage, the problem is even harder to uncover as they could drive up once a week purchase gas and download the data.  If they managed to get access to other POS terminals this could be a bigger problem, just walk through with a smart phone and collect the data...

The publicly known better surveillance will likely keep this technology from ATM&#039;s and cash drawer termnals, but who knows with criminals?

The technological answer is to put a specrum analyser at the locations to monitor all wireless signals to see if there is a device translating the data an pushing it to another network.

If I had a C-store, I would have my pumps checked out by a third party to protect my customers, this could be a much bigger problem if it came from the pump distribution chain.</description>
		<content:encoded><![CDATA[<p>Accoding to the story, the thieves need to be very close to the pump to read the data, but I believe that with a throw-away wireless phone collecting and relaying the data, basically just a little more technology, they could collect the card numbers and pins from anywhere in the world.</p>
<p>This sounds like too much effort, expense and project management skills for a common criminal, this is likely a small group, probably with someone inside one of the companies that make, deliver or service the pumps.</p>
<p>What is scarey is that this technology can translate to other card readers and if the perpetrators add local storage, the problem is even harder to uncover as they could drive up once a week purchase gas and download the data.  If they managed to get access to other POS terminals this could be a bigger problem, just walk through with a smart phone and collect the data&#8230;</p>
<p>The publicly known better surveillance will likely keep this technology from ATM&#8217;s and cash drawer termnals, but who knows with criminals?</p>
<p>The technological answer is to put a specrum analyser at the locations to monitor all wireless signals to see if there is a device translating the data an pushing it to another network.</p>
<p>If I had a C-store, I would have my pumps checked out by a third party to protect my customers, this could be a much bigger problem if it came from the pump distribution chain.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

