Pages

Showing posts with label operation. Show all posts
Showing posts with label operation. Show all posts

Sep 27, 2012

TSA agent steals iPad, busted using Apple’s tracking software

Find My iPad

Despite the existence of GPS tracking applications for security, criminals still think they can get away with mobile devices.

Detailed extensively in an investigative sting operation conducted by ABC News, an Florida-based TSA agent named Andy Ramirez was caught with a iPad stolen from the security line at the Orlando International Airport. In an attempt to test the honesty of TSA agents at ten major airports around the United States, ABC News representatives “accidentally” left their iPad at the security checkpoint. Each iPad had a case that displayed the owner’s name and phone number. At nine of the ten airports, TSA agents correctly followed procedure and contacted the owner of the tablet. In addition, ABC News representatives tested sending checked bags containing cash and an iPad through security, but nothing was stolen from any suitcase at all ten airports.

Former TSA Agent RameriezRegarding the iPad that went missing, ABC News secretly filmed Ramirez handling the iPad at the security checkpoint. Two hours later, representatives used Apple’s Find My iPad application to track the location of the expensive tablet to Ramirez’s home.

Over two weeks later, ABC News sent reporter Brian Ross and a camera crew to Ramirez’s home. Catching Ramirez outside in his TSA uniform, Ross introduced himself and asked Ramirez about the missing iPad. Despite showing Ramirez the current GPS location of the iPad on another tablet, Ramirez denied that the iPad was located within his home.

Ross then used the Find My iPad sound feature that overrides the volume or silent setting on the tablet to activate a loud alarm. After hearing the tablet inside the home, Ramirez retrieved the iPad and blamed his wife for stealing the tablet. Ramirez said “My wife said she got the iPad and brought it home.” Ross disputed his claim by bringing up the footage taken at the security checkpoint, but Ramirez refused to answer any more questions and closed the door.

As of Wednesday afternoon, Ramirez was no longer employed by the Transportation Security Administration. Regarding the incident, a TSA representative stated that the organization has “a zero-tolerance policy for theft and terminates any employee who is determined to have stolen from a passenger.”

However, this isn’t the first time that a TSA agent has been busted for stealing electronics or other valuables from passenger luggage. In a similar case during February 2012, police at the Dallas-Fort Worth International Airport arrested 31-year-old Clayton Keith Dovel after using Find My iPad tracking to locate eight stolen iPads at Dovel’s home. Dovel was a TSA baggage inspector at the Dallas airport.

Also during February 2012, a 31-year-old, New York based TSA agent named Alexandra Schmid was arrested for stealing $5,000 in cash from a passenger’s jacket. After wrapping the cash within a plastic glove, Schmid was filmed taking the money into a bathroom to pass it off to an unknown person. Shortly after the incident Schmid was arrested for grand larceny. During July 2011, TSA agent Nelson Santiago-Serrano at another Florida airport was arrested after authorities discovered an iPad shoved into his pants. His arrest led to the discovery of $50,000 dollars of additional stolen electronics during his employment period with the TSA.


Source : digitaltrends[dot]com

Sep 4, 2012

Leaked: One million iOS device identifiers stolen from FBI laptop

hacker-keyboard

A file containing one million Apple UDID codes has been leaked, after it was allegedly stolen from an FBI agent's laptop earlier this year.

Operation AntiSec has made a return, this time leaking a file containing 1,000,001 unique device identifier numbers, or UDIDs, for Apple devices. The hackers are claiming that the data was stolen from a laptop belonging to the FBI, and that in total, it contained more than 12 million UDID numbers.

The file containing the data was accompanied by a longer than usual Pastebin post, which claims that in March, a Dell laptop belonging to “Supervisor Special Agent Christopher K. Stangl,” who works for the FBI’s Regional Cyber Action Team, was compromised using a Java vulnerability and a variety of files downloaded from it.

One was the above list of 12,367,232 UDID numbers, along with other personal data such as user names, Push Notification tokens, telephone numbers, address and the originating device.

According to the post, the personal data has been removed prior to uploading, but the UDID, notification token, device name and device type apparently remains. Forbes.com’s Andy Greenberg downloaded and decrypted the file, and found it contains a massive collection of 40-character strings, all of which could pass for Apple UDID codes.

Real UDID codes?

As you’d expect, the leak raises more questions than it answers. To whom do the UDID’s belong too, and why — presuming the information on the source is accurate — would the FBI have a single file listing 12 million of them.

While labeling its existence as proof of a conspiracy will be popular, there is an equally good chance the file is part of an investigation, or was supplied to the FBI quite innocently. There’s also the chance it didn’t come from the FBI at all, but from a developer. It’s also not the first time AntiSec has targeted Apple.

In its Pastebin text, Anonymous says that the “FBI is using your device info for a tracking people project or some sh*t,” and calls for UDID codes and similar device-identifying numbers to be “erradicated (sic) from any device on the market in the future.”

Apple’s use of UDID numbers has caused controversy in the past, with even Apple telling developers to stop tracking users using the codes. UDIDs themselves don’t carry personal data, but can be combined with other information to aid device tracking and monitoring.

Over at Hacker News, at least two contributors claim to have found UDID codes relating to their personal iOS devices. One lives in the USA and the other in the UK, but no common link between them or the apps they have installed has been established.

Interestingly, Cydia developer Jay Freeman (AKA Saurik) adds to the conversation, saying that 16.7-percent of the UDID’s in the file come from jailbroken iOS devices, according to his research.

FBI Agent

As for Special Agent Christopher Stangl, it appears he exists, which potentially adds some weight to Anonymous’ claims. There is a LinkedIn profile for someone under that name, who works for the FBI and has that job title; plus in 2009, FBI Agent Chris Stangl made a video for Cyber Security Awareness Week at NYU.

His name also appears on an FBI email list published on the Internet earlier this year, which led to hackers listening into a conference call discussing the activities of LulzSec and Anonymous. It’s speculated that these addresses were phished and led to a compromised website, where a Java vulnerability was exploited.

Anonymous has said it won’t be providing any further details, but hopes that due to the large amount of leaked information, “someone should care about it.” While we’re not expecting much from the FBI, it’ll be interesting to see if Apple provides a response.


Source : digitaltrends[dot]com