Live data from Hacker News

How London thieves exploit organisational silos

medium.com

41–50 of 53 posts

Re: How London thieves exploit organisational silos

#41
This reminds me of a card skimmer I found on an ATM about 12 years ago (unfortunately, after I had used it to withdraw cash). I basically lucked into finding the camera hole and managed to rip the fake cover + video camera + transmitter from the frame of the ATM. With that in hand (unfortunately I dis not think to also take out the card reader itself), I called the police. While I was on the phone with them, a foreign couple tried to use the ATM. I told them not to, they pretended not to understand, I went back to my phone call with the police. When I turned around, the card reader was gone: that nice couple was the thieves, they were somewhere near (to catch the video footage of people entering their PIN) and swooped in to retrieve the card reader and the data stored in it.

The police squad that came around was fairly decent, but they didn’t really seem to be on the lookout for this type of crime; one of the cops confessed that he’d used the same ATM the night before and was genuinely impressed that I’d spotted it. Spending a couple of hours in the police station to give my statement (rather than going to the restaurant as initially planned) sucked, of course. I was shocked at how bad I was at describing the thieves, even though I’d seen them and talked to them.

Following up with the bank was similarly frustrating; the bank director told me he personally checked the ATM at opening and closing time, meaning the thieves installed and removed the card reader every night. I never found out if the other victims were made aware of the fact that their card details were stolen.

So, yes, thieves are brazen and smart; police are nice (sometimes) but helpless or just don’t care about these types of crime; and even though I did all I could to mitigate the situation, I still felt a bit shitty and helpless about the whole experience.

Re: How London thieves exploit organisational silos

#42
post #3

Earlier quoted context omitted.

>find out which phones pinged the phone tower near each of the locations at each of the relevant times I don't know that that is actually possible. The police can access the records for any one number, but accessing all the records for a set of towers in a given time window is a different matter. I would actually love to know if this is within their capabilities.

It totally is within the capability of telcos. It's a database query away. Whether the police can get a warrant for it is a different matter. I'm not au fait with the details of RIPA post the EU decision [1][2] but it is safe to say the barriers are not that high. Meta data (like cell tower signal strength) is almost certainly available. Towers log everything, and location is a valued derived product. [1] https://www…

That's just it. There's already a frontend for the police to use that gives them access to all the data for a single phone number, sans warrant. Does that same frontend allow them to perform arbitrary queries across the entire dataset?. If not, then pursuing this lead would involve filling out forms and writing letters to telcos, possibly even obtaining warrants (unlike the usual process), and they probably wouldn't bother.

Incidentally, the ability to perform unrestricted arbitrary queries without a warrant across the entire phone-location dataset is a fairly horrifying amount of power for the police to have. But I suppose legally that ship has sailed with RIPA, and now it's just a question of the fine details of the implementation.

Re: How London thieves exploit organisational silos

#43
post #30

One of the morals of the story is to never leave your wallet out of sight or out of feel when you’re in public spaces. Leaving your wallet in a back-pack and the back-pack in a corner of a restaurant/pub is asking for big trouble. In the very few cases when I have to leave my wallet unattended (like in a backpack at the side of a basketball court) I previously leave my bank cards and ID at home, I only bring some cas…

Especially somewhere as central and busy as KX. Scottish Stores is an ok pub but fuck off would I let my bag leave my sight in there.

Re: How London thieves exploit organisational silos

#44
post #20

Nicely written article and I am sorry for what happened. Similar thing happened to a friend of mine some years ago and since then I don’t dare take my bag out during evenings. Re The Met - it’s a sad state of affairs with policing in the UK. It comes down to the following: police only ‘care’ to investigate or deal with 3 types of criminals: 1. Terrorists 2. Paedophiles 3. Speeding motorists If you wish to do any othe…

They have been pretty good for domestic violence issues and assault when I've needed them, though.

Re: How London thieves exploit organisational silos

#45
post #3

Earlier quoted context omitted.

>find out which phones pinged the phone tower near each of the locations at each of the relevant times I don't know that that is actually possible. The police can access the records for any one number, but accessing all the records for a set of towers in a given time window is a different matter. I would actually love to know if this is within their capabilities.

It totally is within the capability of telcos. It's a database query away. Whether the police can get a warrant for it is a different matter. I'm not au fait with the details of RIPA post the EU decision [1][2] but it is safe to say the barriers are not that high. Meta data (like cell tower signal strength) is almost certainly available. Towers log everything, and location is a valued derived product. [1] https://www…

You will never be able to justify the collateral intrusion that getting all the connections to a single cell site would represent.

If you don't know who you're looking for then it isn't actually that much help in any case.

Assuming you know that the suspect phone will have pinged a given cell site, then you still have to work out which phone it was. Assuming that they're not daft enough to use anything other than an unregistered PAYG sim, then you're left hoping that the IMEI of their handset has come to police attention.

If you had the resources, you could get the top-up data for all the unregistered sims attached to that cell site and hope there's CCTV at a given newsagent or that they've used their own bank account to top up online.

Re: How London thieves exploit organisational silos

#46
post #42

Earlier quoted context omitted.

It totally is within the capability of telcos. It's a database query away. Whether the police can get a warrant for it is a different matter. I'm not au fait with the details of RIPA post the EU decision [1][2] but it is safe to say the barriers are not that high. Meta data (like cell tower signal strength) is almost certainly available. Towers log everything, and location is a valued derived product. [1] https://www…

That's just it. There's already a frontend for the police to use that gives them access to all the data for a single phone number, sans warrant. Does that same frontend allow them to perform arbitrary queries across the entire dataset?. If not, then pursuing this lead would involve filling out forms and writing letters to telcos, possibly even obtaining warrants (unlike the usual process), and they probably wouldn't…

No.

Getting a request approved is a nightmare. It's literally easier to get a search warrant from the courts than it is persuading police SPOCs to approve your RIPA request.

The gatekeeping is fearsome. They take their duties incredibly seriously.

Re: How London thieves exploit organisational silos

#47
post #46
post #42

Earlier quoted context omitted.

That's just it. There's already a frontend for the police to use that gives them access to all the data for a single phone number, sans warrant. Does that same frontend allow them to perform arbitrary queries across the entire dataset?. If not, then pursuing this lead would involve filling out forms and writing letters to telcos, possibly even obtaining warrants (unlike the usual process), and they probably wouldn't…

No. Getting a request approved is a nightmare. It's literally easier to get a search warrant from the courts than it is persuading police SPOCs to approve your RIPA request. The gatekeeping is fearsome. They take their duties incredibly seriously.

I'm not quite sure what your 'no' is specifically in reference to. I'm also not sure what a SPOC is, and I'm not familiar with the details of the process.

But The Guardian reported in 2014 that "EE, Vodafone and Three give police mobile call records at click of a mouse", and in 2015 that "UK police requests to access phone calls or emails are granted 93% of the time", with rejection rates varying wildly by county from as high as 28% to as low as 0.1%. So it doesn't seem to be as hard as you're making out, unless things have changed wildly in the last few years. May I ask your sources?

https://www.theguardian.com/world/2014/oct/10/automatic-poli...

https://www.theguardian.com/world/2015/jun/01/police-request...

Re: How London thieves exploit organisational silos

#48
post #45

Earlier quoted context omitted.

It totally is within the capability of telcos. It's a database query away. Whether the police can get a warrant for it is a different matter. I'm not au fait with the details of RIPA post the EU decision [1][2] but it is safe to say the barriers are not that high. Meta data (like cell tower signal strength) is almost certainly available. Towers log everything, and location is a valued derived product. [1] https://www…

You will never be able to justify the collateral intrusion that getting all the connections to a single cell site would represent. If you don't know who you're looking for then it isn't actually that much help in any case. Assuming you know that the suspect phone will have pinged a given cell site, then you still have to work out which phone it was. Assuming that they're not daft enough to use anything other than an…

I'm not sure if you read the links? The UK doesn't have the same requirements as the US. They don't have a collateral intrusion limitation.

Once you have the IMEI of interest you can find everywhere it has been and every number dialled, and all DNS requests and IP transfers. You just need a dialled number which has a plan attached and you can look up the phone book entry from that persons phone (though police would need a warrant for that).

The only thing preventing the Met from finding this thief is a lack of person time.

Re: How London thieves exploit organisational silos

#49
post #47
post #46

Earlier quoted context omitted.

No. Getting a request approved is a nightmare. It's literally easier to get a search warrant from the courts than it is persuading police SPOCs to approve your RIPA request. The gatekeeping is fearsome. They take their duties incredibly seriously.

I'm not quite sure what your 'no' is specifically in reference to. I'm also not sure what a SPOC is, and I'm not familiar with the details of the process. But The Guardian reported in 2014 that "EE, Vodafone and Three give police mobile call records at click of a mouse", and in 2015 that "UK police requests to access phone calls or emails are granted 93% of the time", with rejection rates varying wildly by county fro…

SPOC = single point of contact

The filtering isn't about civil liberties (although keeping councils out seems sensible) but rate limiting requests via paperwork, so only important ones get done.

Re: How London thieves exploit organisational silos

#50
post #47
post #46

Earlier quoted context omitted.

No. Getting a request approved is a nightmare. It's literally easier to get a search warrant from the courts than it is persuading police SPOCs to approve your RIPA request. The gatekeeping is fearsome. They take their duties incredibly seriously.

I'm not quite sure what your 'no' is specifically in reference to. I'm also not sure what a SPOC is, and I'm not familiar with the details of the process. But The Guardian reported in 2014 that "EE, Vodafone and Three give police mobile call records at click of a mouse", and in 2015 that "UK police requests to access phone calls or emails are granted 93% of the time", with rejection rates varying wildly by county fro…

I'm a police officer who routinely uses communications data in investigations.
Post reply on HN