Multimillion-dollar L.A. heist was seamless, sophisticated, stealthy
latimes.com
latimes.com
Wi-Fi conveniently enables x-ray vision (IEEE 802.11bf) through walls of home, making it easier for attackers to identify where valuables are stored, observe password keystrokes, etc. Any room with a safe should have EMF shielding.
https://www.cnn.com/2024/04/05/us/burglary-tourists-visa-wai...
> Prosecutors say the break-in is part of a larger issue in which so-called “burglary tourists” enter the United States .. they join sophisticated burglary rings that prey on luxury homes.. “They take advantage of the fact that most people don’t have window sensors or motion detectors on their second floors. They have WiFi jammers to stop the alarm company from being notified.. the stolen goods are often sold quickly and the money is sent back to the suspect’s home country. Most often, that’s Chile.
Most large sites put their cameras on segregated networks, so it might not even be obvious to folks for a while.
Or an NVR deployment could use 802.1BR to isolate all the cameras.
I’m a firm believer in endpoint security — endpoints should not need to trust the network for authentication or authorization when communicating with each other. But the network really ought to be able to do its job despite attacks by rogue endpoints or someone compromising a single piece of network infrastructure, and the network’s job is to maintain reliable connectivity.
I've spent a lot of time handling support for big camera deploys and I was surprised by the number of customers who would bring their systems down by misconfiguring their own networks.
It's called Ethernet for a reason. You fling packets into the ether and hope they come out the other end. What happens in the ether is anyone's guess.
A friend did this - he hid the DVR in a space under his steps then took a cheap dead DVR, gutted it and shoved an RPi in to run Firefox and the DVR web UI. Even set it up in with a monitor and mouse on top. He left the old HDD in there for weight too.
One thing to think about though, he had a NAS box in his office next to the router on a table and I said, what if they take that thinking its the DVR? That is now under the steps too.
> Any room with a safe should have EMF shielding.
You just made the target that much more visible.
Given that wires can also be cut, is that worth it given the extra cost to install?
A better solution might be for alarm to be triggered if traffic from cameras is lost (although that would create a lot of false triggers)
Proper camera deployment includes redundancy in camera viewpoints. If you're cutting a camera's cable, I'm seeing you cut it from at least one other camera on property.
First off if the wires can be reached the installation is a failure. My cameras are up high with all wiring well out of reach or in metal conduit. Getting near the wiring also means theives get closer to cameras setting of motion sensing algos wasting time and risk making a racket trying to climb up to disable them.
Wifi is useful for many things - just not anything security related.
Shouldn't the NVR have real time offsite backups and/or a redundant NVR instead of a decoy?
First, decoy recorders are extremely rare, and never really recommended. Most higher-end systems are using software on a PC for the video recording, not a little NVR appliance anyway. In that case your recorder can be any random PC, potentially even hidden in plain sight.
Real time offsite backups is usually not practical for reasons of upstream bandwidth limitations. A common camera can easily produce a bitstream of 2+Mbps. Get a dozen of those going, and you're bumping up against the upstream bandwidth limit of cable internet providers in the US. If you have the bandwidth for realtime offsite backups, then you can skip the on-site NVR/recorder and go with a full cloud solution like Eagle Eye (this will have a small onsite PC that acts as a buffer so that if you have a short outage of a few hours, or congestion, you don't lose video).
Either way, in the city I live in most residences have 1gb up/down fiber connections. a real time offsite back up is trivial for anyone who wants to do that here.
Internet connections have certainly become more robust in recent years, and cloud video storage is becoming more common, but I don't think it even makes up 1% of the market at this point. Offsite backups, remote storage, etc. are still the exception, not the rule.
Overall, the video surveillance market has many price sensitive customers. Redundancy means increased costs, it is not an easy sell, particularly when attacks on the video surveillance system/components are exceptionally rare in most cases.
During this, it will become apparent that this was an inside job, and the attackers had knowledge of the system, and thus most common hardening or mitigation procedures would be less effective against an informed attacker. Because of that, the feeling of a need to install the most robust systems with offsite backups will drop to near zero.
The article doesn't even state that the video system was in fact disabled, or that they were using wifi cameras at all. Obviously, the police are not disclosing many details, it is possible that they have video from the robbery and are simply not saying it.
Is always smart - use unique bright yellow (say) CAT cable to route from cameras to local storage .. and on the last leg route the real camera data to a hidden NVR behind a good false panel and "continue on" with fake yellow CAT to a decoy NVR in plain view.
It's a good feeling when robbers have visually followed the bright cables to the decoy storage and trashed the drives that don't have the idiots faces and other data stored in HiRes.
security by bamboozlement
That's why matching cable from cameras [ ... disappears, reappears ... ] and into visible on office desk sacrifical anode NAS box works. They don't trace the cabling, they make assumptions based on matching colour. The 'trick' is to make sure the camera display screens cut out if the "fake" NAS goes down .. best to route to screen through sacrifical secondary storage.
> That is a scenario that only happens in the movies.
Here, in my part of the world, it's used by several contracters I'm aware of, in homes, shops, warehouses .. fake drives near camera display screens get destroyed in break ins more often than you realise - and more frequently in recent years.
Even in the US the Afroman raids show the police about to rip drives out of the security system .. if there'd been a decoy box | real time cloud backup there'd be more footage of the raid for his songs and court case.
If you feel that you have a legitimate threat that might lead to attackers trying to disable your video system you would more commonly install better equipment. Cameras that are more covert, or are ruggedized/vandal proof, and installed out of reach. Installations that leave no exposed cables, PC-based video recorders that don't have branding or indications of what they are doing, etc.
I think bigger problem is people that think they can do that in first place still being employed in police...
https://www.rapiscan-ase.com/products/mobile/zbv-cargo-and-v...
Tito, René, Lee Kwan Yew, Park Chung Hee. Only two countries remain true to its art form.
If you spend any time talking to law enforcement, the conversation inevitably goes to how dumb most criminals are. It is the position of law enforcement of course that criminals are only those who they apprehend. It is completely beyond the ability of them to understand that their could exist an entire sphere which they have no insight into at all.
This is not a stealthy crime. It is not seamless and has only a meager level of sophistication. This has been all over the news for a while now. If it was anything of those things, we would never even know it had happened.
This is because most criminals are actually incredibly dumb. Deal with them and you'll see it, too.
That said, some of them are pretty bright. Just like all of humanity, there are a spectrum of abilities found in the carceral population. However, they trend towards the lower end of the range of possibilities when it comes to innate intelligence.
> It is the position of law enforcement of course that criminals are only those who they apprehend. It is completely beyond the ability of them to understand that their could exist an entire sphere which they have no insight into at all.
I spend a lot of time talking to law enforcement as part of my day job, and my experience is nothing like yours. I would encourage you to expand your horizons (or not, whatever).
https://en.wikipedia.org/wiki/Hatton_Garden_safe_deposit_bur...
It makes the entire thing far more seamless, and gives you a better window to get away with it.
At least in the UK, it's one of the few times that there are a guaranteed 4 days of closures, given that Christmas can fall on different days of the week each year.
In the UK both Christmas and the following day (Boxing day) are public holidays and the holidays will move to the next working days if they fall on the weekend. So this is the other time of year that can have 4 consecutive days of public holidays/closures.
> Gardaworld describes itself as a “global champion in security services,
Oh, the irony!
How do these work? (I made this account to ask this)
The advantage is that it works on the protocol level, so you don't have to nuke the entire spectrum for the entire neighbourhood (which would attract attention)
Why do phones/laptops continually broadcast a list of all SSIDs they have ever connected?
https://blog.spacehuhn.com/probe-request
https://www.theatlantic.com/technology/archive/2016/08/wi-fi...
I'll see your conspiratorial bent and raise you: why is iPXE enabled by default?
It's not really "secure" in the academic sense of the word, but many devices record the BSSID along with the SSID to be a little more safe from hijacking.
It's trivial to spoof the BSSID if you're an attacker since it's something that's just advertised wirelessly.
maybe a form of planned obsolescence to sell routers with WPA3 support
intelligence agencies plugging agents into standards bodies is also not unheard of
Malicious clients/APs need much less energy to DoS a network Wi-Fi network. WPA3 adds optional PMF (802.11w) to protect against rogue deauth over WPA2. Also, not deploying 802.11r but deploying WPA-3 only mode and device/user cert-based 802.1x auth also help.
Sure, but compliant Wifi devices use miniscule transmit power. If you're a criminal you can easily hook up a car battery/generator to a 1000 W transmitter and cover a pretty wide area, or use a directional antenna to focus it a bit more on your target. These sorts of jammers definitely exist, too. Downside though is you're also lighting a huge beacon that says "HELLO I AM DOING SOMETHING ILLEGAL", so you will not be able to keep it up forever. Protocol-based attacks are more discrete, but newer APs (especially enterprise) have countermeasures.
I dunno how legit they are but a Google search finds examples claiming a 20 W jammer can cover 500 meters. I'm skeptical that's accurate but it's probably within an order of magnitude. Enough to cover a house, and a large transmitter would plausibly be able to block out a larger facility.
Adding a couple of thoughts I had while reading it:
- If the criminals' jamming only needs to protect their identity when people look at footage in the future (as opposed to taking offline a large facility's entire network of cameras so that security can't tell where the criminals are in real time) then they could potentially carry the jammer with them, in which case it just needs to be strong enough to block any camera within sight rather than the full building
- In addition to scaling the power of a jammer to take out a big enough area, they could place multiple jammers around the location, either to combine to a larger area or to expand on your directional antenna idea to target individual networked items (cameras, routers, whatever). Even if having many of them means there isn't time to collect them all again when leaving, assuming the crime's pay-off is significant then it could easily still be cost-effective to consider them single use jammers (I'm assuming it wouldn't be hard for people smart enough to plan this sort of crime to make sure that the left-behind jammers can't be traced back to them as an easy solve for the police).
Ideally a well-designed camera would buffer locally when its WiFi path is down. But there's always limits there and I suppose if the criminal started the jamming a bit before entering line of sight, it should work. Then again I suppose most security cameras probably don't buffer at all or just barely enough to smooth out a network hiccup.
Jammers also aren't super expensive and don't need to be supervised, it's entirely possible a thief could just leave a big one in a trash can or something and then abandon it.
All that said though I don't think this is a credible threat against anywhere with minimum legitimate security. Everything should be hardwired and battery backed up in any reasonable security system. It's mostly a thing that would effect cheap residential systems.
What you can't do is operate a business and fill the lobby for example with jammers that wipe out cell phone service and then require people to pay for access via WiFi.
My guess would be that A is legal and B might not be, but I've never had reason to look up the relevant laws and I don't know if it would be the same in different countries either.
But yeah, I doubt most purchases of portable jammers are for legal use.
a) I've never been quite sure. People do testing in Faraday cages so there has to be some exception. I'm pretty sure as long as you aren't interfering externally and are being responsible nobody is gonna fine you.
- HN Guidelines (https://news.ycombinator.com/newsguidelines.html)
Or if you're going to post a shallow dismissal, at least say something interesting about why you're dismissing, unlike your comment which literally adds nothing to the conversation and doesn't educate anyone who doesn't already know what led you to your opinion.
* But I'm not god, nor am I perfection personified, you're very welcome to disagree with my opinion. (Though to be completely honest I am a bit surprised that two people replied disagreeing with me, I'd expected my view that the comment didn't belong on this site wouldn't be controversial, so maybe my judgement is off in this case. But I've not been convinced to change my mind.)
* Unless you ripoff rich or powerful people like Madoff or SBF. If your quant shops causes global financial chaos on a diffuse and global level, it's okay to use financialization trickery like LTCM.
Sure, buddy.
A few thousand last minute tables “sold” at Coachella side parties will do the same
LA / Socal has so many things and a big enough spread out enough economy to wash any amount
Can use a design studio “by appointment only” with some phantom customers and phantom projects the studio is paid for
I could keep going.
who put my email in my bio, that’s weird
Take your first example: the music festival promoter shows up at his bank with a duffel bag of cash -- that's not unusual until suddenly every single missing serial number lights up the bank's cash handling systems.
Busted.
It's possible to launder marked cash, but it has to be in such small quantities that it's always plausible that it was simply spent in circulation, which in practice dramatically limits the speed with which it can be laundered.
Probably the single most straightforward approach to dispose of marked bills would be to swap for unmarked cash with someone who doesn't care, like an overseas drug lord. But man, good luck with that.
Many armchair money launderers on HN cooking up unrealistic schemes..
There’s a reason real money launderers charge up to 50 cents on the dollar. It’s f** difficult.
It turns into a fascinating business and process problem, since you can only inject a certain percentage of dirty money into a legitimate cash revenue stream. And this in turn means - even if you had infinite dirty income, you end up with a finite amount of money you can launder per month. And marked bills make this a lot harder. And if attention comes to the business it becomes harder.
And that in fact has happened in reality. Some cartels were earning so much dirty money that they couldn't launder it all. And in fact, just storage of the dirty cash became a real logistical issue. And to be honest, "storage of large amounts of illegal cash" hasn't been a problem on my radar so far.
> While the involvement of Chinese money-laundering rings in handling drug proceeds from Mexico is nothing new, a number of recent court cases in the United States have revealed crucial information about how these schemes work ... weekly pick-ups from representatives of Mexican criminal groups, made in cash ranging between $150,000 and $1 million, with an average of $500,000. These were made in large cities including Chicago, New York and Atlanta ... network of Chinese-owned businesses in the United States and Mexico ... transfer a correspondent amount of money through Chinese banking apps. This happened entirely through the Asian country’s domestic banking system ... “It’s the most sophisticated form of money laundering that’s ever existed,” one of the US sources told Reuters.
Jane picks up 500K in cash in Chicago and then transfers 450K from her business in China, to Joe's business in China. Joe then transfers 400K from his US account to Juan's account in the US.
Is that how it works ?
It relies on everyone having other money already aside from the illicit funds
I find any US crime show that places the IRS above FBI, DEA etc in terms of fear factor is generally a better one.
It does actually work exactly that way all the time. On the larger end, major drug traffickers routinely move millions in cash to Mexico and elsewhere with little trouble.
On the smaller end, many lesser criminals and groups also do the same in creative ways. 20 million in cash is a lot, physically, but nowhere near enough to be really hard to move overseas through smuggling in several largish, carefully concealed shipments, especially if you can use a small part of that same money to pay for all kinds of object shipping arrangements.
I wonder what's the difference between the IRS and their French and Italian equivalent. For what I've experienced in both those countries, the easier path would be paying a percentage of the heist to whoever is making those checks.
I have no sense of scale for any of the things in this topic, my reaction to this is "only 50 cents?" because that would still leave these thieves with 15 million USD, which is significantly more than most Americans earn in their lifetimes.
If you get caught with over $10,000 undeclared at any US border or at the corresponding border, it gets seized
If you declare it, it gets seized.
The Mexicans usually don’t bother.
And in both cases, most remote crossings are unmonitored.
I don’t think financial institutions care as much as you’re assuming, and there are alot of types of organizations that count as institutions - where the whole anti money laundering regime relies on trusting that the other institution vetted the money - but assuming they do care, it means avoiding them in alot of ways
I still think reintegration can be done with just cash payment, and cash investment into a revenue producing business. But what you’re saying does rely on the recipient also not depositing into a bank for some time until there are enough other dollars intermingled too. What’s “enough”?
There are workarounds even for that, such as shipping the money overseas and using it in places that love US dollars but don't much care for cash transaction reporting rules.
However, I doubt any group as apparently pro as these guys, who seem to have known exactly what to hit and when for a ton of money, would have done so without first also verifying that the serial numbers weren't recorded. I'd bet that they werent, at least not yet.
Considering how ‘cost efficient’ they were being on security, hard to imagine they were maintaining detailed databases of each serial number for this cash. These are the same folks that bitch and whine over $.25/hr raises for their employees.
There are machines for this. Garda absolutely has them.
They just didn’t have them installed here for whatever insane reason.
I don’t think they would be but I’m trying to play along and work around that too
and trying to stay under $10k is illegal structuring too, if flagged
There is still a trail with that method.
there are gaps in the AML/KYC framework but I don’t think this a good one
2 edits: wash isn't really the right word because you still can't prove where you got it. Secondly, you'd potentially be showing yourself on video so that's a significant risk.
The software is specifically designed to track people between cameras, to be able to point to a person and 'rewind' their movements, to be able to say "which people played these three slots between 10pm and 11pm", etc.
Hell, you could find the lowest volatility game such as video poker that has a 99.5% hold and play it for a calculated amount to converge to the mean as quickly as possible. It's not like cheating where they are going to be running after you as soon as you put in funny money.
Until you're suspected of laundering.
All I'm saying is that as soon as the Secret Service comes knocking (although maybe they only deal with counterfeiting, but [insert any federal agency]) with a suspicion that you, or that money, are involved, the casinos will fall over themselves to assist. They're not going to risk threats to their licenses.
> Don't drive in with a vehicle tied to you, wear a hat or basic disguse
You say this like casinos don't also employ systems, and people who are trained to look for hustlers, con artists, cheats who might be using disguises to enter.
You're right, though, absent any suspicion of you, they won't be looking for you.
It's very easy for banks to tell what merchants have had skimmers installed. Three or four fraud reports that all have a common merchant, and you're off and running, by seven or eight you can isolate pretty much any merchant.
But this also the fallacy of superiority, and "the intelligence of criminals". "Hah, stupid criminals, basic opsec, and you're fine." Were you carrying a cell phone? What's your gait as you walk look like? Etc., etc. "Oh, they won't go to that length"... for thirty million dollars cash stolen? They absolutely will. "Gait analysis is pseudoscience"? Maybe. Do you think that will stop efforts at parallel construction?
> Hell, you could find the lowest volatility game such as video poker that has a 99.5% hold and play it for a calculated amount to converge to the mean as quickly as possible. It's not like cheating where they are going to be running after you as soon as you put in funny money.
This would stand out like a red flag as soon as you did it a few times. Because who goes from video poker machine to video poker machine (even at different casinos - and many of the casinos can and do track and work with each other on surveillance to watch people moving between them) just to "play for a calculated amount to converge on the mean" and then cash out? No, they're not running after you, but when the po-po come knocking, you'll be wearing a neon sign above your head.
You would need a lot of planning and coordination on how it's spent and where it's spent to make it look legit. And have enough untainted income to live while you plan on how to spend the tainted stuff.
[1]: https://www.latimes.com/california/newsletter/2022-01-05/dun...
"Despite the daring robbery, what ended up solving it was not that exciting: An informant identified Hill as the person who rented a 14-foot U-Haul truck a day before the heist and had returned it a day later."
If I were the cops I'd check Google maps records to see who was looking at the satellite view of the area before the heist.
And it's not really that surprising imo. If you need to pay translators, contractors, bribe local officials or collaborators, assets, etc in a country that doesn't have a functioning banking system you need cash. And it's quicker to deliver some pallets with a C-130 and have guys dump it into duffel bags for whatever they need then to ask Congress nicely to set up bank transfers.
Even the USG says $6B+ was probably stolen.
https://www.wnycstudios.org/podcasts/takeaway/segments/14047...
Well it just did.
The cops weren’t armed well enough because ‘nobody robs a bank in body armor and fully automatic weapons’. Until they did, of course.
Interestingly, HEAT came out 2 years prior.
Underwriters Lab conducts the test and provides certification to the safe manufacturers. It also helps determine the maximum insured value you can get out of a particular safe. Their process is essentially white hat safe Crackers evaluate products. Pretty neat stuff.