The FBI Can Now Legally Hack Everywhere Around the World
saintlad.com
saintlad.com
It seems rather nefarious, but there is Judicial oversight, meaning they need permission in each instance, which is at least one good thing.
But if a Russian hacker leaves Russia, or if a FBI hacker leaves the US, they can be prosecuted for those hacks. That's not what most people expect as the outcome of a "legal" action.
I think "government sanctioned" is the word we usually use for these cases, not "legal".
Of course they can't, FBI Hackers are likely liable to arrest and/or extradition if caught, while it's possible that the US might abrogate its extradition treaties in this case, suspects may find themselves arrested by 3rd countries the moment the leave US borders, or, depending on the country even tried in absentia
As for the FBI hacking outside their borders ...
Obviously, this is immediately problematic, no doubt.
But we live in a new, globalized world, and it includes not just social issues and business, but law enforcement.
A lot of pernicious crimes like sex-trafficking and child pornography etc. are very international in nature.
Ideally, we'd want authorities to work with one another, which is obviously the case in many ways ... but ... it's not always so easy. A lot of these regimes are totally corrupt, inefficient, have other priorities, or are politicized.
Remember that we are trying to achieve actual justice - and the rules are there to enable that - not the other way around.
I'm not exactly comfortable with what the FBI might be doing - that said, it depends a lot on what they are actually doing.
If the FBI hacks into the computers of some sex-traffickers in Burma, Ukraine, Belarus and is able to catch them ... then all the power to them. I think it's probably for the greater good, even if it does bend some rules.
Now if they start to go after political dissidents, and journalists, well, we have a problem :).
I'm not saying it's impossible, it would just be the first I'm hearing of it.
Just any international bank just about anywhere in the world with any US citizens as customers can tell you all about it.
Judicial review is likely now or soon to be a button in their hacking tools.
Where is this requirement located?
I asked this question in a thread here when the rules were proposed earlier this year, but received no replies because the topic was deleted as a duplicate. In the months since then, I've seen plenty of speculation in reporting on the issue, but nothing close to an answer to the question—so let me repeat it:
Do these new rules expand the claimed foreign jurisdiction of US federal courts, or not?
The amended rules provide new authorities for issuing warrants when "the district where the media or information is located has been concealed through technological means". In other words, the new rules seem to expand the authority of federal courts when there is a question of which district court has jurisdiction. But what do these new rules mean for cases in which the location of the information is clearly outside of the jurisdiction of any US federal district court, or when there is a question of whether it might be?
Apparently the rules were previously amended to remove the definition of "district court" [0], making this question still more subtle. Note also that the rules explicitly expand the jurisdiction of US federal courts to issue warrants "inside or outside" the geography of their districts in cases of terrorism, but not explicitly otherwise. I believe that rule has been interpreted to mean that federal courts may issue warrants worldwide, without regard to sovereign geography, in terrorist cases.
0. See the note pertaining to Rule 1(b) of the 2002 amendment, at https://www.law.cornell.edu/rules/frcrmp/rule_1
Microsoft's attempt to quash a warrant forcing it to turn over emails stored in Ireland seems relevant. The last I can find the Second Circuit ruled in Microsoft's favor.
This[0] article talks about the case it's effect on Rule 41.
[0]http://www.forbes.com/sites/insider/2016/08/02/the-microsoft...
How relevant is this question really, if we now know that they've been doing all this already for quite some time? What does it say about their need for legal rules?
[1] https://www.wired.com/2016/11/ross-ulbrichts-lawyers-point-a...
[2] https://en.wikipedia.org/wiki/John_Connolly_(FBI)
There is also more to the problem than corrupt individuals. Sometimes incorrect attitudes (racism, mistrust of whistleblowers, unjust patriotism) can result in organizations doing awful and immoral things even if single members are not publicly charged with a crime.
Or when an organization believes it knows better than the constitution (https://en.wikipedia.org/wiki/James_R._Clapper#False_testimo...)
As I see it, the illegal and immoral activities of individiuals within acronym agencies comes down to group think, tribalism, and a removal of separation of powers which this country was founded on. If a DEA agent does it, I think that increases the odds the FBI will do it.
So, yes, the distinction is substantive.
If one out of 5 acronym agencies is corrupt, that's a 20% corruption rate.
Now of course one incident doesn't prove a whole organization is bad. But it does show the processes used by that organization have insufficient oversight to prevent it.
Moreover, it's not simply one case. Yes, the comment brought up an isolated case, but there are many more known cases, and I'm curious how many unknown cases there are....
I feel like your arguments have been willfully oversimplifying and I question what your dog in this fight is.
I don't think that's really true. If for instance a FBI agent hacks into a computer located in Brazil and owned by a Brazilian citizen, he is still breaking Brazilian law, no matter what a USA judge says.
(B) the premises—no matter who owns them—of a United States diplomatic or consular mission in a foreign state, including any appurtenant building, part of a building, or land used for the mission's purposes; or
(C) a residence and any appurtenant land owned or leased by the United States and used by United States personnel assigned to a United States diplomatic or consular mission in a foreign state.
So it says clearly "owned, leased, used by... US diplomatic or consular mission in a foreign state". Not that any laws have prevented the FBI/NSA from doing any of this already.
Apparently, citizens of other countries should not be worried (with this particular law). Could anyone with more knowledge in this area double check this?
From: https://motherboard.vice.com/read/us-judges-can-now-sign-glo...
Astroturf much?
EDIT: For the downvoters, its like trusting peta for a neutral stance on animal welfare on a farm.
Nor is the EFF's position reasonable - suppose you want to search a computer in an unknown jurisdiction, where the location of the computer has been obscured by Tor. What's the alternative to allowing magistrate judges to issue warrants outside of their jurisdictions? Requiring warrants for every jurisdiction that the target computer might be within?
The thing is, technology alone will not be enough as a protection. We need a sane legal framework. They have a virtually unlimited budget (our taxes) that they can use against us and they will always find new ways to carry out their mass surveillance.
If we allow our governments to take our money to make us puppets, then we're pretty much f#cked until the next big revolution (in whatever form that will have to be).
Instead of having to deal with it we have to face it an confront, fight and destroy authoritarian laws as much as we can.
> The officer executing the warrant must give a copy of the warrant and a receipt for the property taken to the person from whom, or from whose premises, the property was taken or leave a copy of the warrant and receipt at the place where the officer took the property.
The post-change version appends another sentence to that:
> For a warrant to use remote access to search electronic storage media and seize or copy electronically stored information, the officer must make reasonable efforts to serve a copy of the warrant on the person whose property was searched or whose information was seized or copied. Service may be accomplished by any means, including electronic means, reasonably calculated to reach that person.
But the theory does not make enough sense in that such a government would want to disclose their mass surveillance program only when absolutely no resistance is possible anymore, which is currently not the case yet.
Even if we don't all end up in dystopian bubbles that have some legal tie back to the U.S., the focus should be around proper architecture, defense in depth, plausible deniability by design, etc. If you are not required to keep logs, then don't. If you are, encrypt them with half of a key. You get half of the key and your customers get half of the key. Yes, logs per tenant. This is getting _somewhat_ easier to do these days. Design decentralized or partially centralized systems that permit delegation of control over encryption of data so that lawful intercept is less useful and so that hacking a thing is less effective both technically and legally. I.e. encrypted data-stores that you and your customers can partake in the legal custody of the data. Once you receive the NSL, you won't be able to talk about it and warrant canaries may not always be feasible either, so design your systems with that in mind.
If you code products that folks will use to protect their families freedom and/or way of life, then please consider the attack vectors and generalize your way out of them and/or create really easy to read docs that people can take away action items from and implement.
I only mention this because HN is full of intelligent creative thinkers, engineers, architects and highly experienced attorneys. Hopefully a few doc/tech writers too!
...now back to my really bad coffee.
Also, though I agree adding technical security is a MUST, what happens when the FBI hacks your computer directly to record the logs itself? Or backdoors your OS? Or even makes a law making TOR or the fundamental technologies of self protection into "hacker tools that subvert government's rightful knowledge?"
In my experience there just aren't enough people that care to actually do anything more than debate issues. Debate is a great way to think through problems and try to get the facts. Until these facts cost businesses a lot of money or put excessive burden on the courts, I just don't see this changing is all I am saying. If anything, this helps feed the self feeding system, so there just isn't any incentive for those in power to change deviate from business as usual.
In a morbid sense, I am actually curious to see how this plays out. They (the feds) may be opening a can of worms that is bigger than they imagine, as this may have other potentially complex legal ramifications that folks just didn't really think through.
The huge difference is that when FBI breaks into your house you always know it.
> when FBI breaks into your house you always know it
That's not true. In January 2014, the bureau obtained a court-issued “sneak and peek” warrant,
allowing agents to secretly search Raphel’s northwest Washington home while
she was away.
The FBI sent a special Evidence Response Team trained in surreptitious
searches. Raphel’s home had an alarm system, which the FBI team bypassed.
http://www.wsj.com/articles/the-last-diplomat-1480695454The FBI now even hacks thousands of computers in hundreds of other countries. Still make sense?
EDIT - Here you go:
"The FBI ended up hacking some 8,700 computers in 120 countries."
From: https://motherboard.vice.com/read/us-judges-can-now-sign-glo...
It seems even the president isn't fully aware of whats going on.
"This Constitution, and the Laws of the United States which shall be made in Pursuance thereof; and all Treaties made, or which shall be made, under the Authority of the United States, shall be the supreme Law of the Land; and the Judges in every State shall be bound thereby, any Thing in the Constitution or Laws of any State to the Contrary notwithstanding.
The Senators and Representatives before mentioned, and the Members of the several State Legislatures, and all executive and judicial Officers, both of the United States and of the several States, shall be bound by Oath or Affirmation, to support this Constitution; but no religious Test shall ever be required as a Qualification to any Office or public Trust under the United States."
Therefor, being that such a warrant system is in violation of the fourth amendment (they key here, for those naively claiming this isn't such a big deal, is the interpretation by the executive that such warrants give them the power to hack thousands of computers without description of their location, their probable cause, and the person that owns them):
"The right of the people to be secure in their persons, houses, papers, and effects,[a] against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."
The FBI and every congress-scumbag who passed this, or blocked the delays, is very close to being in violation of their oath, technically and in spirit. Now, for congress they must sign an affidavit that (5 U.S.C. 3333) will not violate their oath while in office, the punishment of which (18 U.S.C. 1918) is removal from office and confinement or a fine, but the criteria is hard to pin down legally.
(5 U.S. Code § 7311) "An individual may not accept or hold a position in the Government of the United States or the government of the District of Columbia if he— (1) advocates the overthrow of our constitutional form of government; (2) is a member of an organization that he knows advocates the overthrow of our constitutional form of government; (3) participates in a strike, or asserts the right to strike, against the Government of the United States"
My question is, are the executive officers also supposed to sign that affadavit? If so, that's a starting point, but if not, what punishment is there, what legal recourse, to get rid of people in the executive or judicial who are pushing or acquiescing to blatantly unconstitutional expansions of power?
Bonus question: does the third amendment apply here as well, since they are putting their own malware in our houses?
"No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law."
Information distribution on the web is broken. Where's the startup to fix that?
Well, the answer is research and discussion.
Why do people here seem so worried that the government is lying to them about their powers and can't be trusted?
because: https://en.wikipedia.org/wiki/James_R._Clapper#False_testimo...
because: Edward Snowden, who revealed illegal government activity. The government reacted by instead of admitting it was wrong, turning him into a criminal. Worse, all kinds of pseudo-news (TV, radio, internet, even NPR!) bought into this dialog that he's "Helping Russia." The fact is that he's in Russia because the US canceled his passport when he was on his way to South America.
Just because people are scared and emotional doesn't mean they're wrong (e.g. Germany in the 1930s). If you think the conclusions people are coming to are invalid, try to question in a respectful way instead of labeling.
Right, because companies whose founders' sole goal is to get a big payout and move on is going to fix journalism/news/information distribution.