Dutch secret service tries to recruit Tor-admin
burojansen.nl
burojansen.nl
On a side note, it's always worth pointing out, especially in Europe, that direct attitribution to a service making a pitch is never so sure. Many countries make pitches pretending to be other (usually local) services. For example the US and Israelis are often aware that Europeans often take personal political stances against their government policies so they will impersonate a local service like AVID. People have spent years not realising what service or country they are really working for.
Imagine someone's surprise when they get arrested. They thought they were doing their country a service and it turns out they were actually aiding the enemy...
If this stuff is true, I need to start weighing digital rights a lot more in my politics.
https://www.privacybarometer.nl/maatregel/37/Bewaarplicht_te...
Gives information on the telecom metadata retention directive: 12 months for telephony, 6 months for all Internet traffic.
Note: "In addition to this retention directive, all communication providers are required to submit a daily copy of their entire customer base to the DOJ, including name, address, phone number, email and assigned IP".
https://www.privacybarometer.nl/maatregel/45/Kentekenregistr...
About the recent addition that traffic cameras may be used to record and store all license plates passing the camera. This data is accessible to enforcement agencies without warrant.
https://www.privacynieuws.nl/internet-en-telecom/bewaarplich...
- news aggregator for various privacy issues
But when it comes to more invasive measures like internet censorship [1], or requiring suspects to give over encryption keys (else potentially put them in jail if they refuse) [2] or simply the way you are treated at an airport. The UK is much, much worse.
[1]: https://en.wikipedia.org/wiki/Internet_censorship_in_the_Uni...
[2]: https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
1) All ISPs are supposed to delete all logs of customers within 6 months.
2) All websites that deposit a cookie on your machine are required by law to require user consent before doing so (which is why so many American websites become a bit different when browsing them from the Netherlands -- all those popups requesting consent).
While I know the Dutch basically invented the wire tap decades ago, and I have no reason to believe they don't have an advanced spy mechanism in their government, your claims seem to go much further than reason, and feel a bit tabloid to me. You need to provide some concrete evidence about this.
There are license plate scanners in lots of places. The total number of taps is mostly undisclosed. The police routinely tap conversations between suspects and lawyers. Those are supposed to be deleted but sometimes end up in a file anyhow.
There are limits on what the police can do, but by and large there are only very vague limits on what intelligence agencies can collect.
So it is safest to assume that all information that is collected in digital form is available to the government in one way or another and only occasionally are there enough protests that some data is not used anymore (such the tax office using information related to parking)
Note, the government has no problem restricting what companies can do with data as long as gets what it needs.
> If you work with us there are benefits, for example if we ask you to crash a system in a public place and you would be arrested for that, we make sure you don’t get arrested and nobody will know about it, not even the police
"If you do us a favor, there's the amazing perk that you might not even go to jail for it!"
This means the individual has a) compromised themselves and now cannot feel "clean" in this previous environment and b) are starting to get used to/spend the new perk/cash so pretty soon they can't live without it. The power relationship then swings more towards a needs based one. Suddenly the handler(s) are the only people who really know the truth about how the informant truly is. Also the handler(s) are the only people how can meet the new need that the person has got hooked on.
Shit on these people and burn their identities whenever you can because they're not your friends. You might even be able to limit the future career opportunities of a younger intelligence officer who's approached you by not only telling your friends, but informing the entire internet.
These people may be a necessary extension of diplomacy, but history shows that it's likely toxic for any individual to be ensnared as an asset in any kind work for this sector of the government, foreign or domestic.
There are enough 'useful idiots' who will fall for this, you don't need to be one of them. Unless you're an actual employee of an intelligence agency or a contractor, these people will fuck you over in a heartbeat.
Anyone unfamiliar with this line of business could do worse than to read any old basic textbook on intelligence and counter-intelligence work (such as 'Thwarting Enemies at Home and Abroad', linked below. There's a good audiobook version on Audible).
Training in this business is based on cultivating anti-social behavior in susceptible individuals. Just as you don't want any garden variety sociopaths in your life, you don't want to deal with people who've been trained to fuck with you.
http://press.georgetown.edu/book/georgetown/thwarting-enemie...
It really depends on many factors - location, group activities, training, personal, the threats they pose to the actors with the will/desire etc to target them, also how you define compromised (a cleaner keeping tabs? a phishing email opened? a disgruntled volunteer? a paid staff member who walks out the door with data? a leader who has been turned?)
This is actually my gripe with the Dutch pirate party. They are often very alarmist and exaggerate problems in the same way the parties they oppose do. I wish there was a party that's focuses on major issues in stead of exaggerating a small number of issues in order to get popular with a specific market.
I admit I might still vote for them anyway if I can't find a party that better represents me. Fortunately we get quite a few to choose from! Dutch might want to take a moment and be thankful we have that :)
As an example the Taliban was targeting NGOs in the Afghanistan/Pakistan region because they believed efforts to vaccinate against polio were in fact an attempt to poison Muslims. Dozens of doctors, nurses, and volunteers were killed because someone like you decided to start a baseless rumor.
Most first world intelligence agencies have policies against embedding spies in aid operations. When it became common knowledge we used a vaccination campaign to collect on UBL, many people resigned from the Agency.
I wrote about one aspect of that specific case here:
https://medium.com/@roryireland/latest-wikileaks-documents-i...
Or more likely a terrorist organization in those countries started such rumors to turn public sentiment against the west. Oh, and then the USG used a vaccination program to attempt to track down terrorists, which played a role in the take-down of Osama Bin Laden.
It's fair to say that there are compromised NGOs, based on the OBL incident alone.
I am not really patriotic, but this is about 'protecting' your country, right? And if we will have some WWIII I think it will be mostly 'cyber'.
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
But eh, I am not an (ethical) hacker, I just build software...
What % of Tor traffic is for illegal/immoral/subversive activities?
Honestly, I would suggest that more people ought to consider encrypting more of their communications just for day to day use.
It doing so is much more difficult than these options, then it seems unlikely to happen.
Edit: that said, if there are - in fact - simple ways of achieving this goal I'd like to hear so I can share them.
Here are some things which aren't too hard, but which provide a reasonable improvement in security:
1. The easiest thing to do is replace your current SMS application with Signal, and to encourage your less technical friends to do likewise. You can still send regular SMS messages, but if both people have Signal, it will switch to encrypted messages. I've talked a fair number of non-technical, non-paranoid users into doing this and they all seem pretty happy.
2. Tor is surprisingly easy to set up and use these days, it works well, and it uses DuckDuckGo search by default. Again, it won't provide flawless protection against a sufficiently powerful adversary, and it's obvious you're using Tor. But still, launching Tor and using it is pretty easy. And it will definitely keep, for example, web advertising companies or ISPs from building detailed dossiers on your behavior.
Again, if you just want something easy to use and you don't pay attention to the fine print, you're not necessarily going to be well-protected against sophisticated adversaries. But you can improve your security a lot for relatively little effort.
What % of $100 bills are used for illegal/immoral/subversive activities?
Conclusion: Anyone handling a $100 bill is a criminal.
He is not being recruited as a soldier, but as a civilian. This works by drip feed. To simplify, let's assume the agents are actually from the AIVD (versus a foreign government or criminal syndicate) and that the account is 100% true.
First, he might be asked to recruit. A few months in, he may be asked to "to "crash a system in a public place". Then he will be told to dragnet his Tor exit nodes. If he says no the agents may be unable to continue protecting him from prosecution for crashing that system earlier. He did it as a civilian, after all.
These are people used to total impunity from our rules of law. They will be self-serving and deceptive. You make your own bed by heeding the sirens' calls.
There's always been running gags about spooks at hacker conventions, but it's "nice" to have a confirmation (even if it's hard to verify).
Was the 'meet the feds' panel at DEFCON not enough of a confirmation? I've seen people at academic security conferences wearing name-tags with "National Security Agency" right in the employer field.
[1] - https://en.wikipedia.org/wiki/The_Man_Who_Was_Thursday
FWIW, I'm assuming they would have asked him to report on fellow hackers without openly saying so. I got that implication from the article, but it doesn't say so and presumably they wouldn't have made that explicit when they approached him.
Theoretically, yes. But when you have agents allegedly asking civilians to "crash a system in a public place" while promising they won't "get arrested and nobody will know about it, not even the police," other possibilities emerge.
You may be deployed for political or commercial purposes, domestically or abroad. If you push back, your prior assignments, done while you were a civilian, could be used against you. Consider, too, how easy it is for foreign governments or criminal syndicates to pose as the AIVD and recruit patriotic civilians thusly.
> WWIII will be mostly 'cyber'
We are not at war and he was not being recruited to be a soldier. He was allegedly being asked, as a civilian, to commit crimes, domestically and abroad, under the alleged cover of an intelligence agency.
---
Buro Jansen & Janssen only verified "the existence of this person and confirmed their existence." We should consider this account plausible but unconfirmed.
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
Running a Tor exit node is probably not a crime in the Netherlands - I haven't checked on this. In any case, if it's a crime, it should maybe worry you that they also promised to protect the guy against police if he works for them. That's at least dubious. If on the other hand running an exit node is not a crime, which seems more likely to me, then the guy was really just threatening and harassing him.
> this is about 'protecting' your country, right?
Something like: "If you do illegal things for us we'll protect you from the police. If you don't... be a shame if you get raided for your exit nodes."
This sounds like setting up a criminal organization. Not sure you want that "protection"
Nor is blackmail very good way to recruit
How would we all feel if secret service people were recruiting moderators/ycombinator people that wrote paid comments and informed on the content of private conversation between founders and investors?
Personally I would trust the community less. I would expect contributions to have lower quality, be less insightful and more hostile, resulting in a general distrust that in the long runs kills the community from within.
HN already has something of a negative bias towards the work of the various security services (that is, the mood is largely pro-Snowden and anti-NSA) - having a better balance of views may well be a positive effect.
Similarly for the pro-capitalist bias here, and what almost amounts to a religious veneration for VCs and the very wealthy. Then again, HN is a bit of a chimera in the topics it covers. So we do have some diversity of interests and opinions.
I'm sure the AIVD's cyber division has some talent, but the AIVD leadership is pretty naive about the internet. Last year the director publicly criticized WhatsApp for providing end-to-end encryption because it makes his job harder. Sure. It's not as if any half-decent terrorist wouldn't use advanced cryptography or simply use burner phones to plan and coordinate their attacks.
Besides, high level statements like that (that make the main stream media) aren't meant to be factually correct or framed considering all nuances. It's political maneuvering. People don't always mean literally what they say; part of social intelligence is understanding this, and being able to read between the lines. I wish I had learned about this 2 decades ago. I guess us computer types aren't predisposed to have this come natural to us.
I wonder if he could (potentially) be prosecuted for it; the exchange includes "information reasonably assumed confidential."
Artikel 85 Wet op de inlichtingen- en veiligheidsdiensten 2002 http://wetten.overheid.nl/BWBR0013409/2017-01-01#Hoofdstuk7
It's a lot easier to track, store, and attempt to crack one single terrorist's encrypted traffic in a sea of non-encrypted traffic, than try to pick out the terrorist's encrypted traffic in a sea of other encrypted traffic.
If terrorists are the only ones using encryption, then their traffic will stick out like a sore thumb. While if everyone uses encryption, their traffic will simply blend in.
Or maybe he included some false info for noise injection... if so, how do we know which parts to believe? Skepticism suspension lifted, I suppose.
I understand how it can be viewed that way and it's certainly a bit of a risk but realistically it's not a huge risk.
If this is AVID, at the end of the day, despite what many may think due to outlying examples, they are an intelligence organisation working in a democracy and their agents aren't normally going to be in the business of retribution for someone turning down a pitch. Plus, if they became known for unnecessary retribution for minor things like someone saying no to a pitch, it would damage their long-term efforts in other areas.
They will expect that probably the majority of the pitches they make will be rejected. It's not something new to them. Similarly they will have risk assessed and planned for the eventuality of it being made public. Yes, it will annoy them but they will still just keep on moving through the social network analysis diagrams until they find and pitch the right people they are looking for.
Plus, while it will make some people more weary in future, occasionally exposure of efforts like this often leads to a softening up of others who might be interested in doing this sort of thing for them in future. Maybe a few months down the line someone in the community gets pissed off with others and remembers this article and drops AVID a mail........
By far the biggest part of what those teams do isn't secret and fits within the law. The "problem" is that Dutch law is very liberal on wire tapping, decryption etc as long as there is a reasonable suspicion and/or court order. Actually not far behind the rubber stamping in the US, but without the limitation that they can't target our own citizens (so: much worse than the US for locals, but similar for foreigners)
Obviously the military and domestic secret service hire the same people and have even wider abilities within the law and quite a wide grey area. Most of the public doesn't care enough to make it a political topic, so nobody stops them.
I hope the authorities don't go after him for making this public though.
I don't know what it would take for Governments around the world to acknowledge the importance of encryption and anonymity tools. Access to private data cuts both ways, if the Government can do it so can the black hats. Maybe a large scale hack of Government networks devastating the economy will bring them to their senses.
Given the allegations of Russia's involvement in the recent election, whether true or not, I was expecting Governments around the world to think deeply about cyber security issues. Looks like that won't happen anytime soon.
It is also a huge problem to a government struggling to halt, for instance, Islamic terrorists that are well established within that population and potentially use Tor for communication.
I think this is a case of the latter and I don't disagree with the sentiment 100%. The region faces some substantial challenges and we're going to see civil liberties erode.
If others do it, you have to do it too.
And this is why war exists.
Is it after tax?
Promises are cheaper than deeds. You don't need to actually protect anyone. It's actually better, from the agency's perspective, if they can convert an asset from an honest law-abiding man to someone who has "crash[ed] a system in a public place". They have leverage over the latter.
This is how criminals work. Given the secrecy involved, you could never be sure you weren't working for one.
How do you know it's the Dutch intelligence agency recruiting him and not a foreign agency or criminal group? It's unlikely AIVD would put him on their official payroll. From an asset's perspective it will always be difficult to tell--that's how the handler maintains deniability.
He thinks that AIVD wants him to infiltrate hacker scenes. Reality is probably that they want him to recruit more hackers.
Same story about the tor nodes, AIVD knows that hackers want to have tor nodes. They obviously do not care about Tor, thus want to look like they are cool.
Note they did offer him a position to manage young hackers.
I guess the sad part is the threat. Hackers have to decide for themselves if they want to work for the government or not. But is bad if part of recruitment is making threats (and demanding that those threats kept secret).
So mostly likely he didn't want to work for them anyway and was very unhappy about the implicit threats related to his tor exit-nodes.
There are lots of stories about people who in one way or another got in contact with the intelligence agencies and nothing really bad happened to them.
Of course, agreeing to secrecy and then spilling the beans is not recommended. But in this case the agents decided to tell him stuff without any kind of agreement.
While its easy to give in to paranoia or a witchhunt it would be equally amiss to pretend these things don't happen regularly. Things positioned as privacy centric would especially have a lot of attention on them from services around the world.
Few would be able to resist, the money, power, purpose and if they have leverage less so. Which makes privacy that much more important, its easy to get leverage if everyone is on file.
Trust is a huge premium. For those who need privacy or secrecy better to trust yourself. You don't need any specific technology or project to get those things.