Uber remotely locked down offices during police raids, shutting off computers
bloomberg.com
bloomberg.com
To me this just falls under the category of unauthorized access. If my threat model included people physically present using force to access my sysadmins' computers I would be implementing the same security with a company-wide lock-down triggered by a panic button on every machine.
>> When the call came in, staffers quickly remotely logged off every computer in the Montreal office, making it practically impossible for the authorities to retrieve the company records they’d obtained a warrant to collect. The investigators left without any evidence.
I keep my head above water so I really don't really care if the police can access the data. I do have a problem with the raid giving them access to data well beyond the scope of their warrant and relying on the courts to pare it down after the fact.
Just because some people in uniforms show up at your door and demand access, doesn't mean that's the entire process. Even if they have a nice piece of paper from a court, it's just the start of the process.
What if its just a ruse and they aren't really cops? What if they are cops, but the government is corrupt? What if the warrant was obtained in a faulty manner?
This sort of measure allows the company to engage with the process in a less disadvantaged way.
Making a mistake in this regard gets you a obstruction of justice charge. Call a lawyers, but don't expect a judge not to take this badly when they have issued a warrant.
> What if they are cops, but the government is corrupt? What if the warrant was obtained in a faulty manner?
That's for the lawyers to deal with in court. Once again, obstruction of justice on a legally issued warrant is going to be bad news for you.
This is the whole point of why police conduct raids:
...to use the element of surprise to arrest targets that they believe may hide contraband or other evidence, resist arrest, be politically sensitive, or simply be elsewhere during the day.
If he refuses to comply or try to alter the evidence while complying, sure, they are guilty and I'm pretty sure there's a legal process for this situation, but at this point right now if they seized the data, they can no longer alter it.
However, the problem is that this represents a nuclear escalation that I'm not sure tech companies really want to have.
These warrants will probably now move directly to "comply or shut down."
I suspect that the next time this occurs, the police will decide that intimidation is the better part of valor, seize EVERYTHING, arrest EVERYBODY, and tell Uber to come sort it out.
They may not be able to get Uber, but I suspect that they will grind enough employees through the police and legal system with enough force that everybody will think twice about calling a shutdown number ever again.
Since when was Canada considered a lousy jurisdiction? Last I checked, most of the jurisdictions they operate in are no worse than the US. Unless you’re saying that all first world countries are lousy jurisdictions, I think you are being rather hyperbolic.
I can easily see this tool having been built for operating in those kinds of countries.
What's upsetting people is that this got used in a country which is nominally not corrupt in order to hide from "proper" law enforcement.
If this was being used to hide from a raid in Russia, people would be cheering instead.
Personally, I wouldn’t be cheering. I’m of the mind that if you’re going to do business in a country, you can’t choose to ignore the local laws and expect zero repercussions.
That said, do I care that Uber built this system, nope! But I would laugh if it backfired on them and got them into more legal trouble.
Actively building a specific system to counter a warrant is probably going to go a long way to prove its obstruction. Uber's less than lawful reputation won't help here.
Some guy in Canada pages a number - as the company training teaches - hen cops show up. That's plausibly not an attempt to fail to comply with a court order. Pretty sure telling your boss your office is being raided isn't an easy thing to prove contempt for, especially if it's company policy in subpoena-able training manuals.
Then some anonymous team initiates a nuke-it-from-orbit sitewide computer lockdown remotely from the US. Where they're quite likely fairly well shielded from Canadian contempt-of-court rulings.
Sneaky.
Many people equate standards in criminal law to "beyond any doubt", when the reality is "beyond reasonable doubt".
When you write a program like this, and you can be shown to have executed it at a police raid, _followed by_ a call to your company's general counsel (or in this case to a "special team", "specially trained" to run a program called "Ripley", with the purpose of "nuking a site from orbit") to advise them, the claim that "this is common practice" goes out the window and "we're specifically obstructing a warrant until counsel/whatever other process happens takes place" becomes entirely "reasonable" as a depiction of what you are doing.
https://en.wikipedia.org/wiki/Sergei_Magnitsky#Exposing_the_...
TL/DR: police had given the materials taken during the police raids to organized criminals, who used them to fraudulently reclaim $230m of the taxes previously paid by the company.
You are a person entitled to rights. A company is not a person. Border searches are warrantless, arbitrary, and lack any oversight whatsoever. The company was searched by a court order signed by a judge for suspicion of a specific crime. In every way possible, these situations are entirely different.
* there are too many entities that may think they can get this information
* you are to ignore them all, execute a physical intrusion protocol (lock every and make everything inaccessible ) and notify your contact at USAO.
* our legal signed off on it.
We have executed intrusion protocol four times during my time there. In one case it involved a dick waving contest between state police and state court and USAO, USMS and federal court.
The bottom line, learned in trenches, is that if you are a reasonably big fish, you classify all search warrants as intrusions and deal with them as you deal with other physical intrusions. Documents/data will be turned over in an orderly fashion by your legal.
Locking your computers that are no longer in company possession is a common Enterprise control. They take protecting your data seriously!
If the authorities need the data on the computers the will surely present a properly scoped warrant!
It says, in about as many words, "FOAD until our counsel green lights unlocking, potentially before or after some housecleaning".
Correct, Uber's lawyers will be able to review and perhaps fight the warrant in courts. Uber's sysadmins will have time to figure out how to reveal the required data in a clean way that does not compromise the rest of Uber's data which includes but is not limited to data about where private citizens travel from time to time.
>"FOAD until our counsel green lights unlocking
Perfect, yes it does say this. We should all say this. Would you like Google or Facebook or whatever other service you use to reveal your private information if the government does not provide a proper warrant?
>potentially before or after some housecleaning".
Okay, well in this imaginary scenario Uber would be guilty of tampering with evidence and I'm confident Canada has relevant laws.
How or in what way was this warrant deemed to be improper? There was zero consideration of that, instead it was "nuke from orbit" at first sight.
You are suggesting that the authorities should always be granted arbitrary access to a random amount of data, which is almost certainly not relevant to their case, any time they get a warrant for any data at all.
Further, you are acting as if that article is the end of the story, but it's not. There will be legal review by relevant professionals and Uber will provide whatever it is legally required to provide.
Locking down the computers until Uber's lawyers have had a chance to verify what the warrant covers and what access the investigators are entitled to seems like a fairly prudent security measure.
If somebody showed up at your office with a piece of paper saying they were allowed access to everything on your computer, would you unquestioningly give them that access? Personally, I'd hope any services that I trust my data to wouldn't give up access without some verification that it's a legitimate request.
The person who first see the police is likely a receptionist or similar who does not have access to the information specified by the warrant. That person, quite reasonably makes the local management aware the police are present immediately.
Management hasn't encountered the police or seen the warrant yet. They don't know the nature of the encounter, but they know they're supposed to tell corporate immediately. They do so, and make no attempt to prevent the execution of the warrant once they have received it.
Corporate, located in another country doesn't know what's going on except that people claiming to be police showed up at a foreign office. They initiate a lockdown of the local computers until legal can sort it out.
Now if management read a warrant demanding access to something on local computers, then made a call to corporate they knew would cause those computers to be remotely locked, they could be in trouble. I make no comment here about whether Uber is good, but Uber is definitely smart.
Gosh, I first read this as "a poorly scoped warrant" and didn't think twice about it.
In weaker, but likely relatively accurate words: They're logging all of their remote users out of Google Drive so the authorities can't access the spreadsheets there. In essence. That's what I'm reading.
Point being, Uber could still be compelled to present the evidence in court, and Uber may comply with that compulsion. Does a Canadian warrant give the Canadian government the right to access information stored on a server in the United States? The answer to that is an emphatic No. Does it give them the right to possess an API key which would allow them to access information stored on a server in the United States? Does this change if it could be reasonably expected that the information was, at some point, in the ephemeral memory, not even a hard disk as far as we know, of a computer on Canadian soil?
I really don't know. We all knew the global power of the internet would begin to raise questions like this, and our legal framework simply hasn't dealt with them yet.
That seems like it would fit the definition of “destroy” to me.
Once the warrant is served, anything done to delete anything off that computer is obstruction of justice, it doesn't matter what the mechanism of storage is- whether it's RAM, Hard Disk or floppy disk.
Secondly, the warrant is what compels uber to give access to the evidence, there's no 'We don't feel like it right now, go to the courts to try something else'. The ability of the authorities to gain evidence through other legal avenues provides literally no defence for uber in failing to comply with a warrant.
Someone in Canada just paged a number they'd been trained to when cops show up. That could easily be no more obstructing that calling your lawyer immediately (depending on what you could prove they knew about what'd happen then).
Some team in San Francisco remotely shut down (and possibly deleted data/evidence from) company machines. Anybody on that team might want to forgo any planned trips to Canada, but it'd be a long stretch to think Canada would try to extradite them to face contempt of court charges.
"Uber", the legal person is who. Why does HN think the law is a series of fixed instructions rigidly executed by a computer and can be easily hacked by overly clever constructs? "Well, I didn't shoot my wife, I just set-off the first domino on this rube goldburg machine - the hamster pulled the trigger - gotcha! ha ha ha".
This will be put in front of a judge, and they will see through this for what it is.
It's pretty clear "Uber the legal person" is pretty happy breaking laws and has a long history of not suffering any real personal consequences. I'm reasonably sure a Canadian judge doesn't even have an existentially dangerous penalty they could apply to Uber-the-legal-person. Worst case seems to be they could shut Uber down in Canada and jail some local senior management. Uber-the-global-corporation probably has contingency plans and has determined and budgeted for that risk. That's their "business as usual".
"The law", while generally robust locally against clever constructs, is probably not as effective a tool against globally distributed corporations - at least not in a very satisfying "Yeah, someone's gonna pay for that" kind of way...
https://www.reuters.com/article/us-apple-tax/apple-plans-new...
At least they're choosing to pay - at least in the US - and only after the Trump administration cut the tax rates, but still...
When someone else in the chain has agency, the argument for it being a rube goldberg machine gets a lot weaker. While some would argue that what the husband did here is bad, it certainly wasn't murder - not unless a lot of other factors come into play.
1. Both sub-entities are part of the same company
2. One is acting on instructions from the other
So how about this:
"As a Corleone, have a very tight-knit family, and the senior members are afforded a great deal of respect. My uncle the gun enthusiast firmly instructed me that if I were to ever discover my wife in bed with the mailman, I should immediately leave him a message, unlock the doors and windows, and leave the house until he calls me back with additional advice."
Uber's actions are similar to shredding evidence of tax evasion, which in the case of Arthur Anderson during the Enron scandal, resulted in federal obstruction of justice charges, and a strengthening of federal powers for charging of similar actions.[0]
Note: I am not a lawyer, nor a resident of Canada, so I am not sure if my proposal above is legal within that country. But it would seems to me that actions similar to the above have taken place in the USA in the case of tax evasion with probable cause.
[0] https://blj.ucdavis.edu/archives/vol-5-no-2/document-destruc...
If I had to guess: Very little data is stored on site.
If all of your local office computing platform is basically a thin client, confiscating the local equipment with a warrant doesn't do much. You can take it away to a forensics lab and image its disks, but you're not going to get any usable data off it without a network connection into the corporate WAN, crypto keys, sending subpoenas to specific people for their login credentials, etc.
I know nothing about Uber's internal software architecture and network topology. But I would be very surprised if most of their day-to-day operational systems like ticketing, customer service, recruiting, finances, were not operated through TLS1.2 connections in a web browser to a set of intranet servers, located thousands of km away from where the branch offices are located.
My other question is, if all the data is in the cloud in SFO, wouldn't the data technically reside in the US?
Looks to me like the Canadian police were hoping to get lucky. That some user wouldn't have enough time to log out.
But Uber didn't delete or otherwise destroy the evidence. It locked the evidence while preserving it, so that it can provide the required amount of data if / when properly served with a warrant.
Don't mind. If the police has good evidence, they will show up later and take some of the Uber's servers that hold the relevant data.
The article vaguely makes it sound like Uber acted within their rights and the police just don't like that they didn't find a bunch of unlocked computers to rummage through, by virtue of what it omits. I don't have a problem with that. If their warrant amounts to a fishing expedition, it actually sounds like harassment of Uber. A warrant should specify something you have some likelihood of finding. If the police walked away empty handed and Uber doesn't face charges for destroying evidence, it seems like they had a bad warrant to begin with.
While I am loathe to defend Uber, these measures appear designed explicitly to prevent police fishing expeditions, which I am fully in favour of, and to serve little further purpose.
All this protects Uber from is fishing expeditions where the police hope to come across an "unlocked door" so they can sift through everything hoping to find something.
I get that we don't like Uber, but I support this type of action and think it should be standard operating procedure for every organization.,
What I am worried about is the employee that gets directed to lock things down and then, as a result, is possibly personally targeted by police and prosecutor both for it.
Now if Uber destroys or refuses to provide data covered under a properly scoped warrant, then I will gladly pick up the pitch fork with you.
My understanding of the majority of warrants are that they have a nebulous grasp on transnational corporations.
For example: if I (the police) have a French warrant and serve it on the Paris offices of Uber, but Uber has a pager service that performs whole disk encryption and sends the keys to a server in Panama, where does that leave me?
The French government isn't going to raise a diplomatic ruckus over a taxi company operating illegally in Paris.
And I'd strongly suspect a judge wouldn't be inclined to allow me to forceably repatriate the data (which data?) without further evidence (exactly why I was serving the warrant!).
So essentially, I don't see it as being technologically hard to construct a system where I am enabled to operate illegally in a country, as a matter of corporately-sanctioned policy, while skirting around local technical ability and federal legal will to call me to account.
You can try saying "lol, the data is in Panama", but the judge is unlikely to care about that.
The court will simply order you to cease all business functions in France until the data is provided to the court.
At least for US law, there are split decisions. US v Microsoft (the Ireland case) [1] is currently pending a Supreme Court ruling.
I'd hazard to say that I'd be surprised if they didn't rule in favor of national security concerns, except that Jesner v. Arab Bank [2] is coincidentally also pending.
Given that the latter concerns the Alien Tort Statute [3], aka the ability of US law to be applied internationally, it will be an interesting pair of decisions.
I'm not familiar with how things work in France (other than rough knowledge of EU data privacy directives), but at least in the US things aren't as simple as "what the legal system wants via warrant, the legal system gets."
[1] https://en.m.wikipedia.org/wiki/Microsoft_Corp._v._United_St...
[2] https://www.oyez.org/cases/2017/16-499
[3] Subject of a fascinating episode of More Perfect, https://www.wnyc.org/story/enemy-of-mankind/
That's not the case here with Uber. Uber itself, a Canadian company subject to Canadian law, is being compelled to provide data relevant to its own business within Canada. I would be very surprised if Canada allowed businesses to not provide relevant financial information to the tax man.
What if the warrant was looking for memos on illegally circumventing local parking laws? Memos that may or may not exist?
If Uber hosts that Canadian-focused data on servers outside of Canadian jurisdiction, good luck getting ahold of it unless the government's willing to play the "We'll bankrupt you unless you give us something" card.
And my point is that kind of international leverage isn't available to, say, a suburb outside of Toledo. Which effectively means a company willing to play hardball with encryption (at great legal risk if they slip up) can have their cake (illegal corporate policies) and eat it too (not be held liable for illegal policies).
Wrong. Compelling them to do so does not mean that compulsion will be successful. Encryption exists.
But I digress. I think we've established that we agree the original security procedure with a secure remote lockout is a good idea.
It wasn't to prevent an overreaching warrant, it was to prevent -any- warrant from being meaningfully served.
Generally speaking warrants are not granted for "all of your data." Imagine if every time the authorities got a warrant for some data Google has about a particular suspect, Google would reveal all of its internal data about every user, all of Google's internal financial files, etc. That would be insane.
If you have a physical device such as a Yubikey that unlocks your laptop, the court can order it to be given over, but the requirement that you produce the key from your own memory seems to be a different story.
That is a slightly different situation, as the evidence had been seen, and was known to be in the suspect's possession.
https://en.wikipedia.org/wiki/Key_disclosure_law#United_Stat...
There are two cases referenced in this wiki page which are relevant if you're curious. https://en.wikipedia.org/wiki/Key_disclosure_law#United_Stat...
[0] https://arstechnica.com/tech-policy/2014/04/lavabit-held-in-...
[1] http://blogs.findlaw.com/third_circuit/2017/03/man-held-in-c...
The page might also trigger other processes such as alerting council, that they have the right to do.
So possibly not as risky?
Is this what the on-site employees were doing though? According to the article they were:
> they’d been trained to page a number that alerted specially trained staff at company headquarters in San Francisco
Depending on whether they knew what the "specially trained staff" was "specially trained" to do, this seems logical and harmless? If the police came to my office I would probably text the company owner to find out WTF is going on.
Where are you getting this from the article? How do you know it is "cryptic"? Of course it is pre-arranged.
Uber is known to run into problems with the government (which includes law enforcement). I'm not surprised there's a protocol for what a manager should do in this situation. If I was hired to work there my first question would be WTF do I do if the police show up?
I hate Uber as much as the next fickle HN commenter, but the idea of sending a text/paging a number doesn't feel that odd.
And from all reports, employees were specifically trained to do this, and they knew why. Open and shut case.
The internal alert might not have been "law enforcement has arrived with a warrant for our computers." It might have been more like "a bunch of armed men just demanded to be let into the building, I don't know who they are yet, shut everything down now and ask questions later."
Employees might have a legal obligation to protect some of the data that's accessible from their office computers. Maybe credit card and banking information, or health information for drivers?
Yeah... Not buying it. Random armed men appear in the building and some employee is more worried about the company data, rather than calling police to alert/verify?
The first thing the armed men will do is show identification and a warrant. This isn't a no-knock raid by a swat team in the middle of the night.
Judges tend not to take those kind of coy answers very well.
Are you an expert in identification and warrant? I never saw one, you could print a fake one and I couldn't tell if it's right. Same for any identification.
Once we talked about doing some relatively public MILSIM with friends. It didn't take 5 minutes for us to realize that it would end badly because of that. If your goal is to access Uber data or any big corporation for that matter, you can see how easy it would be to profit from that.
Thus, lock everything down and let legal experts actually take care of that seems like a pretty good solution to avoid this kind of situation. They are there to seize data, they can do it as much as they want. They can then force Uber to unencrypt the computers.
If they're going to risk decades in jail anyway, there's a good chance they're just going to shoot you if you start telling them they can't have what they want.
Your job isn't worth risking obstruction charges or facing down criminals.
The raids are just theatre.
Law enforcement has already been seen to act adversarial to private interests, remotely logging out of computers is utilized to try and limit law enforcement's ability to obtain information beyond the scope of a warrant. There is little doubt that law enforcement would willingly take information beyond the scope of the warrant and later find a way to use it against them.
If enforcing law is seen as adversarial to private interests, then those private interests are by definition, against the law.
>> When the call came in, staffers quickly remotely logged off every computer in the Montreal office, making it practically impossible for the authorities to retrieve the company records they’d obtained a warrant to collect. The investigators left without any evidence.
Come back with a better warrant.
Oh gosh, what a meeting that must have been with the devs who came up with this codename. This should go down in Tech History.
[1] https://www.bloomberg.com/news/articles/2018-01-11/uber-s-se...
However, as they grow, as they get autonomous cars, as they get autonomous drones, once they get to the point where there could be more serious consequences, I'd like to see more accountability.
You would hope they wouldn't need to take it, but if I were CEO of a company I would order the computers shut down even if everything were above-the-book.
Of course, maybe that's why I'm not CEO of a company. Who knows.
That's true if they've just come knocking. But at the point they have warrants you're risking prison.
Court orders are orders, and they are to be obeyed in full and on time.
https://www.judiciary.gov.uk/wp-content/uploads/JCO/Document...
> What I fear is an even greater cause for concern – and it is for me a real concern – is something symptomatic of a deeply rooted culture in the family courts which, however long established, will no longer be tolerated. I refer to the slapdash, lackadaisical and on occasions almost contumelious attitude which still far too frequently characterises the response to orders made by family courts. There is simply no excuse for this. Orders, including interlocutory orders, must be obeyed and complied with to the letter and on time. Too often they are not. They are not preferences, requests or mere indications; they are orders. This principle applies as much to orders by way of interlocutory case management directions as to any other species of order. The court is entitled to expect – and from now on family courts will demand – strict compliance with all such orders. Both parties and non-parties to whom orders are addressed must take heed. Noncompliance with an order by anyone is bad enough. It is a particularly serious matter if the defaulter is a public body. Non-compliance with orders should be expected to have and will usually have a consequence: see Re W (A Child), Re H (Children) [2013] EWCA Civ 1177.
But you're talking about a parent ignoring court orders, I guess, in which case this one is more relevant: a mother made false allegations of abuse against the father, and continued to do so; and removed the child; and continued to do so; and she did those things after being ordered not to, and she got a (suspended) prison sentence as a result: http://www.bailii.org/ew/cases/EWHC/Fam/2017/3358.html
> The judge had indicated that she was prepared to authorise disclosure of her Judgment to the Judge at the Kingston Crown Court, and that if the 1st Respondent objected she would be required to make her objections known. On 25th January 2016, the judge ordered her judgment may be released to the sentencing judge. The 1st Respondent received a four-month sentence, suspended for six months on 27th January 2017.
EDIT: And here's a direct link to the cases he mentions at the end of the para I link above: http://www.bailii.org/ew/cases/EWCA/Civ/2013/1177.html
The submitted title was "Uber remotely locks computers during police raids to block information access". Since the site guidelines ask submitters not to use article titles when they're misleading or linkbait, I assume the submitter was trying to helpfully follow the rules. It's better to use representative language from the article itself, though, to avoid blunders—and in this case the subtitle can easily be shortened.