Tracking logo found in Navy email to Navy Times amid leak investigation
militarytimes.com
militarytimes.com
When through the normal course of using a technology you reveal information to the government (in this case the military) they can use that information against you.
Having an embedded image from a third party server in an email is well within normal usage of email. Logging IP addresses of machines that access content on a web server is also well within the normal usage of that server.
I'm also not sure what the journalist is afraid of in this case. Your IP address reveals almost nothing about you beyond a rough physical location on its own. Considering the Navy sent this email they already know WHO the recipient is. From an editor or authors name I could most likely find what city they live in with no extra help beyond Google.
There absolutely isn't anything illegal or even suspicious about this. If you want to go absolutely crazy mad with paranoia maybe they could collude with another federal agency to tap that network connection... but that is INCREDIBLY unlikely for this.
That’s not the legal standard for searches and seizures under the 4th amendment.
It’s about the reasonable expectation of privacy, and when a defense attorney emails their client the client has a reasonable expectation of privacy. A reasonable person doesn’t think the prosecutor has embedded tracking into emails sent to their attorney which will relay information back to the prosecutor when shared forwarded to the client by the defense attorney.
>That’s not the legal standard for searches and seizures under the 4th amendment.
Was Katz overruled?
Regardless of the location, a conversation is protected from unreasonable search and seizure under the Fourth Amendment if it is made with a "reasonable expectation of privacy".
The law is not and never was:
>When through the normal course of using a technology you reveal information to the government (in this case the military) they can use that information against you.
It seems the journalist here believes some tool much more powerful than a tracking pixel may have been used. I've never heard of a "splunk tool" and frankly it seems like BS, but if the journalist believes this then the tone of the article is explained.
The only way the access described there is even remotely possible is using a vulnerability in a systems image parser or network client stack (using only the URL and server response). Burning an unknown 0-day vulnerability with that level of power wouldn't be wasted on even a high profile military court case.
I would think there'd be a wider attack surface to attach a PDF though...
They lay it out pretty clearly in the article. What you are describing might be true for a private company, but that same behavior from a military branch of our government is very different.
This is a really interesting area of law that I don't think has been settled.
One could argue that attaching this tracking pixel to an email is similar to attaching a GPS tracker to a vehicle. In United States v Jones in 2012, the supreme court ruled that placing a GPS device on violated the 4th amendment.
> "the Government's installation of a GPS device on a target's vehicle, and its use of that device to monitor the vehicle's movements, constitutes a 'search'"
Regardless of whether it was "well within normal usage of email" or not is kind of irrelevant.
It is also very different coming from the government as opposed to a private institution.
It is also very different to be targeting a news outlet (especially one that has been critical of you!).
I would absolutely challenge you on both points - this is ABSOLUTELY suspicious, and as they pointed out in the article, likely illegal – and I haven't gone crazy mad with paranoia.
The target is irrelevant in the case of legality. The only additional protections a journalist has is on not revealing their sources. This doesn't impact or interact with other emails so no sources could be compromised via a tracking pixel. Being "shady" isn't illegal and I wouldn't even say a tracking pixel is shady. The closest approximation of what this tracking pixel is doing is as a read receipt for a piece of mail.
If you want to quote "United States v Jones in 2012" against others you should probably be aware of what the presiding judges actually ruled. It was determined that the action was illegal only because physically attaching the device was considered trespass of private property not because the tracking of the vehicle's location required a search warrant.
If you wanted to make a similar argument you would have to instead refer to the Computer Fraud and Abuse Act to cover something similar to digital trespass. A tracking pixel does not violate that law under any circumstance that I'm aware of.
That said, target is not irrelevant for illegality. There's also an issue of ethics in targeting other lawyers; if I was the defense lawyer this is the issue I'd be pushing like crazy with the judge, ethics panels, etc. Right or wrong, they can do something with that, esp. if they can get some discovery that proves there was actually an attempt to target -- that would be huge. (And they're not allowed to delete any documents to that effect since they are the government).
Journo forwards email to source for comment. Source triggers tracking pixel. Source is compromised.
They can also do discovery to find out the intent behind the pixel -- if they find anything about tracking to find the source of the journalist or learn about the defense, they risk having the entire case thrown out.
This could get really, really interesting. If I was the defense lawyer I would push this as far as I possibly could.
One can't make this arguments based on the Jones ruling because Jones doesn't apply in this situation. The entire reason why the court ruled that physically attaching a GPS tracker to a car is against the fourth amendment is because attaching the device involves physical trespass on a suspect's vehicle which they considered part of his "personal effects." A tracking pixel doesn't have the physical intrusion bit that the court found unconstitutional. In Jones the court only addressed the physical intrusion, not the GPS data itself.
https://en.wikipedia.org/wiki/United_States_v._Jones
>Also left unanswered was the broader question surrounding the privacy implications of a warrantless use of GPS data absent a physical intrusion – as might occur, for example, with the electronic collection of GPS data from wireless service providers or factory-installed vehicle tracking and navigation services.[27] The Court left this to be decided in some future case, saying, "It may be that achieving the same result through electronic means, without an accompanying trespass, is an unconstitutional invasion of privacy, but the present case does not require us to answer that question."[36]
Assuming it is just a normal tracking image, though, it doesn't provide "detailed, encyclopedic, and effortlessly compiled" information about someone's activities - just whether they opened that particular email while displaying remote images, and - if so - their HTTP request. I think it's unlikely this fits the facts under Carpenter.
Also, Carpenter was about a warrantless search. We really have no idea if the prosecutors did this on their own initiative to try to address the violation of the protective order, or if they did it at NCIS's behest after a warrant. It's entirely possible that this is at NCIS's initiative. Still a lot of facts to uncover here.
It does trigger a request on the user's computer, which is a personal effect, after effectively smuggling code onto it. Definitely a grey area.
(What I'd do is a different topic.)
Regular people won't make the mail <-> WWW connection in their head without being told, nor should they be expected to.
I understand how you're just trying to reason from the other side. Just trying to show how the reverse argument might happen.
As far as I'm aware, one of the reasons "hacking" has been defined to be a crime, is that unauthorised access to someone's machine has also been defined as a kind of trespass. Allowing them to rule that deploying code from one location to another is also trespass against the physical location.
There's something bizarre about that argument.
Why should it be OK for private companies?
Sorry for the undeveloped response, but....hahahaha
There is very very little information you can get from an individual image being loaded by a user agent.
Substantive e-mails will have attachments most of the time, and be from trusted sources obviously, or will just be text.
Maybe that's just my experience?
> There's no way that was an intended part of the design.
There is certainly a way. And regardless of whether it's intended, it you're dead-set on configuring your system so that it automatically contacts arbitrary 3rd party servers, then you shouldn't be too surprised when that happens. "Bad guys" are known to be opportunistic.
It is "normal" in the sense that it is a common practice, but it's also nefarious and shouldn't be done.
Fortunately, it's easy to defend against.
Which they seem to have gotten in trouble for violating on occasion: https://www.cnet.com/news/government-web-sites-are-keeping-a...
It's not malware, really, and it can't harm a local computer that opens it.
But it is a sign that the prosecutors in this case believed the reporter would forward the email on to their source, giving the prosecutors the IP address of that person. And there is some question of whether that's ethical or not.
It is up to you, or the reader, to choose to believe him or not and the information he provided is already more than he is obligated to give to enrich your life with. It is, as you put it, a “good place to start” if you wish to google more yourself.
Perhaps those with no legal training should be the ones Googling, since many here clearly have no idea what they're talking about.
Think of any comment by anyone here as someone graciously providing you with free counsel out of the time of their day, with the big disclaimer that they are not your client, and that the information is under no warranty. This disclaimer is implicit on all internet comments. It is up to you to consider their claims, and verify them. If you’re not willing to research their claims yourself then it’s pretty clear that
1) you’re just here to argue for one side to the public (aka propaganda)
2) pursuit of the truth is not actually your goal
Given that your profile states that you are both part of the military and also a government lawyer may indicate that both 1) and 2) are true.
I think you’ll be hard pressed to convince people they are wrong simply by accusing them that they are wrong due to lack of evidence. There is no court here, no jury to decide you win or lose. You can contribute more to this discussion by offering your unique perspective given your background.
https://pubs.geoscienceworld.org/msa/rimg/article-abstract/6...
Here's an analogy from the civilian world: An employee reports an OSHA violation. Their employer is fined and forced to spend money on fixing the violation. Angered by this, the employers management tries to find who reported them to OSHA.
They were caught doing something wrong, and now they are trying to identify who caught them doing it. The ethical response is to admit wrong doing and make it right, not intimidate your opponents. If you don't understand that I'm not sure there's much debate to be had.
https://www.americanbar.org/groups/professional_responsibili...
It’s unethical because the only reason they are trying to unsurface the leaker is so that they can potentially punish them to discourage that behavior which revealed bad behavior in the first place.
If the original comment far upthread was contemplating reporting someone to the state bar for something that didn't violate state bar ethics rules, then that's even more egregiously inflammatory.
It is pretty normal in the advertising world to use these features. Some mail clients (for example gmail) load these images without prompt by default (although they do so via an anonymizing proxy).
> The tracking software appears to be “an unusual logo of an American flag with a bald eagle perched on the scales of justice” included in an email from the lead prosecutor, Navy Commander Christopher Czaplak. Images in email are routinely used for tracking purposes, though the image files are typically transparent. Navy technology, it seems, is less subtle.
http://www.caaflog.com/2019/05/14/navy-prosecutors-accused-o...
Can't harm a local computer? I think you're wrong.
Malware has often hidden inside of specially-crafted images.
I helped build a product that blocks them at the enterprise level without affecting the presentation of the message or requiring end user effort: https://messagecontrol.com
Folk selling B2B complain about the long time it takes to convert a lead to a sale, to a PO, to a payment - but these slimey sales tactics are just as much to blame.
You also have to understand how providers deal with email to make sure delivery is never affected. We had to ensure 100% delivery and never fail.
It's about the sender seeing whoever the recipient forwards the email to, and about the sender seeing the recipient's network information (although that's a hard sell because the recipient already advertised their network presence by using email), and the use of non-HTTPS servers that could be compromised to intercept traffic.
What? How does a tracking pixel do that?
Either way, if such were the case, this payload would need to rely on the presence of, and thus exploit, some sort of vulnerability in whichever host cached it. Not impossible, but not exactly a trivial maneuver.
If they had suspects in mind, and had an awareness of OS version and patch level, it might be within the realm of possibility to land a working payload.
Furthermore, if they were targeting Navy personel, there might even be a level of control to selectively enable a backdoor that permits a more advanced outcome than would ordinarily be possible in the wild against random individuals around the world.
Maybe the plan was to hit internal personnel with a specialized payload that only affects Navy assets...
Laymen do not understand that simply opening an email can be tracked via image loading "secret pixels". I think that makes it an open secret.
The only thing a tracking pixel "takes" is the address of the computer that downloaded it and the time it was downloaded. None of that is your private information.
Let me just list a few of the things that I consider private:
* The fact that I viewed the email in any way
* The fact that the email was opened on more than one date
* What IP address is assigned to me by my service provider
* What user-agent is used by me (and what version)
* Whether or not I share my IP with other email addresses
* Bandwidth information about my network
* Latency information about my network
> None of that is your private information.
You are dead wrong on this point.
Even if you turn off images it's not always good enough: some trackers try to load any external resource they can, like sounds and fonts.
Whoa. While that doesn't surprise me, I didn't know about it. Can you demonstrate it with various providers? Gmail, for instance?
The privacy rights between attorneys and clients is particularly sensitive. Not to mention a government agent sending it to journalists with the freedom of the press rights.
In this case, the journalists have confidential sources, they may forward that email to them, which would leak the source's IP, which could reveal the identity of the source.
A free and strong press is how we keep powerful institutions in check. It is not an inflammatory statement to say that a reprisal by a government institution that has been accused of doing something unethical is unethical. It's just common sense.
In case you decide to answer that question eventually, the model ethics rules are here: https://www.americanbar.org/groups/professional_responsibili...
I would really be interested in knowing which one you're alleging was violated.
IANAL, but clause (a) looks potentially applicable.
https://www.americanbar.org/groups/professional_responsibili...
> or use methods of obtaining evidence that violate the legal rights of such a person
I don't expect to see this prosecutor disbarred, but one can still call out the unethical behavior.
I am not aware of a legal right not to receive e-mail with remote-loading images.
Simply not liking someone's argument doesn't mean they didn't answer your question or are arguing in bad faith. To automatically assume that would imply that you are the one arguing in bad faith.
However, if they can establish the navy did it expressly in the hopes this email would be forwarded to a “leaker”, that might be a bigger deal
We (American people) essentially let it slide, and as a result, we deserve the consequences.
I'm really curious if this would have been considered an issue if it was just a visible header image like a logo. Does making it a single pixel make it more illegal than a image in plain sight? Both perform exactly the same function and both must be explicitly loaded by most email clients.
"The Navy email to Navy Times contained hidden computer coding designed to extract the IP address of the Navy Times computer network and to send that information back to a server located in San Diego. Under U.S. criminal law, authorities normally have to obtain a subpoena or court order to acquire IP addresses or other metadata. Not using one could be a violation of existing privacy laws, including the Electronic Communications Privacy Act."
"“It is illegal for the government to use [the emails] in the way they did without a warrant,” he said. “What this constitutes is a warrantless surveillance of private citizens, including the media, by the military."
"Hicks would not state for the record whether the Navy obtained a search warrant or subpoena in connection with the emails with tracking devices."
> “I am writing regarding your emails from yesterday, which contained an embedded image that was not contained in any of your previous emails,” Parlatore wrote. “At the risk of sounding paranoid, this image is not an attachment, but rather a link to an unsecured server which, if downloaded, can be used to track emails, including forwards. I would hope that you aren’t looking to track emails of defense counsel, so I wanted to make sure there wasn’t a security breach on your end. Given the leaks in this case, I am sure you can understand.”
Unfortunately I do not live in Europe. :'(
I'm not aware of any major change in article 7 since that moment, so I'm fairly confident that opinion is still relevant. If you're asking if it's been tested/challenged in court or in a DP measure, I don't know.
So? The mechanism doesn't ameliorate the issue.
The government is rightfully held to a higher standard when it comes to information collection. Particularly when it comes to collection of information from defense attorneys on an active case.
It doesn't tell you WHO downloaded the image (but you could deduce that if you had other information, such as who was using the computer at the time it was downloaded) and it doesn't tell you WHY that image was downloaded (was it because an email was opened? Or was it because the email was scanned for viruses?).
https://www.dol.gov/general/ppii
Email addresses are considered Personally-Identifiable Information even in the United States (and certainly in the EU too).
Deduction of who downloaded the image is obscene and a violation of that person's privacy.
Any correlation of email address information with any other information at all could be considered a violation of that person's privacy: the IP address and user-agent information alone is sufficient enough to point in the direction of a malicious attack. And there are people who have some serious safety concerns: people who've been abused by significant others and are prone to being victim to stalking or hacking is just one example.