Police tracked a terror suspect until his phone went dark after Facebook warning
wsj.com
wsj.com
They ask for what seems like a reasonable request - let us read terrorists’ emails if we have a warrant, without affecting everyone else. Anyone non-technical would probably vote for this no problem.
They don’t understand it’s just not possible without creating some impossible to keep secret master key. I guess politicians are used to giving other people problems and just expecting them to figure it out.
Society just need to decide how it wants to play this because its an either or proposition.
There is no technical encryption protocol that works only for the good guys. Unfortunately the legislators are too thick to realise this simple fact.
If I hired a messenger to take a spoken message to my partner across town, the same applies. Nobody has any right to interrogate my messenger and he has no obligation to answer.
If I send electronic messages it should be no different.
The fact that interception and surveillance is possible doesn't suddenly make it obligatory.
Technology is power, in whatever form it comes in from weapons to education to communication. That power makes law enforcement more powerful and criminals more powerful.
Law enforcement wants it both ways. They want the increased power of their own encrypted communications, their own education, their own better tools and techniques AND they want to use technology to take away power that their supposed adversaries wouldn't have even been able to lose before the tech existed.
The technology exists. It can't be taken off the playing field. It doesn't matter how bad the "bad guys" are, law enforcement does not deserve that much power in a free society. The power balance between the state's monopoly on force and the people needs to be maintained. If it is not, abuses are inevitable.
Basically, it says as soon as you involve a third party - in your example, a messaging app - you can't expect privacy and therefore law enforcement doesn't need a warrant.
If law enforcement had to get warrants for all of this information from services, providers, and vendors, they'd be forced to a) be more selective and b) move slower for judicial review. Both constraints would significantly improve the situation.
Now that I think of it, the idea of end to end privacy never really was a thing before we had ubiquitous encryption. Involving a third party always meant that you were vulnerable at that third party. So, I suppose that you could implement laws that dissallow E2E encryption, but still allows encryption from the client to the service -- allowing the service to record the data if presented with a warrant. Now that I think about it, the "wire tapping" code in the telephone switches were literally a legal requirement for selling the equipment otherwise they would never have convinced me to write the code! Now that I'm older and wiser, I'd never do it again... but I kind of understand the symmetries....
But my phone is my voice, my memory, an extension of my mind in many ways. What is "me" and not a third party extends to the actions I take with my phone.
If we can just say my encryption key with a password in my brain is "me" and not a third party's (which can be true with tech setup correctly) then everything is fine. What I give to the third party is not "private" but acquirable without a warrant. But what I give to that third party is cyphertext. You can read my encrypted messages all you want... in their encrypted state. The decryption keys are private parts of my person and the person I am sending the message to.
In the US the odds of dying in a terror attack have remained historically low since the mid 1970s.
Specifically, it's between 1:12M and 1:40M - about the same as picking the correct inch between DC and NYC.
Conversely, the odds of a US citizen (who is not suspected of a crime) being inappropriately surveilled is near 100%.
How to play it? Prioritize real threats over the nearly imaginary ones.
It should be straight up impossible.
In general I have seen that if people are smart enough to get people to vote for them, they probably have smarts and leadership skills not dissimilar to business leaders. They very likely understand what encryption entails. They probably don't share your values on whether it's a good thing.
Backdoored encryption is an interesting concept, but suffers from the problem that the bad guys could get their hands on the key.
But could there be another way? Something like k-out-of-n keyholders have to agree for the backdoor to open. Shamir's secret sharing could do it, but has the drawbacks that it's one-shot and that someone has to know the key to set the scheme up. You want every investigation to require a new k-out-of-n agreement.
Ultimately we ought to design society so that a large group (legitimate protest) of people can defy the government but a small group (criminal gang) cannot.
For example, a better measure might be the nature of the harm, if any, done by the defiant group.
Edited to show that the person was only suspected of terrorism.
I have the disadvantage of not being able to read the article, but the headline, at least, says he's a suspected terrorist, not an actual terrorist.
I know this was in western Europe, not the US, but in the US, the distinction between "suspected" and proven is really very important, because we have a strong track record of suspecting innocent people of being terrorists.
> "No, that can't be right. Why would they do that?" the official said he asked his contact, thinking it a joke.
Maybe don't buy spyware from malicious actors. It's ridiculous that investigators with this amount of power to invade on suspects most intimate areas of life aren't close to sufficiently briefed.
Does somebody have a source on which agency the European official is supposed to be from? Using spyware that's also used by authoritarian regimes must be a bad joke. Not that our German homebrewn spyware would be any more ethical but I'd have thought that EU level agencies would at least do some level of due diligence.
I don't think the article made any reference to EU level agencies, though. It seemed to only talk about "European officials", "Western agencies", etc., which could be EU-level or local.
The "official" shot their pitch in the leg with this line.
If this guy bragging or trolling? I am genuinely confused. But I can only assume that many in intelligence services act in a similar manner, i.e. NSA, GCHQ, etc.
https://www.morningstar.com/news/dow-jones/202001026663/poli...
Riiight, that's certainly what they'd like the world to believe!
When the software can be modified OTA without the user's knowledge, even if you did have e2e encryption without any sidechannels or backdoors at the client software today, you might not when you wake up tomorrow.
I suspect it won't for long though.
I think people should have a right to privacy, and I think law enforcement agencies should have a right to monitor potential near-future massacre-committers on a limited and singly-targeted basis. Dragnet surveillance is very different from surveiling a single individual for a specific and dire reason.
Now, if they never sent Facebook a signed court order related to this matter, then it's entirely the agency's fault.
So, in my opinion, the issue here is the choice of contractor (and the agency apparently not sending Facebook a court order??); NSO has so many ethical issues (specifically that they're a hired gun that'll fire no matter the wielder or their intent) that Facebook has a moral obligation to send these warnings. Pick someone who actually aligns with your goals, agencies. A firm you could actually theoretically work for yourself and still sleep peacefully at night. And if you can't get one, then do it yourself.
Here is evidence that they used Pegasus to find and kill a dissident: https://en.wikipedia.org/wiki/Jamal_Khashoggi
It'd only be moving the goalposts if I had said "with some fraction of the global community". I clearly meant the entire global community, not just one or a few countries. Obviously at least some countries support this, else NSO would get no business and would not exist; some governments supporting and procuring them is the whole problem in the first place. So pointing to a few countries supporting NSO doesn't really provide any counter-argument: it emphasizes my point that there needs to be globe-level coordination here. Perhaps you could remove certain rogue countries like North Korea from the consensus list, but it would otherwise need to be a global consensus.
UN officials have also expressed their concern with their ethics, and the UN is probably as close as you can get to representatives of the global community (even if it's not at all perfect). Facebook could look to the UN's positions as a starting point, for example (and perhaps that's exactly what they did here and maybe is part of their legal grounds for why they consider NSO to be a bad actor).
If it were the case that every country and regulatory body in the world collectively decided that this kind of thing is ok, then yes, I'd need to change my criteria.
I was just saying if an intelligence contractor (in the same domain as NSO) is universally in good standing with the global community and a court order is sent, I think it's ok. I am not aware of any currently existing ones which are in good universal global standing, so this will probably only ever apply in many years or decades.
How is Facebook supposed to determine this? All they know is X was breached by an NSO Group tool.
Nobody presented Facebook with a warrant. Nobody even told them who is doing the breaching. It could be the French or the FBI or the Saudis, or a terrorist cell.
I'm just trying to argue that, I think, in a grand theoretical sense, this sort of behavior is not necessarily unethical of law enforcement agencies if they send a signed court order and work with an ethical contractor instead of NSO or Black Cube or whoever.
But yes, as far as I'm aware, none of the currently existing ones have any ethical standards at all. May be some decades until that changes (maybe in the form of a startup that tries to go a somewhat different route).
So... a gag order? The reason why they didn't send facebook one is simple: they didn't expect to get caught. If tech companies start getting proactive about warning their users, I'd expect gag orders to be SOP when hiring cyber mercenaries.
https://www.forbes.com/sites/thomasbrewster/2018/11/21/exclu...
“Not your 0day.... so not your 0day”.
Can you elaborate on this one more? A corporation that does illegal things cannot be criminally prosecuted, but if a member or director authorizes criminal activity then the government can pierce the corporate veil and prosecute the individual(s) directly.
Example: eCorp directors have a grudge against xCorp's cleaning lady so they hire a hitman and pay for her death. the police would arrest the directors and any parties involved and they will seize both personal and business assets related to the crime. Cleaning lady's family hires a lawyer and sues eCorp and each director personally for damages. eCorp loses and pays gobs of money. each director loses and pays whatever gobs of money they have left. Ergo, a corporation did something that was illegal (conspired and then paid for a killing) which left them civilly liable. Then the corporate veil was pierced and all of the guilty were found and charged.
The government wouldn't use this service because it is illegal. If you are making an overly general and vague comment on the legality of stingrays.. there is nothing illegal about hosting a BSS/LTE station with Voip and SMS integration and logging all of the MACs of local phones as they connect. The secrecy comes from the police not wanting their methods coming out in legal texts for public knowledge.
I’m not entirely sure why you’re mentioning stingrays and IANAL but what you describe sounds illegal under 18 U.S. Code § 2511[1]. But again for some reason a corporation is making these devices and selling them (also illegal under §2512[2]). I presume they are selling to law enforcement and pseudo law enforcement for use where a wiretap is not obtained (otherwise they can just lean on the carrier who is legally obliged) which would seem illegal under ECPA [3] even with its problems.
There’s a whole section of EU law that covers man in the middle, hacking, data protection, etc. that would also make this specific case cut and dry. A government agency crying that Facebook notified an account holder their account was hacked by their corporate contractor seems beyond the pale. Further that news agencies publish this story with a slant that Facebook or Apple have somehow enabled terrorists is shameful. We should be holding our governments accountable to follow the law and obtain warrants. In the US all the corporate support they need is built into laws like CALEA and USA PATRIOT Act, the least our governments can do is follow the laws we entrust them to protect.
[1] https://www.law.cornell.edu/uscode/text/18/2511
[2] https://www.law.cornell.edu/uscode/text/18/2512
[3] https://en.m.wikipedia.org/wiki/Electronic_Communications_Pr...
When the phone homes are unexpected, a lot more than the signatures start getting phoned home for further investigation.
Add some other constraints on how big the binary/memory space can be in the sandbox and an attacker would have trouble running a shadow copy to provide the right responses.
Maybe some timing checks too where the system denies anything that starts taking longer than it should and phones home with it.
All just a thought though.
I would guess all those video calls had a few fields set differently compared to the official client, so it was easy to filter the logs and find all instances of it.
...but go on.
Disclaimer: I did only read the beginning of the article, because of the paywall.
https://www.morningstar.com/news/dow-jones/202001026663/poli...