Did a weak WiFi password lead police to our door?
bbc.co.uk
bbc.co.uk
I'm holding Theresa May directly responsible for this family's hellish experience.
Previous HN: https://news.ycombinator.com/item?id=26430266
The most complete solution I can think of to recommend to people to protect themselves from this insane law is to route all traffic over a VPN at the router. Otherwise you have to be worried about every single device that connects to your router - and you will just end up looking like a jerk when you don't let your friends use your internet out of fear of malware.
It’s worrying that every time there’s a problematic internet law, the response is “use a VPN”. I even saw that suggestion where it would be downright useless—the European law to require upload filters.
If the recommendation is always to use VPNs and otherwise keep quiet, those in power can calmly strip you of every right and ban VPNs at the end. What do you do then?
There is also the highly probable case of the IP address being shared by many people or switching to a new user mid day which does happen.
Something as trivial as the police forgetting to check what timestamp their website file upload date is in could easily result in getting the entirely wrong customer from the ISP.
If the contours of the internet are such that every local despot can change it, then it's not really an internet.
> they would have to be within about 20 metres of the house
Using a directional antenna, they could be substantially farther away.
> to do anything particularly sinister on the home network, the hacker will need to change the router configuration
That's not even remotely accurate. Uploading child abuse images to a message board as in the central story this article covers does not require configuration changes, for example. Trying exploits on other devices connected to the network doesn't either.
Given that I felt it was understandable to just jump that whole question even if it is factually incorrect...
At the very least they could have collected the passwords for the devices and dumped the storage to be investigated later rather than leaving these people without their essential devices for 3 months.
I honestly have an irrational fear of this happening to me. It's a great way for a malicious actor to utterly wreck someone's life. I tunnel all outbound traffic over a supposedly privacy-preserving (or at least non-UK) VPN, but honestly, this is the dystopian stuff of my nightmares. And I don't know why!
[0] https://www.expressvpn.com/vpn-software/vpn-router#recommend...
Anyone with that browser extension installed on any device on their network is making themselves an open VPN exit for millions of random people.
I'd suspect that what happened here is they thought they had an easy win, went through the motions, determined fairly rapidly from interviews etc it wasn't actually a viable lead, and didn't pursue further. But the machinery is set in motion by the initial conversation, for fear of prompt deletion if the storage is left with the would-be perp.
What you described is an unfortunate loophole in this concept.
So far, it seems that hasn't been widely abused in the way you suggest. A court is the one who decides if new evidence is substantial or not - simple things like 'we found 11 of his footprints in the snow, but a re-re-review of the photos actually finds 12!" wouldn't cut it...
I'm more a fan of the "better a hundred guilty go free" model - in this case, that means the state gets one and only one bite at the apple, and they'd better do it right the first time. Fewer dragons on this road.
[1]: https://www.theguardian.com/law/2011/apr/11/judges-lenient-b...
"the retrial must be approved by the Director of Public Prosecutions, and the Court of Appeal must agree to quash the original acquittal due to "new and compelling evidence"".
I think this is reasonable - there's checks and balances in place to make sure that the evidence really is 'new and compelling'.
You're muddying the waters a bit with this 'better a hundred guilty go free' thing - you might as well not bother ever arresting someone then? Surely this should be tested at trial, which is exactly what will happen (it's not 'oh we found compelling new evidence so we're putting you in prison even though we found you not guilty before', it's 'we found compelling new evidence, so we're going to give a new jury the opportunity to hear the new evidence and decide if they also think you're not guilty')
It’s not dumb. It’s very practical. Very easy conviction and it entirely turns the burden of proof over to the accused who now have to prove their innocence which is much harder to do especially as they probably lack the resources to do so.
If success is measured in amount of convictions and/or arrests, going with just the IP address is the easiest road to success.
Articles like this are incredibly important to make it clear to judges that an IP address is not sufficient evidence. This is not common knowledge yet
Same with IP addresses, THEY ARE PERSONAL DATA. Ad tech companies routinely use IPs for tracking and identification.
If you'd eaten chips this morning and there was a database of chip-eaters, eating chips would be considered personal information.
It's tiring to see these uninformed hot takes on GDPR on completely unrelated subjects.
If "most" of their online activity is their own, then some of it coming from "their" IP address isn't. You can pretend to be able to identify a person behind an IP address, but that doesn't make it true.
The problem with suspicion is that collateral damage to those who are innocent, but I don't think the answer is to not investigate.
Computer forensics usually means software bought from a vendor and operated by a technician sometimes with no deep technical knowledge beyond the tool they use. It probably even works well for the common case, but breaks in cases where something unusual has happened.
UK ISPs mostly use an IP pool – meaning they have to keep records about who was assigned which IP at which time. Some may run carrier-grade NAT. Those records are obviously trusted, but may not necessarily be accurate – and even if they are, human mistakes occur, especially when working with things like IP addresses, dates and timezones.
But if not for following IP addresses, how else do you investigate this sort of thing?
I would argue the fault is in a mentality that suggests presuming guilt based on an IP address, then looking for the confirmatory evidence as an "icing on the cake," and a mentality that the investigation process should be so harrowing that the guilty will always go punished even if there isn’t enough evidence for an attempt at conviction. This is long after several such scandals around the same type of crimes.
The police aren't really interested in catching criminals or helping people. There's no promotions in that. Meeting a quota of number of arrests however, you'll be chief inspector in no time!
(It's also interesting to compare the amount of sympathy these wrongly accused people receive versus other victims of police action ...)
I would say you search the computers, but do this in a very timely manor so that you do not have to involve employers and social services.
These searches should take minutes or hours, not months, and shouldn’t ruin people’s lives if they are innocent.
Yes. The searches are not designed to ruin anyone's life but informing other parties, like what happened in this article, is sometimes necessary and and can have life ruining consequences even when entirely innocent. Things could leak out from the school to parents, to other work colleagues, limit career progression, etc. These leaks may even be intentional when stupid people are involved. Doing the searches quicker and being innocent or not doesn't help avoid either of the below (from the article) from happening:
> The police needed to unlock Matthew's work laptop, which was encrypted. He had to tell his boss about the case in order to get the decryption key.
> And the police had also informed social services and the children's school about the investigation, meaning Kate was suspended from her role as a governor there.
The first one could be unavoidable. The second one is technically avoidable but it is going to happen (in UK society, at least).
It could definitely have avoided the second.
I think there is a moral duty to carry out investigations in a way that protects the lives, reputations and livelihoods of the innocent, and this example has fallen short of that in my opinion (although a reasonable person could disagree).
This is the bit I disagree with personally, as I think it conflicts with 'innocent until proven guilty' when a person can be removed from their position and have their reputation destroyed by the police without sufficient evidence to convict (remember - no charge was ever made from the police).
It's pretty feasible to do an initial scan of a few devices within a few hours - and if you don't find enough evidence after a few hours of looking then IMO you don't have enough evidence to ruin someone's life (go get more evidence first in that case!).
The 'blast zone' of this investigation was ultimately two innocent people's reputations ruined in an attempt to find one guilty person (who wasn't found).
(Again, reasonable people will disagree on how far an investigation should be able to go prior to charge - my own view is clearly more on the 'protect the innocent, even if it means investigation is harder and a few baddies escape justice' side than some others might be!)
If I ran a message board, not only would I not capturing the upload IPs in any log files (hello GDPR in any case), I'd be tempted to put fake upload IPs in instead -- change the first two or three octets so the logs point to a government owned range.
Society so caught up in guilty until proven innocent.
Justice wasn't swift either. They disrupted their life and this couple is expected to bear all the costs of the govs wrong action.
It's not about finding ways to keep yourself safe so that the gov can't accuse you of something and destroy you (see swatting), it's about the gov not being able to destroy you with such ease.
Worth considering when making backups. A burglary, fire, virus or hacker won't do this but the police may take your offsite backups and your onsite ones and your computer with the credentials to your online backup service.
I guess storing backups on a device that's the property of somebody else would be a way. I'm guessing they won't go seizing non-suspects' property.
I believe this was a remote attack. Either on their computers, phones or router. Consumer-grade network equipment is notoriously insecure and Vodafone has absolutely zero expertise let alone incentive to do anything about it - they just buy these routers wholesale from China for a couple bucks a piece and call it a day.
That said you’re completely right on the state of ISP router security
- Infect the computer via the normal means
- Connect to a CNC relay and await instructions
- Receive instructions and perform the deed
The most important aspect would be to use a non-persistent compromise so that it leaves no trace when the police arrive and unplug the computer to bring it in for forensic analysis. With the trail ending at this computer and no sign of infection, they have their perp; case closed.
Criminal organizations could even offer a SAAS solution - a kind of "crime as a service", where they rent you the infrastructure of ephemeral compromised machines to use.
There is already an entire industry offering "residential proxies," which are relays with the functional characteristics you describe. The difference is that the machines providing the relay are (typically) co-opted by adware etc, rather than being overtly compromised. I believe there may also be some operators who actually own the relay nodes.
That's all pretty great when it comes to foreign Netflix, but it's also an easy way to get other people convicted for posting child porn. I don't think there's a lot of security going on on that network. And you don't even need a special criminal organisation to abuse such a system, you have actual normal, civilian users!
Why would the would-be hacker need access to the router settings? I can't think of anything worth changing there, these routers don't have any extra features.
The usual illicit use is to point an antenna at a router and use it from afar (well, no more than 100-300m, line of sight and preferably no obstructions).
In which case it makes more sense to just get a prepaid SIM card, set up a phone as a VPN in a location far from you and route traffic through it. It's not more complicated than bruteforcing a WPS PIN or WPA2 password. That is, if you can't just get a VPN without using any ID.
Sometimes, they can be retrieved from the MAC address as well. So it's just the illusion of security for most.
[0]: https://www.xkyle.com/verizon-fios-wireless-key-calculator/
In the UK a prepaid SIM is normally linked to you in some way.
However, I just looked into it some more and it appears you can still buy prepaid cards by cash and buy top-up vouchers with cash.
I just checked, and the default credentials for the HHG2500 model mentioned in the article were admin / vodafone1234.
It isn't clear to me whether the router's admin interface was default open on the WAN side, or whether it could be remotely enabled through TR069. I wouldn't be at all surprised if it could.
More likely is that the ISP messed up their logs, or that they were incomplete. That happens more often than they would like to admit.
I was on IRC and someone I have talked to a few times sent me a official looking link to the website of a local political party and it was a sub-folder that had indexing enabled and that's where they stored their backups.
The dude then got in and published all usernames and hashed passwords on pastebin.
He was using a VPN at the time, I wasn't.. The police took all my devices and kept them for a year until charges were dropped. Not a fun time.
I wrote about it here -> https://blog.haschek.at/2015-that-not-so-awesome-time-the-po...
Doubly so putting the explanation with little wording to leave doubt should help the family get some level of normalcy. At least now they can point to an article in the BBC to explain when employers, coworkers, other parents, or staff at the school inevitably bring it up.
It's not perfect but it's an easy explanation to put people's minds at ease and dissuade any notion of wrongdoing from this ridiculous incident which will undoubtedly follow them for at least the next decade or so if not the rest of their lives.
Or they really were guilty...
> The government plans to ban default passwords being pre-set on devices, as part of upcoming legislation covering smart devices.
it shall be deemed a reasonable security feature under subdivision (a) if either of the following requirements are met: (1) The preprogrammed password is unique to each device manufactured.
I read this as a password based on the mac address or serial number would be compliant without meeting what I think is the intent of this law.
Can I claim they cannot arrest me since everyone might use my Wifi?
> The Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007,[20] requires persons to supply decrypted information and/or keys to government representatives with a court order. Failure to disclose carries a maximum penalty of two years in jail
https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
You can read the full law here: https://www.legislation.gov.uk/ukpga/2000/23/part/III
This obviously isn't immune to a zero-day, but at this point you'd be more secure than 99% of the rest of the people so any attacker will just move on (why bother breaking into this router when you have an exploit that will net you hundreds of other ones with much less effort?)
I've been spammed quite a bit by friends with such applications past 6 months...