Hackers gaining power of subpoena via fake “emergency data requests”
krebsonsecurity.com
krebsonsecurity.com
I think the argument being made here is one of those "we can't make a perfect solution so no solution works", which is nonsense. Simply don't answer requests from police departmenents you can't verify. I bet you if a police department would request some business sensitive information they would not hand it over without going over the subpoena with a fine toothed comb. The issue is just that they don't value their customers privacy high enough to do a proper check.
If a non-US company does business in the US, most people would expect the business to also answer to US law enforcement. You can't just operate in a business and not follow the law of that country. Same applies the other way around, you do business as a US company in Germany, you better follow German law. Hence companies tend to have HQ in one country, and then subsidiaries in other countries, who know how the local market and laws work.
This is really a non issue being blown up in to some unsolvable conundrum by people in this conversation that want to find problems in using a phone book.
So much phishing potential in the links below. I know every GP surgery in the UK that uses a windows server is accessible online and Shodan can give away so much information, lets hope people like Cisco and netgear dont have any zero days.
https://www.wired.com/images_blogs/threatlevel/2010/02/micro... https://cyberlaw.org.uk/wp-content/uploads/2010/02/microsoft...
https://info.publicintelligence.net/MSN-Compliance.pdf
https://answers.microsoft.com/en-us/outlook_com/forum/all/gi...
https://answers.microsoft.com/en-us/outlook_com/forum/all/ho...
https://www.microsoft.com/en-us/corporate-responsibility/law...
https://www.microsoft.com/en-us/corporate-responsibility/us-...
https://leportal.microsoft.com/home
https://sendersupport.olc.protection.outlook.com/pm/policies...
https://undisputedlegal.com/how-to-serve-legal-papers-on-mic...
https://customers.microsoft.com/en-us/story/843015-nep-uk-po... https://www.transformation.police.uk/ https://www.transformation.police.uk/what-we-do/national-man... https://www.transformation.police.uk/what-we-do/identity-acc... https://www.computerweekly.com/news/252493673/UK-police-unla...
RING.com LEO portal support page. https://support.ring.com/hc/en-us/articles/360031595491-How-... https://help.publicsafety.ring.com/hc/en-us
Facebook LEO portal https://www.facebook.com/records/login/
Yahoo https://www.eff.org/files/filenode/social_network/yahoo_sn_l...
I think the real issue is that the backlash from politicians and the public for failing to respond to a legitimate emergency will be orders of magnitude larger than the backlash for disclosing some customer information.
For example, in the U.S. E911 services use a database of coordinates and other info to determine what police department to route you to based on location. Requiring an EDR to come from an agency in this database (or larger state and federal institutions that are well known) could solve a lot of this problem. Having a way to look up police badges might help as well, and is also just a good idea.
An EDR is essentially the same as some person on the street stopping you and saying they are police and need to commandeer your vehicle. It makes sense to verify that in some way (such as a badge), as otherwise even if you think a crime has just been committed, you could just as easily be giving a vehicle to the criminal as the police.
> It makes sense to verify that in some way (such as a badge)
But that’s hardly real verification, a badge is trivial to fake.
Yes, but in certain situations is very unlikely to be present. It's not a great way to verify an officer of the law, but it's better than nothing, and lack of it is a good indication that someone is not one.
I have seen this type of "argument" countless times reading HN. I always wondered if I was the only one who noticed. Thank you for calling it out. It is indeed nonsense.
IMO, if "tech" companies cannot exercise due care, then they are at fault. There is no exception based on some idea that "our company must be large and serve millions of people in order to make money therefore we should not be held to the same standard as a smaller company." If necessary "scale" and nonexistent or grossly reduced customer service comes at a cost (e.g., fraud), then "tech" companies should have to pay that cost, not anyone else.
"The current situation with fraudulent EDRs illustrates the dangers of relying solely on email to process legal requests for highly sensitive subscriber data."
IMHO, the amount of important stuff today that depends on the presumed integrity of an email address is astounding.
"This clearly isn't working. We have evidence of it not working." So needs to be shut down immediately because nobody agreed to this level of failure.
From there the next argument becomes "This cannot work." I.e. there can be no adequate solution. But hey, if you disagree with that part and you've got a solution that you think /can/ work let's get it out there and analyse it and see if its worth the risk.
Note that data in Cuxhafen (??) Germany won't be partitioned from your home town and stored in a different and differently secured database. So the weakest link in the weakest country is the one relevant to your data security.
Please note I'm not agreeing with Krebs's argument here. I haven't got all the information to process it, nor have I had time, nor is this my area of expertise, nor do I have to have a firm opinion on everything.
I'm just spelling out Krebs's argument because I really don't care for your summary of it.
If you have a solution you think can work, let's hear it.
Re-approach the problem from a different perspective - companies don't value their customer's privacy enough. What solution can we put in place to force them to care about their customer's privacy? Can we force them?
You have to start there for a worthwhile solution.
The "perfect" warrantless surveillance solution is a totalitarian nightmare. You can't make it "better" because it's broken by design.
Or the one that is hierarchical in theory but provides no accreditation in practice an uses a completely insecure protocol? Or the protocol replacement for that technology that replaces the hierarchical nature and replaces it with cantralized entities that again get full authority to answer any request how they want?
Plus from the article:
> It involves compromising email accounts and websites tied to police departments and government agencies
If websites and emails can be compromized then the hackers also have a good chance of gettng at certificates.
But the root problem isn't even that hackers can claim to be the police when making the requests but rather that the police can make these requests in the first place without getting a court order. "Police" is already a very large group of externally unaccountable actors that will include those willing to abuse these powers without the need for "hackers".
Although, this:
> I bet you if a police department would request some business sensitive information they would not hand it over without going over the subpoena with a fine toothed comb.
is a very salient point.
This is essentially what happened to dark.fail:
https://www.vice.com/en/article/qj8833/dark-fail-fake-court-...
Just wanted to point out there are ~18,000 police departments in the US alone. So, the request doesn’t have to come from an unlikely foreign country for this scam to be a problem. Not that this fact absolves the ISPs and others from failing to secure their data via an appropriate verification process.
What I got from reading is that there are conflicting concerns. An EDR needs to be answered as quickly as humanly possible; they exist for cases where it's likely that someone would die while waiting for a warrant/subpoena. Secondarily, tech companies really don't want to have a headline like "School bombed because $socialMediaCompany refused to hand over records in time".
The competing concern is privacy. The problem isn't directly with the number of police departments, but that there's no way to automatically authenticate the requests. They'd have to manually look up the police department, call them, and try to get routed to the officer that supposedly sent the request.
The difficult part is that in order for EDR's to be at all useful, they need to be faster than getting a warrant. They can probably get a warrant faster than Facebook or whoever can finish their game of phone tag to check on the request. So right now, they're checking the only thing that can be validated within the request itself: the domain name.
The solution he calls out seems workable: a global identity provider for police through the FBI or another government agency. In my rough interpretation, we could use something like GPG to sign the requests and have the FBI run a keyserver. We would need to secure the GPG keys, but if they were kept offline on USB sticks except in the rare case of submitting an EDR, that should be far better. It would require physical access to the keys to submit an EDR, and tech companies can infer that someone has physical access to the keys by the signature.
It seems like the false positives (wrongly assuming fake police department) will cause more present damage than true negatives (giving away data to scammers) because the damage this does is very much somewhere in the future (it takes a lot of time for a person to realise their data had been leaked, especially if it’s not part of a dump)
However, there are often disputes where the feds do not what to prosecute certain groups or individuals, and might interfere with state / local authorities. (e.g. police in a Democrat-run state prosecuting allies of a Republican president and vise versa, or investigations into federal informants who are violating state law).
This would also allow make it easier for the feds to perform on-path attacks where they "forward" EDRs from state / local authorities that were never issued by those state / local authorities.
The feds need to own this and all requests need to flow through them. It wouldn't be hard for them to have a small staff available 24/7 to confirm requests and forward them on to businesses, and then the business only needs to trust a single entity. There may still be disputes over the legality, but those disputes will need to be defended by the central federal authority, rather than putting the burden on every company.
In the US, the police aren't responsible (in a criminal or civil sense) for harm due to inaction. I don't know why you think a national/multi-national corporation would be.
And it doesn't have to even be a decision on a company level, ordinary people are strongly inclined to follow the police requests and see them as an authority, so employees of the company will feel as their duty to provide the data promptly. Just look on all those cases of pranksters posing as police officers and making ordinary people do insane and even clearly illegal things just because they were "ordered so by the police". Compared to what that McDonalds manager did [1], pulling some personal data from the database and emailing it back to the person one believes is a police officer is nothing.
[1] https://en.wikipedia.org/wiki/Strip_search_phone_call_scam
The onus is already on individual companies to vet requests from private individuals that want to move money around via Know Your Customer laws. I don't see why the same shouldn't apply to verifying whether or not a request for customers' private information is valid or not.
I'm having trouble finding any basis for this in law. Can anyone help clarify that? Are EDRs just 100% voluntary compliance on the part of some private organizations who are choosing to divulge customer information without an actual court order?
If that's the case, why are we lamenting the existence of the hackers and not publicly shaming the companies complying with these nonsense EDRs? Real court orders aren't that hard to get, and at least there'd be a more blatant crime to prosecute if anyone forges them.
https://www.apple.com/legal/transparency/pdf/requests-2020-H...
> An emergency request must relate to circumstances involving imminent danger of death or serious physical injury to any person. If Apple believes in good faith that it is a valid emergency, we may voluntarily provide information to law enforcement on an emergency basis.
I imagine this is a middle ground between 'governments always have instant access to customer info' and 'i don't care, get your warrant', because in the latter scenario real harm can be done in the hour/hours it can take to process even a FISA warrant. With this, Apple can deny requests if there is not obvious imminent harm, while probably pretty good at identifying legitimate requests and delivering helpful information within a few hours to keep lawmakers from creating more types of warrants to force Apple's hand. (apple ~= all the other data providers with an emergency request system)
You're saying the privacy of my data depends solely on providers being "pretty good" at identifying legitimate requests from people trying to get their hands on it?
I feel better already... /s
There are already preexisting systems for solving this sort of problem. For example the FBI could set up a PGP based certificate authority[1] for email. Then the FBI signs the identities of the podunk police departments ahead of time. All the service providers would need would be the FBI identity (PGP public key) which they would sign once to authorize it and then they would be able to verify emails coming from any of the podunk police departments with no extra work on their part. This example comes with a revocation system that actually would work in this case.
All secret key material would remain under the control of the specific FBI department acting as the certificate authority. No third party involvement would be required.
[1] https://sequoia-pgp.org/blog/2021/05/12/202105-hello-openpgp...
Their position is likely "it looked like it came from a cop, not our problem if the cop is forging court orders."
We're already very familiar with the concept that ignorance of the law isn't a valid reason for violating the law. What's wrong with that in this scenario?
There's no "magic bullet" in security, you can't just "authenticate" individual emails "with no extra work" and hope that that solves things without addressing the gaping security holes that allowed those emails to be sent from official servers in the first place.
DKIM and SPF only prove that an email passed through a particular email server. The whole point of doing the verification end to end is that the stuff in between does not have to be secure.
In practice you would just register 2 or more keys left in the care of 2 or more people. Each person would be individually responsible, as it should be. When someone left you would revoke the key. You would not have to go super hard on this, most of the requests would be routine and not time sensitive. In an emergency you do the best you can with what you have available.
Real subpoenas would also work.
https://news.ycombinator.com/item?id=30820424
relevant comment: "I had to click through more than 100 links to download all the data, how can this be acceptable? Specially coming from Amazon. How hard is it for them to create an archive with all the data? This is ridiculous, I can't imagine how was the meeting when they decided to produce purposefully such garbage UX."
This would indicate that Amazon has some kind of internal interface for these Emergency Data Requests for law enforcement that just dumps all the data to them immediately without all those barriers to access. Makes one wonder why that's not also available to Amazon users?
Also, are these Emergency Data Requests ever subjected to post-mortem court review of any kind? Is anyone in law enforcement ever subjected to discipline for bogus requests?
If they scratch the government's back, chances are the government will scratch Amazon's back, too.
> Makes one wonder why that's not also available to Amazon users?
There's a benefit to giving law enforcement whatever they want, but little to no benefit to giving users the freedom to move their data out of Amazon's walled garden.
Amazon is the same company that is creating partnerships with law enforcement agencies all over the country with their Ring products and surveillance network[1][2].
[1] https://www.theverge.com/2021/1/31/22258856/amazon-ring-part...
[2] https://www.eff.org/deeplinks/2020/06/amazon-ring-must-end-i...
This sounds extremely unlikely.
Maybe in 1999 someone would have hosted their mail server on the same server as their web site. But today?
Today they use the same crappy hosting company as in 1999, that does the same thing it's always done, just only slightly newer hardware. Especially on a municipal level, there still is not much of a standard when it comes to such things.
If so, then it was likely set up a long time ago and not maintained well.
Some backstory that's not in the piece. I originally started reporting this about six months ago, when an anonymous tip suggested people were creating fake police department .org domains and sending requests from there. Spent ridiculous amt of time chasing that to no end.
As part of that research I looked at all new police dept domains in the last year. Found so many I was sure were fake. They were all real. Some were half-done. Some completely wide open, security-wise. It was depressing to learn after that there are > 18k police depts nationwide.
330,000,000 / 18,000 = 18,500 Americans per police force
67,000,000 / 48 = 1,396,000 Brits per police force
Not sure what to make of that.
[0] https://bjs.ojp.gov/content/pub/pdf/nsleed.pdf [1] https://www.police.uk/pu/contact-the-police/uk-police-forces...
So here in the UK, Special Branch are the intermediate between the security services and police forces, but dont be fooled into thinking UK police forces are independent, there are official channels which is what gets reported and the public are allowed to know about and then there are unofficial channels, in financial stock trading, this could be likened to Dark Pools.
The US just blanket legalized every local paramilitary. Any random-ass local law could give you the right to create your own personal police force.
-----
> It's easier than you think to create your own police department in the United States.
> Yosef Maiwandi formed the San Gabriel Valley Transit Authority -- a tiny, privately run nonprofit organization that provides bus rides to disabled people and senior citizens. It operates out of an auto repair shop. Then, because the law seems to allow transit companies to form their own police departments, he formed the San Gabriel Valley Transit Authority Police Department. As a thank you, he made Stefan Eriksson a deputy police commissioner of the San Gabriel Transit Authority Police's anti-terrorism division, and gave him business cards.
https://www.schneier.com/blog/archives/2006/03/police_depart...
In the US the Top 100 cities (each will have at least one police department) have just 20% of the population.
You have a police department for almost every state, county, city, and town in America. And, the US has about 3000 counties and 19,000 towns (with about 14,000 being 5,000 or fewer people.)
If there's one thing I learned from practice in programming is the more "exceptions" you make, the more room there is for bugs and security flaws. The same applies for everything. Keep rules simple. The more "if this, then that" you add, the more loopholes you may find.
If it's a true emergency, someone should have no difficulty being available for a call.
(The main number could be compromised too, but come on...)
The fact that such requests can't really be authenticated reliably without a human in the loop (because as Krebs says, you can just create real email accounts on the police dept email server) and there are so many of them is terrifying. You could put our entire society (in the us) into chaos just be pushing this more and more until our law enforcement is just overwhelmed. If we were in a war with Russia or China, why wouldn't they do that?
What? If the attack you describe was going on, there would be a very simple remedy: Stop requiring people to comply with possibly-false subpoenas.
The only thing that's "unfixable" about this is that it's not something you can automate. You need an actual human being to perform the verification step(s).
It’s also trivial to create a fake police department in some small town, set up google maps entry etc…
What then? What about when you operate internationally and have to accept requests from 100+ jurisdictions?
Contact the state government to ask? There’s a good chance nobody will be able to provide the answers you seek on short notice.
Not going to work internationally anyway.
You are engaging in bad faith, please stop it.
It’s not even about being a “devils advocate”, the balance of probabilities rests squarely on the side of this being far more difficult than many commenters here try to make it out to be.
I think it is you who is engaging in bad faith.
Sounds like you’re just repeating the point that authenticating these requests is impossible, as that authentication would have to happen fast.
And then you need to do this internationally. What will you do? Contact the embassy? Suddenly your authentication process could take months, which is a problem if you’re legally required to comply sooner than that.
Who said that?
Worst case scenario is probably a horrible PR disaster after a child dies because you couldn’t process a real request fast enough.
And we’re not talking about seconds, but easily days or weeks.
It is literally impossible for request recipients to solve this problem.
This I agree with. I'm trying to find the actual text of the law, I'm surprised the government isn't pretty specific about what constitutes a valid EDR, who can send them, etc. Bureaucrats love to write rules.
The end solution is either an authentication scheme, a $1000 rush processing fee that includes a verification process and the requirement to call it in (It is an emergency, isn't it? Emergencies do not happen often, so what is $1000 to an american organization funded by taxpayer dollars?) or E2E encryption that makes it they can't give data.
Another thing about the $1000 fee, is you get to see the payment information about the account it comes from, and you can further require it comes from a government account which matches the requesting organization. Thanks to governments being very gung ho about their financial surveillance infrastructure being a hard requirement for almost everything now.
No?
Anecdotally, from what we are reading today, a typical EDR response time is on the order of an hour. So while someone on my team is gathering the requested data, someone else is doing the verification.
> Sounds like you’re just repeating the point that authenticating these requests is impossible, as that authentication would have to happen fast.
If anything, I'm implying that if the government mandates that EDRs exist, they should have to back it up with someone to handle authentication. A phone number at the state level would do the trick.
> And then you need to do this internationally. What will you do?
First I'd have to be convinced why I should do this in every jurisdiction, why that jurisdiction would have access to customer data from other jurisdictions, etc.
Sounds like you're saying the problem is that the government is mandating things and providing no rules about how it should work. That seems like such an un-government-like thing to do, they usually get weirdly specific.
The whole point is that verification will take much longer than hours.
> Sounds like you're saying the problem is that the government is mandating things and providing no rules about how it should work. That seems like such an un-government-like thing to do, they usually get weirdly specific.
The government is very specific when it comes to what is required of you. The government is not very specific when it comes to what is required of the government.
How can it take longer than hours to reach the actual police department in $someSmallTown, USA ?
$Deity forbid you actually happen to live in $someSmallTown and need the police in a hurry...
Really?
I'm struggling to get my head around how a tiny and/or part-time police force should be the (sole?) point of contact for an emergency data request when <drum roll> they're not even there for the majority of every 24h cycle.
"Dear $TelCo, you must immediately release location data for subscriber 1-800-555-2368, it's so important and urgent we haven't got time to find a judge. Since it's almost 4pm we're going off duty now and will be at our desks from 9am tomorrow. Yours, $PartTimeForce"
Q: Is government mandating this? At what level?
...and if so, why?
Alternatively, it's possible that understaffed and overworked providers are more concerned about their company looking bad when "Missing Child X with schoolbag containing cellphone" isn't located before the next news cycle?
Doesn't due process exist for a reason? Even if that's occasionally a PITA for the authorities?
I mean I want to call some entity in the US that doesn't have its number on a website, how do I do that now in a non emergency situation? Is there any reason that wouldn't work in an emergency?
This doesn't seem like an actual problem anyone has ever had.
Not that the inability to confirm a phone number in a hypothetical phone book would be an excuse for noncompliance anyway.
This was the question I responded to. I'm not sure how else to explain it?
Ah yeah, because fake subpoenas didn’t work before the internet existed?
> I do not believe that those channels for government no longer exist. If they choose to make themselves impossible to locate offline, this is on them.
Who says they ever existed? Back in the pre-internet days the situation was just worse.
Even the federal government can’t manage this, just look at misissuances of .gov domain names.
Back in the NES days Tengen called the United States Copyright Office and told them they needed the technical details of the NES lockout chip to defend themselves in a copyright lawsuit. The Copyright Office faxed over the requested information. Except it was social engineering, there was no copyright lawsuit. Tengen used that proprietary information to build their own cartridges without paying the NES licences costs.
(Sorry to have to ask) but are there [m]any towns in the USA without telephones?
There are towns in the US where the local government consists only of a couple of people who may only do local government work for a few hours a week.
There are towns with essentially no online presence, you could easily create your own fake local government, police and whatever you’d like.
How does anyone authenticate anything allegedly issued by such small parts of local government?
"Not very quickly" is presumably one part of the answer?
It’s actually a pretty novel idea that companies should be prepared to deal with fake court orders, etc. In theory it’s supposed to be the job of law enforcement to prevent this, but of course that is also essentially impossible.
If the federal lawmakers wanted the federal government to undertake the herculean task of making all these documents verifiable and traceable, they could of course do that. Are they likely to do so? No.
Also, there’s an important detail that is largely being ignored in this conversation: How many hours of paralegal time can we expect companies to spend verifying legal requests concerning accounts that don’t belong to paying customers?
So if a stranger in a suit were to turn up on your doorstep with a "search warrant" to search your house, issued by a court/judge/jurisdiction you'd never heard of, you'd not attempt to authenticate it?
> verifying legal requests
I'm not sure that these EDRs as described can be said to be "legal requests".
Aren't they just asking for disclosure of data without the usual legal checks and balances?
Most people would not, no. I’ve had a search warrant served on my home once by police in civilian clothes, they handed me a piece of paper and refused to give ID even though I insisted.
What are you going to do? Physically fight them? Bad idea.
> I'm not sure that these EDRs as described can be said to be "legal requests".
The thing is that real search warrants or court orders do not provide any additional security over these EDRs when the submitting party is not acting in good faith.
I'm not sure what you're saying there, can you expand on this? Are you saying a fake search warrant or fake court order is no more secure than a fake EDR?
My point is that the EDR system (if we can even call it a system) appears designed to avoid any and all scrutiny, verification or legal process. "We need this in a hurry, lives are on the line, we haven't got time to get a court order" doesn't exactly invite the recipient to understand that they have every right to say no.
EDRs are basically backdooring an otherwise fairly well-understood system with checks and balances.
I guess I don't see the value the town government contact details is providing here. If you have some way of figuring out the real contact details for every town why wouldn't that same mechanism work for figuring out the real contact details of every police department?
Turns out the government actually has no duty to convince you, locking you up tends to be convincing enough.
Look, if you want to preserve your rights you've gotta stand up for them.
> Look, if you want to preserve your rights you've gotta stand up for them.
You have absolutely no such right to refuse to comply with subpoenas, search warrants or court orders not delivered via your preferred means.
> Expecting them to show up in person in some capacity and show you the paperwork is fully reasonable
It’s not reasonable, because actual judges will not partake in such games. They will just hold you in contempt.
It might sound reasonable to a layman, but your lawyer will think you’ve gone crazy.
I'm willing to agree the law is crap and you might go to jail (briefly) anyway, but that's not an excuse for "it should work this way" which is the direction everyone seems to be taking it.
> but that's not an excuse for "it should work this way" which is the direction everyone seems to be taking it.
I see many people arguing that the recipients should solve this problem by doing better verification, I don’t think that’s reasonable.
This is absolutely something that the lawmakers need to fix, but that will be a herculean task.
You still have the issue of vetting each police station, but you can do that once before the EDR comes in. Then when the EDR comes in, you call that number, confirm the details.
It can still be hacked, but not nearly as easily as a random officer's email account.
SO - move the power to make such requests up to (say) State Police departments, or even somewhere in the DHS. Those guys have (or should have) sufficient resources to secure their e-mail, staff call-back phone lines 24/7, etc. And in the other direction, they should be far better able to vet alleged local police officers who contact them with emergency requests.
Then if the people processing these requests don't follow that process, then that is a different problem. But as it stands now, those people can follow the process to the letter and we still get the wrong outcome.
It's honestly pretty stupid that email is being used for this instead of having a secure portal which could include things like RSA hard tokens, or even just passwords with 2FA would be a step up. Nothing is fool proof, but this sort of stuff is common with other sensitive information like finance.
I’m pretty sure the largest deployed PKI system is the US federal government’s - it really feels like we should be able to deploy something for law enforcement agencies. (And in fact that’s what the legislation mentioned at the end of the article appears to do.)
That’s a smart card, containing a certificate that can be used to sign email, be used as a client cert for web access, etc.
Now, it has moved the problem to some extent, in that now you have to secure the CA that’s issuing these certs.
Granted, you only need to compromise a RAPIDs office to issue yourself a CAC, but that is still offline and on military installations (though often much less secure reserve/guard installations).
If they did something similar for law enforcement, it would probably have the same sort of restrictions: you need to authenticate to get a credential, but to authenticate you need a credential. So you need to steal one to issue yourself one.
Sorry for the somewhat off-message thought, but perhaps this kind of thing is actually more secure if you _don't_ attempt to automate it?
Maybe the person receiving the request should actually go and look up the phone number of the police department or court who allegedly issued it/approved it, and then call that number (note: not the number mentioned on the request itself).
Surely if that was the SOP, this kind of stuff would just stop?
There's a huge number of systems across the US. I am assuming that a centralized system would provide better security overall compared to the many small and often neglected local systems. This would also standardize the process, reducing the possibility of some locales practice insecure processes.
Back in the day we had things called "telephone directories" (I'm showing my age somewhat)
Is it beyond the wit of man to have the CIA/FBI/NSA/$TLA publish a "list of places to phone" when you receive an Emergency Data Request?
If the source isn't on the list, you can ignore it. If it is on the list, phone the number on the list to verify it?
This really isn't rocket science. At least not for those of use who grew up in an age where you could step into a phone box and open up a printed directory and look up someone's phone number...
Q: Would one expect police departments to be the kind of places which would change their main telephone number regularly?
Consumers change providers often. Institutions? Maybe not so much. (As an aside, I've just checked, and my old university's phone number is exactly the same as it was 30-odd years ago when I enrolled).
To be frank, I'd prefer a printed version for something like this. Harder to hack a directory that's hard copy and whose entries really ought not to be changing very often. If ever.
Phreaks often dumpster dove for this info.
How does it not change often? There are constantly new departments starting, departments/precincts merging, and departments shutting down.
For the telephone number of their local police department? Is it supposed to be secret? My point is that it should be public!
> How does it not change often? There are constantly new departments starting, departments/precincts merging, and departments shutting down
There is simply no reason for a newly-started/merged police department to be able to unilaterally issue an Emergency Data Request, and I say this as a father of three young kids.
For $deity's sake, some new and/or newly-merged and/or micro police force must surely have their local, regional and national-level police forces on speed dial on all their phones. If someone is missing and needs to be found quickly, all they need to do is pick up the phone and reach out to "higher authority" (who can be quickly authenticated, because they definitely have been around for decades), not start acting like the local heroes.
This isn't a technical problem, folks :(
If I have a list of all the agency numbers, then I can look for organizations that disbanded and use those numbers. Since they could still exist in the book (because it wasn't updated instantly), the other party could think you're legitimate.
"There is simply no reason for a newly-started/merged police department to be able to unilaterally issue an Emergency Data Request, and I say this as a father of three young kids."
How so? For the first year of existence they can't issue anything because they have to wait for the next book to be publish. That's sounds dumb. There's no reason they shouldn't be able to issue anything they have the lawful authority to do so. Have any support/logic for your claim that they have no reason?
"some new and/or newly-merged and/or micro police force must surely have their local, regional and national-level police forces on speed dial on all their phones. If someone is missing and needs to be found quickly, all they need to do is pick up the phone and reach out to "higher authority" (who can be quickly authenticated, because they definitely have been around for decades), not start acting like the local heroes."
Um... so how does this higher level authority authenticate this lower level authority if they aren't in the book we are using for authentication? In some cases, jurisdiction can get in the way of the scenario you just described. And again, how long are you going to prevent a department from doing what they are lawfully allowed to do?
"This isn't a technical problem, folks"
Ok, then how do you solve the authentication issues in my previous comment? So far your system hasn't addressed them.
It's not even that we are old enough to have experienced looking up a number in a phone book and some people here are to young to have that experience. The obvious solution to this seemingly unsolvable problem is to print some numbers on a piece of paper and post it to each company you want to get data from in the future.
The problem is indeed unsolvable by the recipients.
It is a public perception thing. The companies (probably rightly) think the public will react badly to headlines about "Little kidnapped girl could have been saved by Google, but they didn't care" more so than the current article we are discussing.
I don't want my conversations to be "cross-platform compatible" with Facebook. Thank you very much.
There's too many (US) law enforcement bodies to make a centralised system work, as you'd need to get a certificate authority managing every individual officer's status for every one of these (small and large) agencies, and handle onboarding and offboarding.
In other countries there are more formal structures for these request through verifiable channels, with standard operating procedures in place.
The question is whether the companies are adopting a lowest common denominator model (a false but assumed valid US request can request any user's data) or not, as that might start to make it a more global concern, and get it on European data protection regulators' radars.
Could you explain what you mean, or give some examples?
Key distribution has always been the weak point of PGP.
Being able to read back a code to validate the contact is all that is enough. It doesn't even have been complicated.
If they can't be bothered to answer the phone then it's not important.
Think about it, how do you validate any court order? Why is this only a problem now? I think it's beacuse they want to side step the judicial oversight process. Keep that intact, as the constitution requires, and this issue disappears.
As for how you validate court orders now? You largely don't. That's why it's possible to use fake court orders to take down true but unpleasant information: https://www.cnet.com/news/privacy/forged-court-papers-are-be...
Local police departments don't need the ability to engage a global surveillance apperatus at the drop of a hat. Stuff like that can be ran up the chain first.
You will be in trouble if you ignore a real warrant on this basis.
Your lawyers will probably tell you that it’s better to just take the risk of possibly complying with a fake warrant.
This is not a legal requirement. If you fail to comply with a legitimate request because you couldn’t verify the number, you go to jail.
So no, I can’t point you to such an incident. Have people been held in contempt for failing to comply fast enough? for sure.
Ah yeah, I think you are totally right. Our disagreement stems from the fact that I don’t believe that few hours is sufficient at all.
Let's stick to reality, folks.
If you have ever received a demand from a court that you couldn't verify the authenticity of, I'd like to hear from you.
They're also "we think this kid is selling marijuana" cases. Law enforcement doesn't even need a warrant, they can just send a request for data and every company will just rubber stamp it and give them whatever they want.
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
Please, post about legal issues only if you know what you are talking about.
Even more fun would be the process of jurisdictional verification. All of which I'm sure the "Officers" would be more than happy to leave you be with your electronics and whatnot long enough to verify, right?
Longer I'm alive, the more insane our system seems to me on a daily basis. Not sure if it's just cognitive decline or rapidly amplified cynicism as I dig into the signalling nightmare that is the interface between the executive and the judiciary system.
Name one court that signs warrants to service providers that can't be verified by spending 5 minutes doing some basic research, or that has a LEO office serving such warrants that also can't be verified.
The topic at hand isn't whether a lawyer or a court officer can, but whether EVERYONE can in a timely manner such that if a police officer or LEO (or someone impersonating one, since we're talking zero trust) can be told to go sod themselves by a layman.
Fundamentally this is a signal/info propagation problem. Processes take time.
I don't. Hell, even if I had a lawyer on hand, I doubt the lawyer would go "hold up.. checking the registries, yup it's legit"; rather they'd tell you to cooperate then maybe challenge outcomes down the road when the paperwork catches up.
For most, the answer is they take it on faith anyone usurping that authority would have such a shit ton of bricks dropped on them, no one would be stupid enough to do it. Obviously, that logic is showing it's age.
Frankly, if I were the courts/LE and found out this was going on, there'd be a new Public Enemy #1. Trust is too important.
Not saying it can't happen or won't happen, but a criminal has to be seriously determined and ready to risk a long prison sentence to fake a warrant.
But then, even if they're not overtly breaking the law with a simple request for information, debt collectors and car warranty salesman are notorious for sending letters that will imply they are your financial institution, the letter was sent by your account manager, etc. IRS impersonators will tell people that jail time is imminent. I can imagine someone could create something that looks to a non-lawyer (who's afraid and not paying attention) like it's basically warrant signed by someone who's basically a judge, but just doesn't outright say that. You'd still need to verify - hey is this person actually a judge, and did this person actually sign that as a warrant?
The problem here is that companies have a policy of trusting some government email address for little one-off, no warrant needed requests. Don't have that policy.
The problem is that it might not be easy to verify a real warrant, but that’s not grounds for noncompliance.
Ok. Now how do I verify one, assuming the information in this article is accurate?
You should not rely on any information on the document you want to verify - look it up yourself.
“Forged court orders, usually involving copy-and-pasted signatures of judges, have been used to authorize illegal wiretaps and fraudulently take down legitimate reviews and websites by those seeking to conceal negative information and past crimes,” the lawmakers said in a statement introducing their bill.
The Digital Authenticity for Court Orders Act would require federal, state and tribal courts to use a digital signature for orders authorizing surveillance, domain seizures and removal of online content.
So yes, people are faking court documents.
Do people honestly think that's a deterrent for people already committing felonies?
It seems like such a trivial problem from a technology point of view, it makes me believe it’s mostly an organizational problem.
This seems like one of those issues that is solved only when someone is murdered and a law is written after their name.
8<--------------------------------------------
The current situation with fraudulent EDRs illustrates the dangers of relying solely on email to process legal requests for highly sensitive subscriber data. In July 2021, a bipartisan group of U.S. senators introduced new legislation to combat the growing use of counterfeit court orders by scammers and criminals. The bill calls for funding for state and tribal courts to adopt widely available digital signature technology that meets standards developed by the National Institute of Standards and Technology.
“Forged court orders, usually involving copy-and-pasted signatures of judges, have been used to authorize illegal wiretaps and fraudulently take down legitimate reviews and websites by those seeking to conceal negative information and past crimes,” the lawmakers said in a statement introducing their bill.
The Digital Authenticity for Court Orders Act would require federal, state and tribal courts to use a digital signature for orders authorizing surveillance, domain seizures and removal of online content.
8<--------------------------------------------
The current situation with fraudulent EDRs illustrates the dangers of relying solely on email to process legal requests for highly sensitive subscriber data. In July 2021, a bipartisan group of U.S. senators introduced new legislation to combat the growing use of counterfeit court orders by scammers and criminals. The bill calls for funding for state and tribal courts to adopt widely available digital signature technology that meets standards developed by the National Institute of Standards and Technology.
- FBI is CA?
-- Issues hardware PKI to local departments
--- Only PKI-signed EDRs are processed without manual phone verification
It’s not unfixable. It’s broken by design.
If it's that important, then you need to design a safer system and pay the cost of doing so.
Anything else is leaving the front door wide open for hackers.
Others have brought up problems with this but another one is that companies get paid by police agencies to provide these data in response to records requests, they are incentivized to not rate-limit these responses.
Most people don’t realize how boring cyber prevention often is.
Very effective and simple solution.
Ah, very simple then: Ignore such demands for as long as you can, then, if approached by actual law enforcement, tell them you were told such messages are phishing attempts from hackers.
It does seem like AT&T, for example, just sends the records (late) without any sort of verification.
The “secure line” can be just a phone call to police department and ask for officer with badge number xyz.
E: lots of police websites on .com as well, so you can't even depend on .gov.
https://duckduckgo.com/?q=site%3A.com+police+department&t=fp...
Cant LEO get things in front of judges in hours? Is bypassing courts ever actually necessary?
It sounds like there isn't even a well-defined policy for who is authorized.
That said, do you have a source?
https://www.themarshallproject.org/2022/01/12/as-murders-spi...
I imagine the picture is a lot more complex than the charts make it out to be. For example, I'd be curious about rate trendlines of false imprisonment.
just the effort companies made to support the requests allow for shenanigans.
if you cant take over the account - you request it be deleted, then remake the account with the username/email desired.
I don't store your IP or SSN. I store the Md5 hash of it.
If the bit-space is easily enumerable, it is just as bad...
but is it?
I think more people who build systems that will be used by 3rd parties at scale should be aware of this.
Unfortunately, it seems the Venture Capitalist drive to Grow First means we keep ending up with large systems with terrible moderation.
It would be such a "two steps forward, one step back"-move if it doesn't.
A valid warrant would include the intended judge and be signed by the department and the issuing officer before going to the judge, then signed by that judge’s cert to be authorized.
This attack vector from the article? Unheard of clownery.
You don't have security, just a police-state, and to add insult to injury besides having less freedom now you also have less security too.
And yes, let's pretend that only China, Iran and Russia are police states, let's keep singing star spangled banner while we happily slip through this slope towards the gulags.
You had a point until "gulags." You honestly think we're on the verge of becoming a Stalinist state that imprisons and murders political dissidents by the millions?
Maybe that's a tad alarmist?
Source?
Personally, if we survived the 60’s/70’s, I think we can survive this. They literally murdered college students in front of the world.
I’m also not sure how any of this translates into Stalin-era gulags. People throw that term around too lightly, like “nazi.” If you’ve actually studied any Russian/Soviet history you should know how insane those were, even for an era with rampant fascism.
It seems in vogue to use words without understanding the actual meanings. Most people haven't read history and speak, loudly, of that which they don't know.
My parents were activists in the 60s, and my grandparents were activists in the 20s & 30s. My parents mostly feared being beaten, with a background fear of being shot at. My grandparents feared being disappeared along with retribution to their extended family, friends, and neighborhoods.
The advent of increased population, social media, technology, and major american hyper polarization make the current times very different than the 60s/70s.
Let's stop with the both sides are the same bit, m'kay? Plenty to criticize on the left but please stick to facts.
And as far as Civil War goes, I'd posit that it's already begun.
If a civil war has “already begun,” I guess I live somewhere else, because I don’t hear any gun shots. Frankly it feels a lot calmer around here than it did a year or two ago.
A key change this time is not to split apart, but to simply grab all the marbles and declare the game to be over. I wish I could be sanguine about this and would love to be proven wrong, but it's looking grim.
Saying 'this is what we call hyperbole' seems to imply, 'my ideas stand so well on their own, I don't need to respond to your criticism; the problem is not with my ideas or how I've expressed them, it is with your inability to recognize a particular rhetorical device.' Which is both patronizing and wrong. Your use of hyperbole was recognized and is being interrogated.
You're under no obligation to respond to that challenge, no one here has a right to your time, but if you're going to, it would be more productive for everyone if you did so in good faith.
Well. now this is a strawman.
Words have meanings, and using the words inaccurate/the wrong meanings is saying one thing but meaning another, and the word for that is lying.
What was the civil war about? States rights. What rights, specifically? The right of states to allow their citizens to practice slavery. Therefore, the civil war was about slavery.
What was jan 6 about? It was about an attempt to undermine the government. An attempt to undermine what, specifically? The election process. Why did they seek to undermine the election process? So that the mob could extra-judicially install a leader of their preference. Another word for this is coup d'etat.
AFAIK, in common use the word coup involves the military taking control of the government.
That is one common kind of coup, but distinguished from the broader category. That's why the phrase “military coup” exists to distinguish the kind of coup where the military (or some part of it) is the main actor in seizing control outside of normal bounds.
> The sudden overthrow of a government by a usually small group of persons in or previously in positions of authority.
Or to use Wikipedia’s definition
> A coup d'état (French for "blow of state"), often shortened to coup in English (also known as an overthrow), is a seizure and removal of a government and its powers. Typically, it is an illegal seizure of power by a political faction, rebel group, military, or a dictator. Many scholars consider a coup successful when the usurpers seize and hold power for at least seven days.
Yes, the military can be involved in a coup, but the essential definition does not require their involvement. Different terms might be applied if the military is involved, and based on whether or not the military is the primary driver (as in Myanmar) or is backing one side.
Jan 6th was about a small number of ignorant people who bought into a bunch of lies. A protest that got out of control. One that was far, far less violent, with far fewer casualties than dozens of protests that happened around the country the prior year. All mobs are bad, all riots are bad. Unfortunately different partisans have been trying to blow up the implications of one riot while downplaying all the others.
Yet the GOP is sidelining and smearing the few among them who actually want to hold the insurrectionists accountable.
If they were able to successfully break into that room while Congress was still in there, what do you think would’ve happened? They would’ve invited them over for tea?
I don’t like engaging in speculation but I think it’s pretty obvious we would’ve had more casualties.
And stuff is still coming out about Trump. A mysterious seven hour gap in the White House communications logs. A Federal judge ruling that it's "more likely than not" that Trump "corruptly attempted to obstruct Congress" attempting to overturn the election results. He called it a "coup in search of a legal theory." Yes, that's not "beyond a reasonable doubt," but it's also not nothing.
You're right that it was far less violent, and had far fewer casualties, but it wasn't just a riot, nor were there just a small number of ignorant people involved. To think that at this point, or to dismiss all concerns as partisan hyperbole, is kind of ridiculous.
No, attempted coup (specifically, attempted self-coup) is much more accurate.
> Words have meanings
Yes, they do. And the precise political science terms for the coordinated attempts by the 45th President and his allies to extend his powers beyond their lawful duration by extralegal means is “self-coup” or “auto-coup” (in the original French, “autogolpe”), which is a form of coup carried out by or on behalf of the existing leader.
> and using the words inaccurate/the wrong meanings is saying one thing but meaning another, and the word for that is lying.
Yes, that is exactly what you are doing when you explicitly refuse to use the correct term in attempt to minimize the act.
"New information has emerged regarding the death of the Capitol Police officer Brian Sicknick that questions the initial cause of his death provided by officials close to the Capitol Police."
Wikipedia says
"The cause of Sicknick's death was first thought to be from injuries, but months later the medical examiner reported there were none."
"The District of Columbia chief medical examiner found that Sicknick had died from stroke, classifying his death as natural"
The original commenter said some officer was beaten to death. Maybe another officer, or were they just mistaken?
There is no such implication at all. "Without weapons" means "without weapons". The vast majority of people at that riot were gun owners, and none of them were armed or fired a shot. I can assure you, people who own guns and are committed to violently overthrowing the government bring those guns and shoot them. For evidence see any of the numerous coups that occur in countries around the world.
Do you acknowledge it was violent?
Not single LEO was beaten to death on Jan 6th. You are literally spreading misinformation and fake news lol. SCP Officer Brian Sicknick died after having two strokes aka natural causes.
Oh come now. "Hang Mike Pence." "Stop the steal." The former president calling election officials telling them to "find the votes." I don't care what your politics are, what we saw this last election was like nothing we've ever seen before in this country. It was a failed attempt to overturn a democratic election on the basis of a lie.
> a sudden and decisive action in politics, especially one resulting in a change of government illegally or by force.
So, I stand corrected. It does meet the definition of "attempted coup".
I'm pretty sure the police could get away with murdering political rivals right now. But a few key court decisions are all we need to formalize that capability for the next 100 or so years.
https://www.military.com/daily-news/2022/03/13/classified-us...
The American prisons are not full of thought criminals just because you are being denied all the footage and proof of the violent crimes the people in US prisons commit, constantly. I realize that most people live in a negative bubble, where they have no idea what is happening because the truth has been withheld from them, but that does not change the reality most people are at least unwittingly ignorant of.
But yes, the gulag system actually already exists in America, and the political prisoners in the USA right now already know that. Assange is also in that gulag system and can probably be considered the first, Prisoner #1 of the American Empire’s Gulag Equivalent System, even though it is on foreign soil.
Police across the country are letting criminals run rampant due to fear of prosecution for doing their job.
Police are "letting criminals run rampant" because they throw tantrums the moment money or accountability is discussed. Just watch how they behave the moment a city even whispers "pension" despite the fact that police pensions are crushing city budgets across the nation.
https://www.bridgemi.com/michigan-government/pension-costs-b...
https://www.reuters.com/article/us-usa-pensions-policeandfir...
What? I see no-one throwing 'tantrums' in the articles you linked. I see some people trying to keep the pensions they have earned. Do you expect ordinary Americans to jump to take a pension cut after working all their lives?
And this in the hope that magically that money will go to the right places and reduce crime?
We have conservatives non-stop calling for “reduced spending” and “tightening the belt” who are all too happy to cut everything they feel “their people” don’t need, but the big ticket items - military, pensions, etc. - are arbitrarily sacrosanct. Well, it’s not actually arbitrary. It’s because they want to hurt “the right people.”
Reduced spending will never be fair to the people on the receiving end.
Not only did a sitting President betray people and killed millions with anti-masker/anti-vaccine rhetoric, he did so to aid a foreign country that is known for murdering political dissidents, and did so during WW2, during the Cold War, and the post-Soviet era that exists today; but also our Congress, most of those still occupying those seats today, aided and abetted him. What Trump and his Congress did is terrorism without being formally charged with it, and is hardly any different than the pre-Stalin era of Soviet Russia and the pre-Kristallnacht era of the Nazi occupation of Germany.
So, please, I'd like you to tell me why you think people shouldn't be seriously alarmed? You sound like all the deniers in the history books: "Oh, the Nazis wouldn't kill Jews and political dissidents", "Oh, Stalin wouldn't (also) kill Jews and political dissidents", "Oh, Chairman Mao wouldn't just starve tens of millions to gratify his own ego". People keep saying this, it keeps not being true.
History is a goddamned broken record.
You shouldn’t let your personal animosity towards Trump lead to believing misinformation.
Mueller finds no collusion with Russia, leaves obstruction question open
https://www.americanbar.org/news/abanews/aba-news-archives/2...
You should take this opportunity to consider what other things you know to be true about Trump may also be misinformation.
The Washington Post corrects, removes parts of two stories regarding the Steele dossier
https://www.washingtonpost.com/lifestyle/style/media-washing...
The entire Trump Russia gate was to divert attention from what Hillary / Biden were doing.
Oh a laptop was found with solid evidence showing collusion between the Bidens and various countries. Well naturally the same response is to sensor anyone that wants to talk about it and to impeach Trump.
https://legalinsurrection.com/2022/03/mainstream-media-outle...
I don't have to. I witnessed several Republican congressmembers go out of their way to announce that no matter what evidence presented is, they had already decided to ignore it and vote against the removal of Trump from office.
Now, I can't tell you why they decided to announce their criminal enterprise shortly before enacting it, but a quick Google tells me their names are Cindy Hyde-Smith, Roger Wicker, Thom Tillis, Rob Portman, James Inhofe, Mike Rounds, and Jerry Moran.
> Mueller finds no collusion with Russia, leaves obstruction question open
https://en.wikipedia.org/wiki/Mueller_report is a well cited article.
"On March 27, 2019, Mueller reportedly wrote to Barr in a letter, as stated in the New York Times "expressing his and his team's concerns that the attorney general had inadequately portrayed their conclusions".[226] This was first reported on April 30, 2019. Mueller thought that the Barr letter "did not fully capture the context, nature, and substance" of the findings of the special counsel investigation that he led.[227] "There is now public confusion about critical aspects of the results of our investigation". Mueller also requested Barr release the Mueller report's introductions and executive summaries.[228][229]"
What you linked to covers Barr's misleading summary of the Muller report.
> The Washington Post corrects, removes parts of two stories regarding the Steele dossier
Again, Wikipedia has a well cited article on the subject: https://en.wikipedia.org/wiki/Steele_dossier
Also, it is funny how when it comes to politics Republicans have moved so far right that now center-right is considered the left party.
Also, some Republicans have moved far right. Some Democrats have moved pretty far left, too. I will admit that more Republicans moved than Democrats. But both parties have sections near the center, and both have extreme parts. And both are having trouble maintaining unity in the face of that tension.
Many Democrats also decided to join the Putin-backed coup attempt, and also voted to not impeach during one or both trials. Many Democrats also tried to claim Hunter Biden, while working for a natural gas company in Ukraine, somehow was up to something and using his dad's appointment as VP for something.
Funny how Biden became President, and now Russia is invading Ukraine to maintain their stranglehold on Europe's energy supply, and all the pro-Russian bot accounts on Twitter and Facebook that were repeating the "Hunter's Laptop" and "But Her Emails" stories to divide and conquer, suddenly vanished.
I am a socialist, and what both parties do is disgusting, and, honestly, anti-American. Our government has been rapidly degrading my entire lifetime, and the only reasonable action is to ring the alarm bell and hope other people wake up and start fighting the fascism that is threatening to destroy our nation.
It's not "funny." It makes complete sense. Services for .ru accounts are being suspended around the world.
But I'm vexed that it's not even possible to talk about these things here in a policy and goals context because the fucking tribalism is out of control. I can haz such disappoint.
Moreover, the left has moved further left than the right has moved right. https://jabberwocking.com/if-you-hate-the-culture-wars-blame...
The tribalism of politics is fierce, and even a forum with as much collective intelligence as HN is not immune from that force.
We should be able to discuss policy and actions on their own merits without it being taken as a personal affront. I wish I could find the magical incantation that would allow that dialog to manifest.
[1] https://covid.cdc.gov/covid-data-tracker/#datatracker-home
Source on these influential media personalities? I assume they're not fringe in any way, since you called them "influential".
Wildly different death tolls though. Our best estimate is that the gulag system had an 8.88% death rate, with that varying wildly on a year by year basis. Meanwhile the US prison system as of 2018 kills 344 per 100,000, or .344%. But unfortunately those numbers are getting worse, not better. I think the difference here is less about our system being more humane, and more the fact that food and antibiotics are cheap. Heck, just look at how the prison system responded to covid.
I honestly think we’re a lot closer to a gulag system than people think. We’ve already built the majority of the machinery to actually implement such a system, and politically making the system harsher and less humane is very popular. There is also a bipartisan consensus that what we need is to fund the system even more. All that we’re missing is the jump to directly imprisoning political opponents, and we’ve already seen some calls for that although it isn’t quite mainstream yet.
What do you know about the gulag system? Serious question, not baiting or anything. What are the broad strokes of what you understand to be "The Gulags"? Because like you, I am VERY concerned with the US penal system, but to compare the two is...a stretch for me.
All or nothing nihilism, that makes no major distinction between the US & china, Russia and Iran is also a road to totalitarian hell. It's a favoured rhetoric style if Putin and many reactionary extremists.
If only I could have seen this last week. L'horreur! L'horreur!
... ignoring those double impersonation swatting problems, enforcement against crimes online is really hard due to global scope. Police won't even investigate because all they find is that the hacker was some russian and they can't do anything about it.