The only thing that's "unfixable" about this is that it's not something you can automate. You need an actual human being to perform the verification step(s).
The only thing that's "unfixable" about this is that it's not something you can automate. You need an actual human being to perform the verification step(s).
Being able to read back a code to validate the contact is all that is enough. It doesn't even have been complicated.
If they can't be bothered to answer the phone then it's not important.
Think about it, how do you validate any court order? Why is this only a problem now? I think it's beacuse they want to side step the judicial oversight process. Keep that intact, as the constitution requires, and this issue disappears.
As for how you validate court orders now? You largely don't. That's why it's possible to use fake court orders to take down true but unpleasant information: https://www.cnet.com/news/privacy/forged-court-papers-are-be...
Local police departments don't need the ability to engage a global surveillance apperatus at the drop of a hat. Stuff like that can be ran up the chain first.
You will be in trouble if you ignore a real warrant on this basis.
Your lawyers will probably tell you that it’s better to just take the risk of possibly complying with a fake warrant.
This is not a legal requirement. If you fail to comply with a legitimate request because you couldn’t verify the number, you go to jail.
So no, I can’t point you to such an incident. Have people been held in contempt for failing to comply fast enough? for sure.
Ah yeah, I think you are totally right. Our disagreement stems from the fact that I don’t believe that few hours is sufficient at all.
Let's stick to reality, folks.
If you have ever received a demand from a court that you couldn't verify the authenticity of, I'd like to hear from you.
They're also "we think this kid is selling marijuana" cases. Law enforcement doesn't even need a warrant, they can just send a request for data and every company will just rubber stamp it and give them whatever they want.
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
Please, post about legal issues only if you know what you are talking about.
Even more fun would be the process of jurisdictional verification. All of which I'm sure the "Officers" would be more than happy to leave you be with your electronics and whatnot long enough to verify, right?
Longer I'm alive, the more insane our system seems to me on a daily basis. Not sure if it's just cognitive decline or rapidly amplified cynicism as I dig into the signalling nightmare that is the interface between the executive and the judiciary system.
Name one court that signs warrants to service providers that can't be verified by spending 5 minutes doing some basic research, or that has a LEO office serving such warrants that also can't be verified.
The topic at hand isn't whether a lawyer or a court officer can, but whether EVERYONE can in a timely manner such that if a police officer or LEO (or someone impersonating one, since we're talking zero trust) can be told to go sod themselves by a layman.
Fundamentally this is a signal/info propagation problem. Processes take time.
I don't. Hell, even if I had a lawyer on hand, I doubt the lawyer would go "hold up.. checking the registries, yup it's legit"; rather they'd tell you to cooperate then maybe challenge outcomes down the road when the paperwork catches up.
For most, the answer is they take it on faith anyone usurping that authority would have such a shit ton of bricks dropped on them, no one would be stupid enough to do it. Obviously, that logic is showing it's age.
Frankly, if I were the courts/LE and found out this was going on, there'd be a new Public Enemy #1. Trust is too important.
Not saying it can't happen or won't happen, but a criminal has to be seriously determined and ready to risk a long prison sentence to fake a warrant.
But then, even if they're not overtly breaking the law with a simple request for information, debt collectors and car warranty salesman are notorious for sending letters that will imply they are your financial institution, the letter was sent by your account manager, etc. IRS impersonators will tell people that jail time is imminent. I can imagine someone could create something that looks to a non-lawyer (who's afraid and not paying attention) like it's basically warrant signed by someone who's basically a judge, but just doesn't outright say that. You'd still need to verify - hey is this person actually a judge, and did this person actually sign that as a warrant?
The problem here is that companies have a policy of trusting some government email address for little one-off, no warrant needed requests. Don't have that policy.
The problem is that it might not be easy to verify a real warrant, but that’s not grounds for noncompliance.
Ok. Now how do I verify one, assuming the information in this article is accurate?
You should not rely on any information on the document you want to verify - look it up yourself.
“Forged court orders, usually involving copy-and-pasted signatures of judges, have been used to authorize illegal wiretaps and fraudulently take down legitimate reviews and websites by those seeking to conceal negative information and past crimes,” the lawmakers said in a statement introducing their bill.
The Digital Authenticity for Court Orders Act would require federal, state and tribal courts to use a digital signature for orders authorizing surveillance, domain seizures and removal of online content.
So yes, people are faking court documents.
Do people honestly think that's a deterrent for people already committing felonies?
It seems like such a trivial problem from a technology point of view, it makes me believe it’s mostly an organizational problem.
This seems like one of those issues that is solved only when someone is murdered and a law is written after their name.
8<--------------------------------------------
The current situation with fraudulent EDRs illustrates the dangers of relying solely on email to process legal requests for highly sensitive subscriber data. In July 2021, a bipartisan group of U.S. senators introduced new legislation to combat the growing use of counterfeit court orders by scammers and criminals. The bill calls for funding for state and tribal courts to adopt widely available digital signature technology that meets standards developed by the National Institute of Standards and Technology.
“Forged court orders, usually involving copy-and-pasted signatures of judges, have been used to authorize illegal wiretaps and fraudulently take down legitimate reviews and websites by those seeking to conceal negative information and past crimes,” the lawmakers said in a statement introducing their bill.
The Digital Authenticity for Court Orders Act would require federal, state and tribal courts to use a digital signature for orders authorizing surveillance, domain seizures and removal of online content.
8<--------------------------------------------
The current situation with fraudulent EDRs illustrates the dangers of relying solely on email to process legal requests for highly sensitive subscriber data. In July 2021, a bipartisan group of U.S. senators introduced new legislation to combat the growing use of counterfeit court orders by scammers and criminals. The bill calls for funding for state and tribal courts to adopt widely available digital signature technology that meets standards developed by the National Institute of Standards and Technology.
It's honestly pretty stupid that email is being used for this instead of having a secure portal which could include things like RSA hard tokens, or even just passwords with 2FA would be a step up. Nothing is fool proof, but this sort of stuff is common with other sensitive information like finance.
I’m pretty sure the largest deployed PKI system is the US federal government’s - it really feels like we should be able to deploy something for law enforcement agencies. (And in fact that’s what the legislation mentioned at the end of the article appears to do.)
That’s a smart card, containing a certificate that can be used to sign email, be used as a client cert for web access, etc.
Now, it has moved the problem to some extent, in that now you have to secure the CA that’s issuing these certs.
Granted, you only need to compromise a RAPIDs office to issue yourself a CAC, but that is still offline and on military installations (though often much less secure reserve/guard installations).
If they did something similar for law enforcement, it would probably have the same sort of restrictions: you need to authenticate to get a credential, but to authenticate you need a credential. So you need to steal one to issue yourself one.
Sorry for the somewhat off-message thought, but perhaps this kind of thing is actually more secure if you _don't_ attempt to automate it?
Maybe the person receiving the request should actually go and look up the phone number of the police department or court who allegedly issued it/approved it, and then call that number (note: not the number mentioned on the request itself).
Surely if that was the SOP, this kind of stuff would just stop?
There's a huge number of systems across the US. I am assuming that a centralized system would provide better security overall compared to the many small and often neglected local systems. This would also standardize the process, reducing the possibility of some locales practice insecure processes.
Back in the day we had things called "telephone directories" (I'm showing my age somewhat)
Is it beyond the wit of man to have the CIA/FBI/NSA/$TLA publish a "list of places to phone" when you receive an Emergency Data Request?
If the source isn't on the list, you can ignore it. If it is on the list, phone the number on the list to verify it?
This really isn't rocket science. At least not for those of use who grew up in an age where you could step into a phone box and open up a printed directory and look up someone's phone number...
Q: Would one expect police departments to be the kind of places which would change their main telephone number regularly?
Consumers change providers often. Institutions? Maybe not so much. (As an aside, I've just checked, and my old university's phone number is exactly the same as it was 30-odd years ago when I enrolled).
To be frank, I'd prefer a printed version for something like this. Harder to hack a directory that's hard copy and whose entries really ought not to be changing very often. If ever.
Phreaks often dumpster dove for this info.
How does it not change often? There are constantly new departments starting, departments/precincts merging, and departments shutting down.
For the telephone number of their local police department? Is it supposed to be secret? My point is that it should be public!
> How does it not change often? There are constantly new departments starting, departments/precincts merging, and departments shutting down
There is simply no reason for a newly-started/merged police department to be able to unilaterally issue an Emergency Data Request, and I say this as a father of three young kids.
For $deity's sake, some new and/or newly-merged and/or micro police force must surely have their local, regional and national-level police forces on speed dial on all their phones. If someone is missing and needs to be found quickly, all they need to do is pick up the phone and reach out to "higher authority" (who can be quickly authenticated, because they definitely have been around for decades), not start acting like the local heroes.
This isn't a technical problem, folks :(
If I have a list of all the agency numbers, then I can look for organizations that disbanded and use those numbers. Since they could still exist in the book (because it wasn't updated instantly), the other party could think you're legitimate.
"There is simply no reason for a newly-started/merged police department to be able to unilaterally issue an Emergency Data Request, and I say this as a father of three young kids."
How so? For the first year of existence they can't issue anything because they have to wait for the next book to be publish. That's sounds dumb. There's no reason they shouldn't be able to issue anything they have the lawful authority to do so. Have any support/logic for your claim that they have no reason?
"some new and/or newly-merged and/or micro police force must surely have their local, regional and national-level police forces on speed dial on all their phones. If someone is missing and needs to be found quickly, all they need to do is pick up the phone and reach out to "higher authority" (who can be quickly authenticated, because they definitely have been around for decades), not start acting like the local heroes."
Um... so how does this higher level authority authenticate this lower level authority if they aren't in the book we are using for authentication? In some cases, jurisdiction can get in the way of the scenario you just described. And again, how long are you going to prevent a department from doing what they are lawfully allowed to do?
"This isn't a technical problem, folks"
Ok, then how do you solve the authentication issues in my previous comment? So far your system hasn't addressed them.
It's not even that we are old enough to have experienced looking up a number in a phone book and some people here are to young to have that experience. The obvious solution to this seemingly unsolvable problem is to print some numbers on a piece of paper and post it to each company you want to get data from in the future.
The problem is indeed unsolvable by the recipients.
Then if the people processing these requests don't follow that process, then that is a different problem. But as it stands now, those people can follow the process to the letter and we still get the wrong outcome.
Very effective and simple solution.
You still have the issue of vetting each police station, but you can do that once before the EDR comes in. Then when the EDR comes in, you call that number, confirm the details.
It can still be hacked, but not nearly as easily as a random officer's email account.
SO - move the power to make such requests up to (say) State Police departments, or even somewhere in the DHS. Those guys have (or should have) sufficient resources to secure their e-mail, staff call-back phone lines 24/7, etc. And in the other direction, they should be far better able to vet alleged local police officers who contact them with emergency requests.
It is a public perception thing. The companies (probably rightly) think the public will react badly to headlines about "Little kidnapped girl could have been saved by Google, but they didn't care" more so than the current article we are discussing.
I don't want my conversations to be "cross-platform compatible" with Facebook. Thank you very much.
Others have brought up problems with this but another one is that companies get paid by police agencies to provide these data in response to records requests, they are incentivized to not rate-limit these responses.
Most people don’t realize how boring cyber prevention often is.
- FBI is CA?
-- Issues hardware PKI to local departments
--- Only PKI-signed EDRs are processed without manual phone verification
It’s also trivial to create a fake police department in some small town, set up google maps entry etc…
What then? What about when you operate internationally and have to accept requests from 100+ jurisdictions?
Contact the state government to ask? There’s a good chance nobody will be able to provide the answers you seek on short notice.
Not going to work internationally anyway.
You are engaging in bad faith, please stop it.
It’s not even about being a “devils advocate”, the balance of probabilities rests squarely on the side of this being far more difficult than many commenters here try to make it out to be.
I think it is you who is engaging in bad faith.
Sounds like you’re just repeating the point that authenticating these requests is impossible, as that authentication would have to happen fast.
And then you need to do this internationally. What will you do? Contact the embassy? Suddenly your authentication process could take months, which is a problem if you’re legally required to comply sooner than that.
Who said that?
Worst case scenario is probably a horrible PR disaster after a child dies because you couldn’t process a real request fast enough.
And we’re not talking about seconds, but easily days or weeks.
It is literally impossible for request recipients to solve this problem.
This I agree with. I'm trying to find the actual text of the law, I'm surprised the government isn't pretty specific about what constitutes a valid EDR, who can send them, etc. Bureaucrats love to write rules.
The end solution is either an authentication scheme, a $1000 rush processing fee that includes a verification process and the requirement to call it in (It is an emergency, isn't it? Emergencies do not happen often, so what is $1000 to an american organization funded by taxpayer dollars?) or E2E encryption that makes it they can't give data.
Another thing about the $1000 fee, is you get to see the payment information about the account it comes from, and you can further require it comes from a government account which matches the requesting organization. Thanks to governments being very gung ho about their financial surveillance infrastructure being a hard requirement for almost everything now.
No?
Anecdotally, from what we are reading today, a typical EDR response time is on the order of an hour. So while someone on my team is gathering the requested data, someone else is doing the verification.
> Sounds like you’re just repeating the point that authenticating these requests is impossible, as that authentication would have to happen fast.
If anything, I'm implying that if the government mandates that EDRs exist, they should have to back it up with someone to handle authentication. A phone number at the state level would do the trick.
> And then you need to do this internationally. What will you do?
First I'd have to be convinced why I should do this in every jurisdiction, why that jurisdiction would have access to customer data from other jurisdictions, etc.
Sounds like you're saying the problem is that the government is mandating things and providing no rules about how it should work. That seems like such an un-government-like thing to do, they usually get weirdly specific.
The whole point is that verification will take much longer than hours.
> Sounds like you're saying the problem is that the government is mandating things and providing no rules about how it should work. That seems like such an un-government-like thing to do, they usually get weirdly specific.
The government is very specific when it comes to what is required of you. The government is not very specific when it comes to what is required of the government.
How can it take longer than hours to reach the actual police department in $someSmallTown, USA ?
$Deity forbid you actually happen to live in $someSmallTown and need the police in a hurry...
Really?
I'm struggling to get my head around how a tiny and/or part-time police force should be the (sole?) point of contact for an emergency data request when <drum roll> they're not even there for the majority of every 24h cycle.
"Dear $TelCo, you must immediately release location data for subscriber 1-800-555-2368, it's so important and urgent we haven't got time to find a judge. Since it's almost 4pm we're going off duty now and will be at our desks from 9am tomorrow. Yours, $PartTimeForce"
Q: Is government mandating this? At what level?
...and if so, why?
Alternatively, it's possible that understaffed and overworked providers are more concerned about their company looking bad when "Missing Child X with schoolbag containing cellphone" isn't located before the next news cycle?
Doesn't due process exist for a reason? Even if that's occasionally a PITA for the authorities?
I mean I want to call some entity in the US that doesn't have its number on a website, how do I do that now in a non emergency situation? Is there any reason that wouldn't work in an emergency?
This doesn't seem like an actual problem anyone has ever had.
Not that the inability to confirm a phone number in a hypothetical phone book would be an excuse for noncompliance anyway.
This was the question I responded to. I'm not sure how else to explain it?
Ah yeah, because fake subpoenas didn’t work before the internet existed?
> I do not believe that those channels for government no longer exist. If they choose to make themselves impossible to locate offline, this is on them.
Who says they ever existed? Back in the pre-internet days the situation was just worse.
Even the federal government can’t manage this, just look at misissuances of .gov domain names.
Back in the NES days Tengen called the United States Copyright Office and told them they needed the technical details of the NES lockout chip to defend themselves in a copyright lawsuit. The Copyright Office faxed over the requested information. Except it was social engineering, there was no copyright lawsuit. Tengen used that proprietary information to build their own cartridges without paying the NES licences costs.
(Sorry to have to ask) but are there [m]any towns in the USA without telephones?
There are towns in the US where the local government consists only of a couple of people who may only do local government work for a few hours a week.
There are towns with essentially no online presence, you could easily create your own fake local government, police and whatever you’d like.
How does anyone authenticate anything allegedly issued by such small parts of local government?
"Not very quickly" is presumably one part of the answer?
It’s actually a pretty novel idea that companies should be prepared to deal with fake court orders, etc. In theory it’s supposed to be the job of law enforcement to prevent this, but of course that is also essentially impossible.
If the federal lawmakers wanted the federal government to undertake the herculean task of making all these documents verifiable and traceable, they could of course do that. Are they likely to do so? No.
Also, there’s an important detail that is largely being ignored in this conversation: How many hours of paralegal time can we expect companies to spend verifying legal requests concerning accounts that don’t belong to paying customers?
So if a stranger in a suit were to turn up on your doorstep with a "search warrant" to search your house, issued by a court/judge/jurisdiction you'd never heard of, you'd not attempt to authenticate it?
> verifying legal requests
I'm not sure that these EDRs as described can be said to be "legal requests".
Aren't they just asking for disclosure of data without the usual legal checks and balances?
Most people would not, no. I’ve had a search warrant served on my home once by police in civilian clothes, they handed me a piece of paper and refused to give ID even though I insisted.
What are you going to do? Physically fight them? Bad idea.
> I'm not sure that these EDRs as described can be said to be "legal requests".
The thing is that real search warrants or court orders do not provide any additional security over these EDRs when the submitting party is not acting in good faith.
I'm not sure what you're saying there, can you expand on this? Are you saying a fake search warrant or fake court order is no more secure than a fake EDR?
My point is that the EDR system (if we can even call it a system) appears designed to avoid any and all scrutiny, verification or legal process. "We need this in a hurry, lives are on the line, we haven't got time to get a court order" doesn't exactly invite the recipient to understand that they have every right to say no.
EDRs are basically backdooring an otherwise fairly well-understood system with checks and balances.
I guess I don't see the value the town government contact details is providing here. If you have some way of figuring out the real contact details for every town why wouldn't that same mechanism work for figuring out the real contact details of every police department?
Turns out the government actually has no duty to convince you, locking you up tends to be convincing enough.
Look, if you want to preserve your rights you've gotta stand up for them.
> Look, if you want to preserve your rights you've gotta stand up for them.
You have absolutely no such right to refuse to comply with subpoenas, search warrants or court orders not delivered via your preferred means.
> Expecting them to show up in person in some capacity and show you the paperwork is fully reasonable
It’s not reasonable, because actual judges will not partake in such games. They will just hold you in contempt.
It might sound reasonable to a layman, but your lawyer will think you’ve gone crazy.
I'm willing to agree the law is crap and you might go to jail (briefly) anyway, but that's not an excuse for "it should work this way" which is the direction everyone seems to be taking it.
> but that's not an excuse for "it should work this way" which is the direction everyone seems to be taking it.
I see many people arguing that the recipients should solve this problem by doing better verification, I don’t think that’s reasonable.
This is absolutely something that the lawmakers need to fix, but that will be a herculean task.
There's too many (US) law enforcement bodies to make a centralised system work, as you'd need to get a certificate authority managing every individual officer's status for every one of these (small and large) agencies, and handle onboarding and offboarding.
In other countries there are more formal structures for these request through verifiable channels, with standard operating procedures in place.
The question is whether the companies are adopting a lowest common denominator model (a false but assumed valid US request can request any user's data) or not, as that might start to make it a more global concern, and get it on European data protection regulators' radars.
Could you explain what you mean, or give some examples?
Key distribution has always been the weak point of PGP.
It’s not unfixable. It’s broken by design.
If it's that important, then you need to design a safer system and pay the cost of doing so.
Anything else is leaving the front door wide open for hackers.