Fake emergency search warrants draw scrutiny from Capitol Hill
krebsonsecurity.com
krebsonsecurity.com
This really isn't a reasonable expectation. There are only so many judges, and being on-call 24/7 for all emergencies is not part of their job description, and it probably should not be, either. They need clarity of mind when they're making decisions, not to be in a sleepy mood. Moreover, you seem to be proposing a solution in search of a problem. There isn't widespread abuse of this by cops in the US (that I've heard of, anyway) to justify upending an otherwise effective procedure.
There's massive abuse of police power to get access to data that would normally require a warrant. The only reason EDRs aren't abused more often is because it's often easier for cops to use more "straightforward" approaches like threatening the person/organization they want to get the data from, or lying (or misrepresenting) in order to get the other party to "voluntarily" give up the information.
Nobody said anything about "police power" in the general case. The discussion here is about EDRs, which you yourself acknowledge aren't abused frequently. Therefore it follows that making EDRs harder would not really solve that problem. You'd need to make other avenues for getting people's data more difficult before you contemplate changing this one.
One anecdote: a friend moved into a new neighborhood, a gated community. One evening when walking the dogs, a neighbor who is a cop greeted her by her full legal name. She said she never uses her middle name anywhere. As far as we know, there is no way the cop could know her middle name without looking her up. Who in any social situation greets someone by their full legal name (and that too without ever being introduced)?
As far as she can tell this was their way of telling her that the officer knows who she is, knows where she lives, and is watching her. Who does that?
- In my county (and every other county I've looked into in the US) real estate transactions and deed recordings are public record, available online, and sometimes include the purchaser's middle name.
- If it's a gated community, it almost certainly has a HOA, which would have an application/notification process (probably including ID info, potentially including a background/credit check) to feed information to the HOA board (which cops, being local government-oriented people, might be inclined to be involved with).
As to "who does that"...police officers. Always.
Occam's razor - when your friend moved into this gated community, it is almost certain they had to provide some background information, including name to the gated community. Might even had some contractual requirements that needed background checks. This person maybe just looked at the monthly flyer that was stuffed under every owners' door "please welcome Jimmy John Joe Smith living in 123 Fancy St." ...
Do you have a source for this? I just went to check T-Mobile for example and their site says they got 164k of them in 2020. [1] That's about 450/day, and it's just one company.
[1] https://www.t-mobile.com/news/_admin/uploads/2021/07/2020-Tr...
> any police jurisdiction can use an EDR to request immediate access to data without a warrant, provided the law enforcement entity attests that the request is related to an urgent matter of life and death.
I disagree. That sentence is unambiguous. Either that sentence is blatantly incorrect or an EDR does imply life or death. The two possibilities are mutually exclusive.
Counting homicides only gives you the "death" part of "life or death".
It's so funny that you are using the word "proof" without using any logic or reasoning, but just talking out of your head -- "that number seems too large, so it must be wrong"!
My state is only 10% of the population, so it's down to 45 a day. But it's still a lot.
They probably already do. Most jurisdictions have rotating pager duty. The on call judge is called the duty judge.
Imagine a discussion between cops and judges about secure software engineering without anyone knowing what a pointer is. That’s what legal discussions on HN are like.
Now you could try to argue the scale is actually smaller than I expect, and I'd love to see numbers to that effect, but the numbers I've seen so far don't suggest that.
I guess you could always send someone to the courthouse in person, but that seems prohibitively expensive.
And anyway, how much money can we expect e.g. Google to spend verifying court orders targeting users on free plans?
You don't pay money to enter Walmart but they are required to spend as much money as it takes to ensure you don't die in a fire while giving them zero dollars. Likewise food safety standards required by law aren't a sliding scale based on income. The relevant factor isn't how much money you made off the mark its how much harm your behavior can cause to that person.
If you put yourself in possession where your failure causes them greater harm you bought yourself a potentially expensive obligation that you wouldn't have for example if you just served search engine results based on search query or ads served without knowing the persons life story and the contents of their diary since the 3rd grade.
The actual answer is however much it takes to do a reasonable job or we ought to just fine you so much per screw up that you are forced to go sell shoes instead of search engine results.
The government can and should help make this procedure reasonable as it is 99% of the problem. Such orders ought to be cryptographic signed by hardware tokens that are physically in the judges possession on a device that isn't online THEN emailed to google. This relies purely on 1970s technology and probably should have been implemented about 20 years ago if we weren't collectively complete morons.
While this is implemented just coming from judges official government emails as opposed to their personal emails or a billion idiot cops would be substantially more secure.
Part of the problem is, because any cop can send an emergency request, in California there are 93,000 cop e-mail accounts, every one of which has to be protected from hacking.
By creating a bottleneck of, say, 10 judges per state who can issue emergency warrants (generously paid to staff a 24/7 rota) there are only 10 people whose e-mail accounts have to be kept 100% secure.
I dunno, how about all of it?
Maybe start with a few billion and then reevaluate how everyone feels about it.
I bet those aren't the only two options though.
Somebody notices my car parked there with the whiteboard laying on the dash saying "Griffith Shadow 3/24". Any responsible hiker seeing that is going to call it in.
The search and rescue team will look at that whiteboard and note the label tape at the bottom with various bits of information. It should be obvious that I'm inviting search and rescue to use the information printed there, why should a judge be involved?
(And the S&R guys will know it's probably serious--from reading that board they know I should have been able to call for help.)
For the same reason you still need to enter a sudo password when you use sudo for a trivial self-evident thing: It is not the trivial self evident thing we want to prevent, but the difference between a cop tracking the ex they are stalking and that missing person is literally just their no own judgement.
Trusting cops not to abuse a certain power is bad when you can just implement a little systemic friction that prevents large scale abuse.
Sure the NYPD, FBI, etc. are going to (theoretically) have top security, but if any LEO anywhere in the country is good enough, just hack some podunk PD that exists solely to generate ticket revenue and has no IT department, no 2FA, no security training.
https://krebsonsecurity.com/2022/03/hackers-gaining-power-of... ( https://news.ycombinator.com/item?id=30842757 )
> Providers have a streamlined process where they publish the fax or contact information for police to get emergency access to data. But there’s no real mechanism defined by most Internet service providers or tech companies to test the validity of a search warrant or subpoena. And so as long as it looks right, they’ll comply
The bad actors are explicitly exploiting an emergency provision intended for quick information return to prevent serious harm/death using verified police accounts they've compromised.
You either end up with the headline we have here or "Apple's failure to comply with an emergency request led to the death of X"
I don't know what the right policy is, but this is just a tradeoff without an easy answer.
For all of the box ticking, theatrical diligence and audit-preparedness work I’ve had assigned to me in my Devops career, and bespoke security “services” and “products” out there that merely exist to enable more box ticking in the name of “security and compliance”, I think maybe we should start.
The threat actor could compromise the website just as they did for the email, Or create a legitimate looking fake one, not every department has one or is indexed well
Tech support staff handling these requests cannot possibly know the thousands of police departments sites to know if the site is legitimate.
There is simply no single national authoritative source for validation ( international is even more complex with different laws and languages)
Yes, the police web site is another point of vulnerability. But with any luck you can reliably find the area code for Podunk, then call directory assistance in that area code to ask for the police department number. So the crooks would have to compromise that too.
You know who probably would be in a better position to know? Your corporate counsel. Chances are pretty high they not only know who to contact, they probably have additional contacts that your 'tech support' staff do not in the nearby agencies and beyond, not to mention having the actual knowledge on the response mechanisms that said agency requires for compliance with requests for corporate data.
Which forces me to ask this question: I understand that as technologists we probably have an abundance of confidence in the knowledge and skills we possess in our domain, so why are tech support staff even 'handling' legal requests at all?
The only "handling" they should be doing is "handing" whatever evidence or materials that have been requested directly to the company's legal counsel, who should have been the party liaising with the 'requestor'.
Also in my experience counsel who practice civil and corporate law have very little experience with law enforcement. Companies don't generally keep lawyers who practice criminal law inhouse .
To an extent, yes as a matter of fact, or at minimum a Registered Agent. Because in almost all of those 200 Jurisdictions, for a majority of business types (including Corporations) a Registered Agent is required by law for exactly this purpose: to receive and help your company properly respond to legal requests.
https://www.upcounsel.com/registered-agent
Similarly, an Authorized Agent for your business is empowered to respond to such inquiries
Also having an general counsel for your place of business, is not same as having an firm 24/7 on call.
So I’m not sure what is being rebutted here.
https://www.thedailybeast.com/feds-say-bounty-hunter-matthew...
Turns out the war on drugs was a war against the People.
What happens if the police abuses this system (and not the hackers)... does anyone get notified that "p.o. John Doe requested your data on 1. 1. 2022"? And why not? If it's a life or death situation, and you're still alive, you'll either be thankful they used the data to save you, or your laywer could get a lot happier, because you'd be suing them, because they faked such a situation.
https://calmatters.org/justice/2021/01/justice-courts-overwh...
https://legal.thomsonreuters.com/en/insights/articles/backlo...
https://www.dcreport.org/2022/01/12/theres-a-critical-shorta...
“The system is broke” feels like a poor excuse for arbitrarily handing over all of someone’s data without notification
Does this happen often? Most stops tell the story of the officer having probable cause for a search, even if that's just the smell of weed or something (not sure if it's still a valid reason).
There’s always a constraint in resources to take cases to trial - for obvious reasons, they are expensive affairs.
A warrant is mostly boilerplate and there’s no shortage of judges to review them.
None.
The problem is esoteric. The minority that misunderstands it as a handout to lawyers [1], too vocal.
Plea deals are the current tool attempting to address that. They take drastically less time and resources. Scholars estimate 90 to 95 percent of cases are resolved via plea deals at this point. It's been going on long enough that I think we've actually adjusted prison sentences to entice it; we have incredibly long prison sentences relative to the rest of the world, to scare people into taking a deal where they serve a more normal numbers of years.
It's not unheard of for innocent people to take a plea to serve 30 days in jail instead of risking trial and serving 4 years or something like that.
If a majority of defendants actually exercised their right to a trial, our judicial system would fall apart. We don't have nearly enough judges, lawyers, or courthouses for that to happen, and it would start triggering 6th Amendment "right to a speedy trial" issues.
I'm of the opinion that the current system of plea deals is unconstitutional, because it establishes a penalty for exercising 6th Amendment rights to a trial. If the plea deal is 60 days in jail, or they're going to go to trial and recommend the maximum, we are coercing people into not exercising their rights. If the court believes that 60 days is a reasonable sentence for the crime, it shouldn't matter whether guilt is established via a plea deal or trial.
> And, are these massive backlogs concentrated in certain areas (bigger cities?) or are they pretty evenly dispersed?
I can't seem to find any readily available data on that, it's an interesting question. I did read that basically everyone had issues during COVID because courts were closed, and a lot of charges were dropped because they couldn't be handled quickly enough to satisfy the right to a speedy trial.
I'd love to see data if anyone knows where to get it online.
Every MoC has some responsibility to a geographic constituency, and some topical specialization through committee assignments... Geography can create /some/ specialization through electoral incentives, but mostly in rural and resource extracting districts... (Such as Manchin and the coal industry... sigh.)
Plurinominal representatives are also a counter balance to gerrymandering tendencies.
The prospect if using certificate signed email is an unrealistic tech-nerd dream, the average rural law enforcement personal can barely use Word and has poor or no on-site IT staff. If it is harder to use than Gmail, you may have well forget it.
Could a centralized portal get hacked? Absolutely. But the security spend can be significantly higher, and entirely fictional police departments almost entirely eliminated.
This is exactly the way locals use things like codis.
Maybe this should be a sign that they have no business requesting sensitive information be transferred to their poorly secured computers?
If you let them use insecure computers as endpoints it seems like that there will inevitably continue to be data leaks -- regardless of what sort of security you put on the portal(s) that they use their insecure computers to access. I don't see that a national portal fixes this.
Perhaps a national IT-department that controls all the computers involved would work, though I can only imagine what a nightmare setting that up would be.
Still scary that information is given to LEOs without a proper warrant. I think in these emergency cases should notify the individual(s) their information is accessed/requested via quasi-legal channels. This would allow users to take proactive measures as well.
In order to open one of those email accounts you need to give full details using Italian digital identity (SPID). It is also possible to forge a SPID, but that's even more complicated.
So, to sum up, it's quite an antifragile system. Relatively simple, widely adopted and secure enough.
It's a social engineering attack that has worked 2ezily since 2007.
Similar to SWATting, but essentially in reverse.
Also abusable are the new GDPR requests. Compliance is pretty much at odds with security of the account itself. Complying with the inane EU rules basically makes your system at risk at trivial account takeover, which juxtapositionally/ironically then make it easier to leverage a person.
It's like 2FA over SMS....you are basically at the mercy of a Verizon/ATT employee.
Stop trusting humans, make systems that humans cannot make unilateral decisions without a reasonable amount of redtape.
How? Seems to me that if they're storing (and handing over) data that allows trivial account takeover, they have a broken security process to begin with.