Amazon Ring cameras used in nationwide ‘swatting’ spree, US Justice Dept. says
bloomberg.com
bloomberg.com
Tech enthusiasts: My entire house is smart.
Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don't recognize.
The only modification i'd recommend is replacing the gun with something simpler, like a sledgehammer. Can't be too careful.The conventional light switches never fail. The dimmer switches go out every 5 years or so, and I eventually get fed up and just replace them with a conventional switch.
I've had programmable thermostats, but the user interfaces on them are so terrible I eventually replace them with one with a simple dial and thermostat.
Before that I will have turned on a dim salt lamp in our bedroom with a small butten I have near the bed, as to not wake my gf. I turn it off with the wall switch while leaving the room.
The light in the hallway is dim because it is still early. Since he didn't poop I only need a dim light in the changing area operated by my foot.
Various lights in the house turn on automatically by movement or door opening. Lights near the front door go on dinly just before subset and get brighter with movement. The wall switch in the kitchen turns on multiple lights including cabinet downlighting.
These things and more, and the fact I can change them relatively easily and wihtout rewiring, I find convenient and that brings me value.
You don't have to understand though, we both can like different things.
The ones I use are made by Lutron, who has a long history of making conventional light switches. They act just like normal switches, and I could sell my house without the home automation system, and it would be perfectly functional for the new owner.
Having carefully designs home automation brings lots of little conveniences. When I walk into a room when it is dark, the light automatically turns on. When it becomes cloudy during the day, lights in the darker living areas turn on. When I go to bed, I press one button, and all the lights in the house turn off, and the motion sensors are disabled. Another button press in the morning re-enables the sensors and turns on the lights in all the "morning activity" areas of the house.
Bottom line is that I seldom have to press a light switch. I always automagically have light when and where I need it.
I just don't think of it as a burden. I don't think about it at all. My hand goes up to the switch.
I know I don't think about it, because when the power goes out my hand still automatically turns the switch on, even when I'm carrying a lamp. There's a second where I blink wonderering why the light didn't go on.
I have some 1-watt LED lights plugged in and on all the time, so I don't fall down the stairs. I figure the 1 watt is less than the power draw of motion detectors, etc.
Lolz aside, as an engineer, the main turnoff for me is not the privacy, though that is a concern, but the introduction of complexity. I like my house like I like my software: clean and minimalistic :)
I am fed up with phone apps already because of that, nearly no month or several week goes by without one warning me: UPDATE! NOW!
And then when you update its behaviour is altered, many times functionalities you liked are gone. The whole thing is more like a nuisance than genuine help.
Exposing myself potentially to the same kind of problems concerning my whole home?! No thank you!
(recently, after long deliberation and consultation with my keen wife, I gave up the idea of robotic vacums. some are excluded due to shameless price or physical configuration, but many due to the inability to operate without a phone app. i will do my vacuuming without connecting to home wifi, thanks)
It doesn't matter if it's the best vacuum or the most secure vacuum or even the cheapest, for us it matters if it actually gets used and thus the floors are cleaner.
Same reason I've come to like our stick vacuum: we're far more likely to use it than other vacuums that are technically better but are heavier/louder/more difficult to store/etc.
I have also used them to relocate a switch to a more useful place for much cheaper/in a rental. (Automatic switch in the out of reach or inconvenient location, battery switch in reach of where I want it).
Smart lights and outlets are the only smart thing in my home and they really are great imho
It was sorta a pain to set up, over half a decade ago, now it’s small tweaks now and then but otherwise just works.
Smarthomes are currently better at monitoring than they are at control, there's just not that much that needs real automation
Security.
> unless you think a burglar is obsessed with your house in particular
IMO burglars are obsessed with an easy score - "Lights on looks like someone is home - fuck it I will rob the empty looking house up the street"
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux...
Until someone hacks the fire extinguisher and makes it spray chemicals at you. Then you'll need to add a smart fire extinguisher extinguisher.
https://en.wikipedia.org/wiki/Radar_detector_detector
where someone asserted that there was a radar detector detector detector (so that you could tell if authorities were positioned to detect your use of a radar detector).
Some versions of this hoax are described in
https://rationalconspiracy.com/2016/06/02/radar-detector-det...
> Tech Enthusiasts: Everything in my house is wired to the Internet of Things! I control it all from my smartphone! My smart-house is bluetooth enabled and I can give it voice commands via alexa! I love the future!
> Programmers / Engineers: The most recent piece of technology I own is a printer from 2004 and I keep a loaded gun ready to shoot it if it ever makes an unexpected noise.
> Security technicians: takes a deep swig of whiskey I wish I had been born in the neolithic.
No idea where the original version came from, but here's one from ~1.5 years prior to @PPathole's tweet:
https://notcaycepollard.tumblr.com/post/167952829352/tech-en...
I do have an enterprise grade network, next gen firewall, a homelab, and a host of vlans with home automation segmented off to a dedicated network with zero internet access
"no self respecting tech worker". But yeah, have fun with your enterprise grade network. Hyperbole much?
and yes I have great fun with it.
To give one trivial example: if you're selling vinyl records on Discogs, you need to print the mailing address to put it on the package.
(OK you probably wouldn't, but you can)
I'm really hoping they come out with some kind of A4 size color thermal printer for all these one off use cases.
It's just paper with chemicals on it, it probably shouldn't be more than 20 cents a page or so if it were scaled up to be the dominant type of home printing.
"Everyone should be paperless" -- either you live in a country with a unusually advanced, tech-minded government, or you're just completely out of touch with a normal person's needs in a place like the US.
A lot of "smart" devices can be used without giving them access to the world.
Just. don't. give. them. your. password.
> I do have an enterprise grade network, next gen firewall, a homelab, and a host of vlans with home automation segmented off to a dedicated network with zero internet access
You're not a typical tech worker.
Big communities exist online for it now, but a majority of the young professionals we interview have AV/IT racks at home, usually outfitted with a 3D printer or two on top. Whether it's for their home theaters, their video work, or some general labbing or engineering, they're proud of them, and it doesn't hurt to demonstrate investment into their interests and working knowledge.
It might not be typical of coders who favor high mobility or other software-only roles like application support and front end, or it might just be regional since we're in a tech and research hub surrounded by colo facilities and data centers, but it's kind of funny how naked and vulnerable people look when they come in with just a MacBook loaded with their livelihoods.
These days I only buy local-network-only devices (mostly Z-Wave) that I connect to a RaspberryPi-based hub, running software I control, with a remote-access component that I control (and secure) as well. At least if someone gets into my smart devices from the outside, I have no one to blame but myself.
Unfortunately, this sort of setup is just complicated enough to set up and manage that it's beyond most non-technical (or even moderately-technical) people. I really wish it was easier and more accessible.
(I've been on twitter too long and it's given me a sixth sense for detecting clout chasers who just repost others' jokes or make incredibly low-effort tweets.)
https://michaelblume.tumblr.com/post/169525456166/tech-enthu...
Oh wait..maybe this one copied it from this other one in 2017?
https://notcaycepollard.tumblr.com/post/167952829352/tech-en...
We need a "git blame" for the web? :-)
But I don't recommend any of it to anyone who doesn't want to make a serious hobby about of it.
Just to expand, it’s a scale ;) It’s very easy to have a few lights, maybe some presence detection and motion sensors, and make some automation for those without venturing into hobby territory.
From a tech point of view, first in the medium term I first look forward to the long, long, loooonnnng awaited day when this entire class of attacks finally vanishes along with the madness of shared symmetric authentication in favor of proper public key systems. A solid decade and a half or more after smartcards and browser certs might have made it possible if things had taken a different path, the Passkey/Webauthn/FIDO2 ecosystem finally seems to be hitting the tipping point and accelerating towards critical mass. It shouldn't be necessary for anyone to remember more than one or two decent passwords/PINs, and all the actual unique random key generation should get taken care of automatically and with zero concerns about far side security. All other issues aside, it'll be great when this is just, there, and the entire concept of "default passwords" doesn't exist because to setup an account at all requires initialization with a proper key.
Second though stories like this also to me at least have helped a bit in terms of motivation/justification for taking IOT security seriously and advocating for that to colleagues and family. Like a lot of human<>tech interface stuff sometimes it feels really hard, because the deliverable is mostly "nothing happens". It's hard to prove a negative, and since for now some security efforts require extra money, time, and/or convenience tradeoffs, "is this all really worth it" does come up (and probably always will). And it can also be hard to be sure if what you've done is enough before it gets put to the test. It takes some level of stochastic belief, of "faith" even that yes, security, redundancy, decentralization and backups etc really does matter in the modern world, like it or not.
A certain degree of paranoia isn't unreasonable because a certain percentage of humanity really is out to get us. And the internet means that a tiny percentage can reach out and affect other humans far away.
> A certain degree of paranoia isn't unreasonable because a certain percentage of humanity really is out to get us. And the internet means that a tiny percentage can reach out and affect other humans far away.
It is true that better systems will make rare but terrible incidents less likely, but in this case, better IoT which is easier to secure and remain self-sovereign over actually expands what people are willing to use IoT for. I imagine there are a swath of compelling avenues ready to be developed if not for the warranted hesitancy of anyone managing the security of these systems. Sure, the security now isn't terrible or problematic if used right, but when the security is robust, simple and dead-easy then the innovation up top gets uncapped.
Where N is the number of services the key unlocks, is there a O(1) migration story yet?
I'm not 100% sure I'm interpreting what you meant by this correctly, but if you're saying essentially "is there a single click button that will change all my existing accounts over" the answer is a mixture of "no of course" and "there wouldn't be one answer anyway". I mean, there are still plenty of people who don't even use password managers or have any real formal list of services at all. How would you expect there to be any automated migration there? And even with a password manager it'd still be pretty complex to manage some sort of automated switchover given the diversity of credentials and back ends (remember we're not just dealing with websites), even beyond user interaction being required for each use of many hardware key systems (which is indeed good security practice).
However I don't think that matters much having already been through a service migration ages ago with the rise of password managers themselves (and being a fairly early adopter). What happened there (or for email migrations for that matter) was a basic piecemeal/spread-it-out approach. A handful of critical services got changed right away, and then over time I switched others from using old bad passwords of a small set to being listed/managed by password manager(s) whenever I accessed them. The most frequently accessed happened the quickest, others eventually, and I made some systematic effort to get some of the long tail I cared about while just abandoning a few of the very oldest.
As it becomes more universal and everyone gets comfortable with it being battle tested, kinks worked out, rich ecosystems etc, I suspect we'll then start to see sites actively prompting/requiring people to add or switch, which will then happen naturally in the course of normal usage. I currently have almost 1000 items in my password manager (though granted not all of them are passwords) which is intimidating on the face of it, but previous experience tells me it won't actually be a big deal. A few dozen already have keys registered, and over time that will naturally increase as services/systems add support. Well before this time in 2032 I expect everything to be switched that's still actively maintained. Even IRC allowed moving to using client certs instead of passwords a while ago!
One definition (there are many) of assault is as follows: "... the intentional application of force upon another person, directly or indirectly, without the other person’s consent. Classified as a criminal act, it can and will be tried in court."
WEAPONS ACT 1990 - SECT 78 Weapons not to be discharged or operated - a fine- but also usually, a range of offences related to use, possession, storage of the weapon and ammunition
CRIMINAL CODE 1899 - SECT 69 Going armed so as to cause fear (1) Any person who goes armed in public without lawful occasion in such a manner as to cause fear to any person is guilty of a misdemeanour, and is liable to imprisonment for 2 years.
469 Wilful damage (1) Any person who wilfully and unlawfully destroys or damages any property is guilty of an offence which, unless otherwise stated, is a misdemeanour, and the person is liable, if no other punishment is provided, to imprisonment for 5 years.
Punishment in special cases 1 Destroying or damaging premises by explosion If— (a) the property in question is premises; and (b) the destruction or damage is caused by an explosion; and (c) either— (i) anyone is in or on the premises when the explosion happens; or (ii) the destruction or damage actually endangers anyone’s life; the offender commits a crime. Penalty— Maximum penalty—life imprisonment.
but what you will find is that this sort of activity rarely happens randomly- usually there is a relationship between the victim and the attacker- so something related to stalking, extortion (demanding money with menaces) etc. And those all carry heavy possible penalties. (5 years, 7 years etc)
> Whoever discharges a firearm as defined in section one hundred and twenty-one of chapter one hundred and forty, a rifle or shotgun within five hundred feet of a dwelling or other building in use, except with the consent of the owner or legal occupant thereof, shall be punished by a fine of not less than fifty nor more than one hundred dollars or by imprisonment in a jail or house of correction for not more than three months, or both.
This is the law that would definitely apply. Interestingly, it appears that there is a bill before the state legislature that would cover specifically shooting at a dwelling (with intent to hit it), which would carry 5 years/$10k fine.
Depending on particular fact patterns, it might fall under attempted murder, reckless endangerment, or other charge in a similar vein. This sort of stuff tends to be extremely jursidiction-dependent.
The thing that needs an overhaul is the decision making on when to actually send out the swat team. It's lazy, expensive, and dangerous to send them out for every opportunity without any investigation
I don't like the five-oh but going the route you're proposing will make some instances much worse with avoidable loss of life.
In this case, there is a demonstrated and repeated danger from these swatting attacks. They don't have proper risk management in the police forces of the us, as demonstrated by swatting killing people. The authorities being too slow is not a demonstrated problem, it's the opposite.
If the only information police had was a phone call from an anonymous VOIP number, then they'd be comparable.
[1]https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&c...
Especially the one where cops were already there.
This isn't a giant dial that says "cops go fast" <-> "cops go slow"
The overhaul we need is community oversight, community decision making and community policing.
A record of high profile cases where swatters get caught and incarcerated would be a great deterrent.
Specifically police need to learn about time, distance, and cover. Arrive on the scene and take cover a safe distance away from the perceived threat. Take time to identify the perceived threat and confirm they are really a danger. Only then should they attempt to deal with the threat if it actually proves to be one. This would have saved the life of Tamir Rice, a harmless child who was shot by a police officer who had not even finished stopping his car when he shot and killed the unarmed 12 year old. This would have saved the life of 22 year old John Crawford III who was shot by a police officer at WalMart. Crawford had picked up an un-packaged BB gun and then continued shopping. Someone misunderstood the situation and called the police. When officers arrived they ignored the lack of distress among other customers which should have been present, and fired shots at Crawford almost immediately upon entering the store.
There are many accounts like this. Police behavior leads to many unnecessary deaths and swatting is only a threat because of police failing to assess a situation firsthand.
So I'd guess the answer to your question is something like: for the same reasons that men commit the overwhelming majority of violent crime, which probably has something to do with evolution and testosterone and culture.
https://www.statista.com/statistics/648093/australia-impriso...
Also, it doesn't require a 10 year sentence — it refers to "not more than seven years or fined under this title, or both.". [2] That literally means that no prison time is required. There is a cap on prison time, and it could be completely eliminated if a fine is given instead. Not exactly harsh treatment!
It applies to land in states that is owned by the US government, which can include a lot of land thought of as inside states (national parks and military bases are the goto examples here). If you want real fun, try working out which law applies when you're on tribal land.
It does not matter if you think how is police operate is unreasonable, what matters is that what they do is well known and established, and the outcome is foreseeable.
Also, if your best defense is “this isn’t attempted murder, it’s just terrorism” I have questions.
How can the caller be more culpable than the one actually commiting the crime? This literally never happens in the history of crime.
I mean yes, cops are mostly above the law, and in the US they definitely murder enough (disproportionately PoC) people without consequences to be a problem.
But in this case police are being told their are people with guns threatening to kill people, which is exactly the case where police are ostensibly justified in using force.
Police killing a swatting victim is meaningfully difference from police making up a fake claims to get a warrant, breaking down a door without notice, and then shooting at anyone who moves, or pulling someone over, asking if they have a gun, and then shooting them if they say yes, etc
The SWAT team didn't intend to hurt innocent people. They thought they were saving innocent people. The swatter was intentionally terrorizing innocent people.
What you just said is "if someone falsely accuses another person of a crime, and the police arrest them, then the police are guilty of kidnapping", "if someone falsely reports a house fire and fire fighters break into the house to put it out, they are guilty of breaking and entering", etc.
Emergency services respond to the reported emergency, for SWAT that often involves an immediate threat to people's lives, so they come in with the expectation that they will need to use force. Now the increasing occurrence of swatting means that US swat teams should be aware of the possibility of false call outs, but they have to deal with "is this a case where me turning up results in someone killing their family if I don't stop them immediately, or is it a case where some dude on the internet doesn't like someone else?".
The whole point of a swatting is police are being told that the victim is has a gun and is threatening to kill people, which is effective because you get the same call when there is an actual person with a gun threatening to kill people.
Now US SWAT does have an issue (imo) that goes with US policing in general of putting safety of police/swat above anyone else, which is a real issue, but as everyone knows this it merely adds to the "you knew your actions had a significant likelihood of getting someone killed".
I’m simply pointing to the most similar Federal crimes and pointing out that the sentences are proportional. For comparison, Federal attempted murder-to-hire is only 10 years and that’s clearly a much worse crime.
Tragically there’s now over 1000 cases of swatting per year. Only one person (Andrew Finch) has been killed by police. (The swatter in this case was charged with involuntary manslaughter and got 20 years in jail).
It’s not comparable to murder because it’s much more likely that someone would be killed by you offering them a ride in your car than by swatting them.
My car rides don't come with a 0.1% chance of death. I'm not that bad of a driver.
Let's calculate it. There were 42,915 traffic deaths in the US in 2021.[1]
Americans take 411 billion trips per year.[2]
That's 42915/411000000000 = 0.00001% chance of death per trip. So a driving trip is 10000x safer than being swatted.
[1] https://en.wikipedia.org/wiki/Motor_vehicle_fatality_rate_in...
[2] https://www.bts.gov/statistical-products/surveys/national-ho...
It's an awful problem that will exist as long as people suck.
Right now, you could have extra caution for 911 calls which originate from VoIP. Pass a law that in five years telco CEOs are charged as assisting murder the next time a SWATing happens and they’d magically discover that egress filtering is easy to implement once you’re not looking at the revenue generated by spammers.
Second, you can argue anything will be a slippery slope (you should hear what people say raising the capital gains rate 1% will do) but it’s intellectually dishonest to pretend there’s no distinction between contributing to a violence death and “basically anything”. Operating critical safety infrastructure should carry responsibilities beyond the average business.
using a voice changer is asking for trouble... I would use synthesized speech
Is there a link to this? The government decided that calling another branch of the government for help is so dangerous it is an attempt to murder?
It's one thing that it happens, but the fact that it is being normalised is what's truly repugnant. 'Swatting' someone in Britain does not cause any deaths.
It is only a problem in the US because the response itself is terrifying and often dangerous. Multiple people have died from "swatting" in the US[0].
"Swatting" should carry a jail term for sure. But police reform is a large component in solving the problem (and many other topical problems).
[0] https://en.wikipedia.org/wiki/Swatting#Injuries_or_deaths_du...
https://theweek.com/articles/474702/indiana-law-that-lets-ci...
Edit: wow, just saw this part:
> Why did Indiana push this law? The state Supreme Court had previously ruled that citizens had no legal right to resist police officers, even in a case of unlawful entry
What a crazy ruling. I guess this law is checks and balances in action in two ways...
Now, if you’d really want to dissuade the police from making illegal raids, make them liable for all damages, slap on penalties and put the burden of proof on them. Police entered and cannot prove it was legal? Pay fine, repair damage. At the same time lower the bar for personal liability for the officers: Can’t demonstrate that they did at least the basic due diligence? Pay out of their own pocket.
Why not both?
I don't think it's necessarily wise for a homeowner to open fire when outnumbered like that, but it's their right to make that choice when armed intruders break into their home. (And really without the whole knock, announcement, warrant thing the home owner doesn't know the intruders are police.) Making this clear shouldn't exclude these other excellent ideas.
One challenge is that citizens side with the police in court.
Not all of us.
The overwhelmingly vast majority of "protect yourself from government tyranny" types want to massively curtail police powers.
I find this hard to believe. Back the blue, blue lives matter, thin blue line people are propagated by gun enthusiasts who use nice slogans like “government tyranny” to justify their positions in a shallow and emotional way. There’s no actual belief in government tyranny, otherwise they wouldn’t stand with the law enforcement arm of the government’s elevated agents.
Today the pasta was good.
Amongst the reasons they did, were situations eerily similar to what we call "swatting" (and no-knock warrants), which were some motivations behind the fourth amendment.
An amendment that we have, through twisted legal interpretations and arguments for expediency, managed to largely de-fang (civil forfeiture, I'm looking at you).
Well, that and the French navy.
Specifically, even in 1787 it was seeming likely that there was a good chance that at some point the federal government was going to abolish slavery by force, and the framers of the Constitution needed the southern states on board with the Constitution's stronger central government vs. the Articles of Confederation.
So, they probably intended weapons of some proportionate power compared to contemporary military weapons, but the ultimate underlying motivations are suspect.
On the other hand, I could imagine a world where in 1787 alcohol and/or marijuana were legal in some states and illegal in others and the framers were worried about federal troops imposing national drug policy on drugs that never crossed state lines. In that case, it seems more reasonable, which I guess lends respectability to their reasoning at a medium level of abstraction.
The difference is strong regulations disallowing carrying/transporting loaded weapons and enforcing storage requirements as well as a very different gun culture without the emphasis on handguns for self-protection.
There are also government subsidized shooting ranges that do not require these permits.
> 1.2 guns per citizen
After 1 gun, do guns truly become more dangerous? For someone opening a door, I don't think handgun vs AR vs shotgun is a very meaningful distinction - you're going to die if you get shot in the face
> loaded up to the gills
Isn't it true that one of the top arguments used against gun control that criminals will have the weapons anyways?
Therefore, as a LEO being summoned to a potential crime scene, isn't it true that they would behave in accordance with the person being a potential criminal, and therefore living outside of "guns per citizen" statistics? And therefore isn't the global approach to SWATting likely done without respect to the local environment, but instead in accordance with best practices of deescalation and safety?
I look forward to hearing you expand your thoughts.
As for entering the property, if there’s five people and one gun, that’s a lot different to five people and thirty guns.
44% of US households have at least one firearm in the house.
Not "a small group".
In terms of individuals of all ages, it's 32% of all individuals owning guns -- 45% of all men own a gun but only 19% of all women own a gun.
Therefore the population where it's unusual to own a gun is single women. Single men are also less likely to own a gun than married men.
If we look at those who are married, 52% of all married couples live in a household with guns.
https://news.gallup.com/poll/264932/percentage-americans-own...
32% of US adults say they own a gun. 44% of adults say they live in a house that has at least one gun.
https://news.gallup.com/poll/264932/percentage-americans-own...
However, I agree with your overall sentiment -- the distribution is far from uniform.
Also: 2/3rds of Americans don't own a gun, and only 44% even live in a house with a gun.
Ever notice that only in a very small number of cases does a "swatting" result in any danger to the officers, such as the homeowner shooting an officer? The number of times this has happened is in the single digits. Hint: that's because there's little danger to police responding to these sorts of calls.
In fact, there's very little danger to police officers in the US, period. They have a murder rate lower than the general population, because people know that cops don't give a shit about when you or I are murdered (nation-wide the clearance rate for homicides is abysmal, one of the lowest in the developed world) but if a cop is killed, the killer will be correctly identified, found, and arrested within hours.
Being a cop in the US doesn't even rank in the top ten in terms of deaths on the job. Retail workers and cab drivers have a far higher homicide-on-the-job rate;
Pre-COVID the #1 killer of police, overwhelmingly, was traffic collisions, suicide, and heart disease.
During/after COVID, the #1 killer, despite police getting first-in-line access to the vaccine, was/is COVID. Completely preventable.
The reason these "swattings" are so dangerous is because police show up expecting a dangerous situation, confrontation, even though it's incredibly rare.
Far smaller population than the USA, and loads more variables to consider when comparing the two. But at least one country gets it pretty Damn Right with Guns!
That's because both countries are based on the continued enforcement of white supremacy.
> Keffals was swatted in Canada, and Canada has a far less extreme police and gun culture compared to the USA.
I think it's egregious that she was actually arrested for something that the police should have realized was fake, or simply been able to sort out in-person. However, her claim that she woke up with an assault rifle in her face was simply not true. In the context of American swatting, it's more like swatting-light since Canadian police actually require training and attempt to de-escalate instead of solving every problem with guns.
> Officers did not conduct what is sometimes referred to as a “dynamic entry” into Ms. Sorrenti’s residence. Rather, they knocked on the door, announced themselves as police officers, and occupants answered. Any attempt by uninvolved third parties to suggest otherwise is inaccurate and irresponsible.
https://www.londonpolice.ca/en/news/statement-from-police-ch...
The problem is the swatters know the exact type of call to make to elicit a SWAT response, usually involving someone being held hostage and in imminent danger of being killed. The police can't just assume people making that kind of call are lying, they have to respond as if it's real. It's not a problem of the police just responding to every call like that.
I don't think that's what they're implying at all, given the context is about swatting.
Do police in other countries simply not have the capacity to deal with people in imminent danger? Their response to getting a call claiming that there's a crazy person in the house about to murder the caller is to knock politely and ask questions? Seems more like the police in other countries suck then.
The problem is that swatting is enabled precisely because the police's response isn't appropriate. The fact that swatting is so prominent, let alone an issue in the first place, is a testament to that.
Police forces demonstrably: tend to be hyper-militarized, do not train or require de-escalation, do not face legal repercussions for unlawful actions, do not keep up-to-date with various trends and technology, etc. Going in guns-blazing isn't going to save anyone if you don't validate basic information like "is this the right house?" or "did this call purporting to be from someone in our city come from a random Google Voice or Skype number?" or "have we received fake calls from this address already?"
surprise escalation into an unknown, unverified situation where the only basis for the use of deadly force is whether the police feel there is danger. Of course they are in fear for their lives because they are leaping into the unknown, unprepared.
We hear about the militarization of the police. I hate that term. They are playing soldier, not acting it. Having been in the military, if we had a situation and the time we would monitor a location and find out everything we could. Apparently that wasn't passed along to the police, only the guns were.
Speaking from europe, we just don't have that here, at least not enough to have SWAT forces ready immediately.
I can't think of any times that it was a problem the SWAT team was not ready.
The big difference is, those units in Europe are a professiobally trained force and part of a professionally trained police force. And not somw wannabe commandos recruited from ill-trained police officers run by departments too small to even exist in Europe.
Federal.
SWAT ~= MEK, SEK
FBI HRT ~= GSG-9
That fact that citizens of the US have simply accepted that the latter is even remotely a proper response to even "someone being held hostage and in imminent danger of being killed" calls is both sadden, and maddening at the same time
I’m a member of a minority group that is currently experiencing an uptick in violence from the American public. I’m generally a good-natured person and tend not to make enemies. If someone is in my home with a firearm, they’re there to kill me for my perceived connections to big banking, a rational person does not commit random acts of violence like that.
You do, unintentionally, make a stellar point though. If someone in my part of America called the police because someone was trying to kill me, there will likely not be a police response once they see the last name of the target.
Hostage negotiations have a high success rate. It’s one of the very few things to be proud of about our law enforcement strategy. That being said, hostage crises generally happen in public places, and can only be successful if terrorism is not the goal. I would be deeply surprised if anyone decided to attack specifically me if their goal was not to strike fear into my community.
That’s horrible, it’s insane the lengths people will go to satiate their misperceived anger.
What are the violent acts being committed?
You see not every police dept in the world has removed all investigation from the responsibility of their police forces..
But more importantly, with an order of magnitude rarer killings, there is much less of a “we’re at war with the bad guys” culture. In some countries discharging a weapon brings automatic suspension for the investigation, even if nobody gets hurt. Cops simply don’t tend get trigger happy in this environment.
...(assuming EU) apart from hosting some of the deadliest wars in modern history.
It's also not always that boring in other countries. Here is an example that involved more than some questions and leaving:
https://www.wjhl.com/news/local/18-year-old-arrested-in-cana...
Outside of North America, you don't have to worry about police violence too much in developed nations.
> An 18-year-old has been arrested in Canada after investigators traced “swatting” calls at Volunteer High School in Hawkins County and Watauga High School in Boone, N.C. to him.
Note that the caller was in Canada, but the swatting and presumably violent police response was in North Carolina. Swatting is as American as apple pie and baseball, IMO.
The article appears to describe a non-violent response, so you may be wrong in this case as well as about the normal outcome.
I know I can't win the argument you'd like to start about the absolute risk and whether it's tolerable.
I don't want to!
My point was about the variance, and false confidence that two small rates are truly different. Even when one is zero, so the other is infinity percent larger.
It's not that 1/1000 is "low" or "high" in terms of human cost - that is in the eye of the beholder.
The point is that the frequency of rare events is highly sensitive to random chance, and so even with hypothetical perfect records you can't pretend different numbers are necessarily different rates.
Much less if you guess at numbers based on prejudices.
"How to Lie With Statistics" desperately needs a sequel.
Put in another, more unpleasant way, how many innocent deaths are worth one police officer death, because law enforcement justifies this due to (truly existent, but I think extremely overstated) danger inherent in the job.
But I think any rational mind can perceive it's way too far skewed in one direction.
Of course those scam calls are guilty, but the police should also be less aggressive.
If the police would fix it's behavior swatting wouldn't exist.
(2017) Thugs who sent Brian Krebs heroin and a SWAT team sentenced : https://nakedsecurity.sophos.com/2017/02/21/thugs-who-sent-b...
SWATting - Krebs on Security : https://krebsonsecurity.com/tag/swatting/
Instead they use other charges with a few years?
Tricking the police to go kill people is not an "accident" or "oops" or "just kidding", it's a "well that's enough freedom for this lifetime, guess I want to spend rest of my life in prison".
Does this mean that Ring stores plaintext passwords?
It could take on the order of a few seconds per password in the worst case. Normally a few Milliseconds.
So 1,000,000 breached passwords * 100ms per check is 100,000 CPU seconds or about 30 CPU hours to check all passwords. The is easily paraliseable so imagine more like 10-20 minutes in parallel.
For a single user's account. Multiply that by 1 million ring users and you get 30 million CPU hours.
I was actually under the impression that they're generally overhyped and not useful in most situations.
Even if most IoT companies don't use per-user salts, Ring is one of the most respected ones, since it's run by Amazon. So it likely has salts.
Actually, thinking about this more, I don't think rainbow tables are useful here even without per-user salts. The purpose of rainbow tables is to be a storage optimization, so that you can use less storage than a hash table, while still having a lot of the benefits of a hash table. But this specific use case discussed here is "passwords compromised in non-Ring breaches", for which there is enough storage for a hash table. So a rainbow table provides no benefit over a hash table.
For more information on what rainbow tables are read this (note that the first page doesn't even explain rainbow tables, you have to click part 2 at the bottom to get to the actual explanation of rainbow tables):
https://rsheasby.medium.com/rainbow-tables-probably-arent-wh...
Maybe that counts as "regular".
For security related matter like it or not it has to be traceable to USA or worst EU or UK.
Which I tend to agree with. Sociopaths due to genetic differences are, IMO, extremely rare as to be a non-factor. But childhood abuse and/or trauma is the biggest reason for people becoming violent, unsociable or generally evil.
SBF just seems like the stereotypical kid born in a very rich, connected family, that got every material need fulfilled, but lacked something crucial to develop a mature and critical understanding of how the world works. This is often seen in children of ultra millionaires, growing up completely divorced from reality and how other people live. I imagine people like him thinking "oh, fuck, so sorry I lost you a million dollars. My bad. You still have a few mil in stocks to tide you over until I get you your money back, right? Right? What do you mean your parents are also broke?"
There is a lot of chaos in nature too though, and I think even with great childhood backgrounds there are some individuals that just want to go a different path, for better or for worse.
Hopefully, you didn't use sms as 2steps :).
These swatters want the police to turn up and use deadly force. They use voice & call scramblers to call the police. The swatters tell the dispatchers that they are mentally unstable / psychotic and have already killed multiple family members and are ready to inflict more damage. Dispatchers have very little time / training to identify if this call is authentic. They just relay the information to the cops who turn up expecting to face a hail of bullets.