So the FBI used unauthorized access to the computers to uninstall the malware? Scary if you think about it. I'm sure they could have used that access any way they wanted.
So the FBI used unauthorized access to the computers to uninstall the malware? Scary if you think about it. I'm sure they could have used that access any way they wanted.
The FBI is far from perfect but this is the kind of thing they _should_ be doing, using their unique privileges to help with public menaces. Anyone on the internet could compromise them, too, so I’d prefer a public cleanup.
In your examples none of them invole solving problems that you would not be unaware of, in ways that you're not aware of without telling you they were there and oh btw they had to rifle through your undwrware drawer to fix it.
It’s pretty common for there to be problems the owner can’t be reached for - people travel, get hospitalized, die, etc. - but that doesn’t prevent action. What it can do is limit what they’re allowed to bring charges for – in your example, if they said they were pursuing reports of squatters in your house they couldn’t search inside your dresser since that’s not in plain sight.
In this case, I would expect that courts would give the FBI considerable leeway for neutralizing a system which is being actively used to commit crimes but not to check your private data to see if you were cheating on your taxes.
It seems like this might be the case here where some minuscule portion of the botnet base is security research firms / etc. who have a reason to have the botnet software installed and don't want it deleted; in fact, it may even affect their livelihood to delete it.
I have to imagine this is similar. If your livelihood relies on a botnet, and you don't at least let authorities know, my guess is you're not a researcher. . .
This reminds me of frivolous lawsuits. A doctor sees someone needing medical attention. The doctor performs CPR, break some ribs in the process, but ultimately saves their life. The person who would have otherwise died, sues the doctor for breaking their ribs while completely ignoring the good will that saved them from certain death.
It's Also why people normally get a permit or at least contact officials to tell them that they're going to do staging a scene that looks exactly like an accident/crime scene.
It isn't a strike against emergency responders for responding to a situation that someone has staged to look as close to the real thing as possible.
This doesn’t make any sense to me: no ethical security firm is going to allow their resources to be used to attack other people, or complain if the FBI shut down the people attacking their clients.
One time they still managed to damage something outside of the vast location (an abandoned airport I believe) they were working within, and were banned from that location.
The access was always possible. Not just by the FBI. In fact, it was already being accessed by the botnet operators. The issue here is _permission_ and _precedent_. The government gave itself permission to go into these computers and cleanup the botnet. What explicit permission did they grant themselves and what precedent does that set?
I'm pretty hesitant/paranoid about the U.S. government and the powers we (citizens) grant them. But this one surprisingly sits right with me. It looks thoughtfully applied and constrained - a very tactical operation to go in and cleanup a botnet without accessing any unnecessary data in the process.
https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
> This section does not prohibit any lawfully authorized investigative, protective, or intelligence activity of a law enforcement agency of the United States, a State, or a political subdivision of a State, or of an intelligence agency of the United States.
I'm not sure if this is the relevant code for this Qakbot incident, I'm just trying to clarify that the law generally accepts that law enforcement officials get special dispensation from the regular requirements of the law in order to carry out their function or to protect the public.
Sounds like they hijacked a malware proxy server and had it forward the traffic to their own server.
Meanwhile in the physical world https://reason.com/volokh/2021/11/30/federal-court-rules-tak...