Verizon fell for fake "search warrant," gave victim's phone data to stalker
arstechnica.com
arstechnica.com
But it's also worth noting that the "vulnerable" system is not the centuries old system of policing. If you get arrested by a fake cop, that system affords you legal remedies - it might take a few days but you'll see justice. The vulnerable system here is Verizon's process for responding to inbound messages claiming to be search warrants. And when this system fails, the victim has effectively no remedy - their stalker already read the data that Verizon sent him.
So that's even less of a reason to increase centralization of the policing system. It won't solve the problem because the problem is with a different system.
The .gov domain already exists: https://beta.get.gov/domains/before/
That should be enough info where folks can verify the validity of their subpoena w/o revealing too much data. Including date of issuance and jurisdiction should help prevent using stale IDs to scare someone.
If the subpoena is not sealed, the ID would show all the subpoena info, further narrowing down the ability to replay stale IDs.
I'm definitely missing something obvious though because technical solutions are often not a panacea in cases like this
this would probably work pretty well for these "utility-like big gatekeeper corps" which handle a shitton of subpoena requests, of course it doesn't help if a SWAT team is executing a someone-shout-and-knock-with-that-huge-doorfucker-implement on the wrong house.
in many countries there are state-managed online id systems allowing sending documents to legal persons ... which would make it really really trivial. send the warrant to the department executing it and to the department handling these at Verizon. (I wouldn't be surprised to learn that most of the US states already have something like this, but not used like this.)
it can be optional/voluntary for natural persons, it can be mandatory for companies above some size, etc.
What if the head of the agency responsible for verifying these courts institutes a policy that courts will lose their verification for rulings against abortion?
What if two courts in neighboring jurisdictions claim to be the same court? They each submit a different public key, but both can verify they hold the private key that pairs with the public key they submitted. How does the federal agency even verify the identity of a courthouse? Do they need to physically visit them and meet with the judge to tap a Yubikey?
What if somebody steals the YubiKey from the judge? What if a referendum dissolves a jurisdiction?
What is the process for revocation of verification?
Of course, this would require such law to actually survive the lobbying block of the data hoarders in the first place, and that's not likely to happen, alas.
Shouldn't the remedy be the guy goes to jail for a long time for forging a search warrant?
The most relevant example I can think of would be a CCP hacker forging a search warrant for a US-based political activist. The government would probably care, but good luck identifying some random Chinese Army hacker, much less extraditing them.
Says who? I'm not aware of any rule or statute that prohibits the recipient of a subpoena from confirming with the court that it is legitimate?
Usually, there's no one to quash the subpoena.
There's always someone who can move to quash - the recipient. There's usually two people - the recipient and the opposing party.
A federal subpoena includes the rule on how to do it right on the subpoena. https://www.uscourts.gov/sites/default/files/ao088b.pdf
As a side note, there are a myriad of potentially applicable statutes and case law relating to obtaining phone records. Depending on what was requested, a subpoena may not be required.
I have no idea what exact laws and liabilities apply here, but my feeling is there's very likely going to be an undisclosed civil settlement between Verizon and the victim, and maybe some laughable fine (let's say ≤$10k) for violating privacy laws on the criminal side.
That said it really depends on the exact legal framework (which I have no clue about) and eagerness of a prosecutor to make a case. Hence my "maybe".
FWIW I have a side job at a small community ISP in the EU and the GDPR was a no-op for us. The requirements for anyone operating in the telco space were already stricter. If I remember correctly the GDPR fines are higher though, whereas wiretapping (& co.) laws are much more likely to land you personally in jail.
(I was being intentionally vague with "privacy laws"; I do include wiretapping charges in that but, again, I don't know the US legal situation.)
The fact that the US warrant system has holes capable of driving a truck through isn't the fault of Verizon - there exists no sensible way of validating a warrant.
Just because a piece of paper claims to be a warrant, doesn't mean it is one. Warrants and subpoenas contain contact information for the person that issued them. It is on verizon to verify that the warrant the received was legitimate and if it wasn't, to report to the DA that someone is issuing fake warrants (which is a crime all by itself).
Subpoenas (like verizon was issued) are never immediately actionable. You have a right to appeal subpoenas. If the subpoena had a "You must respond right now" trigger it'd eliminate that right. Something I'm CERTAIN verizon knows because they file motions to quash all the time [1].
[1] https://casetext.com/case/in-re-verizon-internet-services-in...
If I host a movie night with some friends, and an altercation occurs between them, then it's unjust for the police to create unreasonable cost on me as a host. They shouldn't tear up the house or create lots of time consuming paperwork without compensation.
You may think that my movie nights are inherently a danger to society. But even if that's correct, we should create direct legislation to discourage this dangerous activity rather than using search processes/warrants to impose cost in an approximate and roundabout way.
But also the cost for you would be the time to call law enforcement, for them is the time to verify the validity of a document, so its just nonsense
Large companies can face massive civil & criminal liabilities for mishandling personal data, whilst also being made whole for the administrative cost of cooperating with law enforcement.
I doubt it wouldn't have cost them anything more than what they're already paying to staff their legal department.
I don't think that would have helped in this case since although it was based on an affidavit from a fake police officer, the name of a real judge was used to approve the fake warrant.
What would have helped is Verizon calling the court and verifying that they issued the warrant.
That's like saying forging a plea from a Nigerian prince is trivial. Verizon should be deeply embarrassed by this - I mean the initial request came from a proton account with misspellings and grammar mistakes of a child.
I don't know how Verizon does it, but I have a friend who works in the "respond-to-law-enforcement department" at one of the FAANGs. Given the company, they get tons of legal requests for info, but also tons of fraudulent ones, not to mention ones from real governmental organizations but that are dubious that they challenge. Point being they have extremely detailed processes and technology to respond to these requests. Verizon is the biggest cell phone company in the US, they can afford to not look like a total clown show in this regard.
Companies have no feelings, only pockets.
Make carelessness expensive enough and they will care.
Many phishing attempts are shockingly bad like this - but that doesn't make it difficult to not have mispellings and grammar mistakes and come from a vaguely plausible domain (gmail?). If your defense against phishing relies on your adversary not knowing what a legitimate request looks like - it's not a very good defense.
"Normal" phishing is a bad example, because many phishing emails notoriously use misspellings and bad grammar on purpose because scammers don't want to waste their time on people with half a brain, they only want people dumb enough to respond in spite of the ludicrous misspellings. But in this Verizon case, that logic doesn't apply, because there was only a single targeted recipient.
With respect to "If your defense against phishing relies on your adversary not knowing what a legitimate request looks like - it's not a very good defense", I wholeheartedly agree. My point was only that the fact that Verizon responded to this fake subpoena despite the reddest of red flags makes me think that they must have horrible procedures generally for verifying these types of requests.
Wait, sorry, sorry, sorry, hold up, full stop...could you repeat that again?
These orders arrive AS GODDAMN PAPER PRINTOUTS?!?
Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key?
Yes. Or a PDF attachment on an e-mail, possibly scanned from something that was printed a few minutes earlier because someone had to sign it with a pen.
> trivially verify with the ordering entities public key
You're underestimating the complexity of establishing a PKI infrastructure to handle federal, state and local authorities, signalling which keys have what exact authority, revoking compromised keys, … and then doing tech support for some redneck judge that owns more guns than electronic devices.
Getting the tech adopted might be difficult (like you say some judges may not see the point of it) but the PKI doesn’t have to be super complicated…
Having different authorities provide signatures for different types of documents may or may not be needed, in theory it is more secure, but just checking the domain name suffix should be a good start. And every tech literate person has a general idea how to tell “valid” domain names from phishing sites, so the scheme translates well
You're not wrong, but you are overestimating the tech skill level of the average non techie.
I'm travelling right now, and a surprising fraction of restaurant websites here aren't https.
I don't know much about the American ones, but the British ones are complaining about the ceilings falling down due to chronic underfunding of basic maintenance; getting the digital infrastructure right is probably lower down their wish list than ceilings that don't collapse:
https://www.standard.co.uk/news/london/courtroom-shut-ceilin...
https://www.wwnytv.com/2023/11/15/st-lawrence-county-struggl...
A single judge, and likely, a single court clerk, are the only people in many, many rural courthouses. And sometimes, that judge themselves might have been able to get into the job with one vote as a joke. Neither of them could have any IT support, just a couple laptops from the county if that to help them out.
These courts out there run a lot more on paper and fax and occasionally normal email (https is 'secure email' right? /s). They'd have zero clue what a CA even is, other than the Golden State.
That is horrifically underfunded, so the pay is low, so the employees get poached all the time. I have a bit more insider information here than most as I had family that has worked in the court system and law enforcement 20+ years, and was good friends with IT at the county.
These counties are generally so busy fixing past problems there is zero time, budget, and manpower to implement new technology like you're talking about. Seriously recovering encrypted systems is a major part of their time. As to the poaching, the number one 'company' that poached good IT people in the county was the feds. They tend to pay a lot more, and they too are generally critically understaffed.
Most IT people simply don't want to work for county/state/fed at the end of the day because pay isn't great, and for that not great pay there are a lot of restrictions.
This is an unnecessary dig. Not all "rednecks" are dumb. They got us to the moon. Not all people who resist tech "innovation" in their space are "rednecks" or "dumb". They probably know a whole hell of a lot more about their domain than you do.
Be cautious of the toxic sense of superiority tech people have that they somehow know better than the unwashed masses, even before immersing themselves in the domain to understand and then solve problems.
Take delivery apps that have somehow made the previously thriving small business of delivering food a giant industry that loses money for everyone involved.
Adding a tech doesn't automatically make things better. When people resist your shiny new (and likely ill conceived) tech that doesn't mean they are dumb. They might just recall the sting from last time.
I agree with everything you said but this. It seems like an industry with sustainability problems where the consumers are winning big. It also seems like it ignores the small businesses that could never support delivery drivers in the first place. I'm not super familiar with this industry but I hear similar arguments against ride sharing which is at worst 10x better on the consumer side than it was before.
Now there are several different payment apps that wants to fight for the customers and they all require you to get their app. Or you will have to jump through five hoops to get to pay the invoice. It's called rentseeking I believe...
I didn't call anyone dumb. Why did you jump to that?
If I translate "redneck" to my native language, the result is roughly "someone who lives away from civilization", "lacking higher education", "anti-progressive and behind the times". Those are exactly what I was aiming for, as that's the kind of person that will (by definition, essentially) have the most & worst IT support issues.
(Also—what's your definition of "redneck" when you say "rednecks got us to the moon"? By my understanding, at the point you start working on the space program you're not a "redneck" anymore…)
Was honestly having a difficult time determining (a) if this was sarcasm or (b) you just have no idea of the technical competence of many of these jurisdictions, not to mention the complexity of managing this type of public key verification system for the number of jurisdictions involved.
They wouldn't want that, because they don't want it to be easy to prove that they demanded surrender either.
Companies can adopt new tech in 1-2 years. Industries have around 5-10 years inertia. Bureaucracies like courts still live in the past millenia. You should be happy that they are using email.
The best security measure they will implement after this article going wide is something like “only emails from @<domain> are valid, but we’ll destroy you anyway in case a judge mistakenly sends you an order from his own gmail”.
This is a feature. We don't want courts to "move fast" because the consequence of breaking is far more severe than losing a few files on Google Drive.
While the US has been around for nearly 250 years.
And truthfully, despite a highly technical crowd, how many of y’all have actually ever sent or received a digitally signed email? If you’ve tried, you know why no one ever does it.
I worked in a data center once, and we would have FBI contacts that would come in regularly to access criminal data (CP, terrorist communique, heavy piracy, etc). We would verify the warrant before secure entry+accompany them to the specific requested entity. I know procedures are similar + even more stringent for the medical field. Things get even more complex for small local authorities, but the idea that "just having a slip of paper" is enough is ridiculous; unless the person accepting the request is dumb/lazy/uninformed/undertrained/etc, as in any social engineering feat (in your case, the responsible person decides to not bother with the QR because their phone connection is bad, it takes too long, etc; for example).
So it's not like on TV where if they have the paper they can just show it to you and barge past you by force?
For arrest warrants that makes sense, but they portray search warrants the same way.
Even in these cases, they still have to give you the warrant and you're able to take it up with the issuing authority/take to court the executing officers.
But yes, arrest warrants and personal search warrants can be executed expediously for evidentiary / flight concerns. It's the exception, not the rule.
This touchstone of 'judicial oversight' is frequently nonsense. You can't tell me that every judge who has to give a warrant for a DUI blood draw at 3am in smalltown US is giving the matter any kind of scrutiny, nor that that judge has any legal or judicial experience at all.
Most telecom providers have a compliance portal that only nominally engages with human supervision or legal departments.
You fill out the form from your computer using the department credentials, typically on a semi hidden webpage belonging to the either the provider or serviced for the provider by a law enforcement program (like FBIs LEEP).
Records are rarely returned to a court registrar for EDRs or any digital request, and in the case of a magistrate federal warrant they are frequently issued after the fact or by email. I suggest it would be trivial to get a real warrant, or real fake-warrant, by impersonating LE.
I have personally seen warrant discussions and approvals between ADAs and small departments take place over personal gmail, if this tells you anything.
More info (Krebs, I know) https://krebsonsecurity.com/2022/03/hackers-gaining-power-of...
Verizon LERT https://cryptome.org/isp-spy/verizon-spy.pdf
Yes, they actually can. There should be contact information associated with a subpoena that verizon can both verify are legitimate and then directly contact to validate the subpoena.
This comes up in the medical field and, due to much higher penalties if they respond to a fake, medical staff get trained to do just this [1]. HIPAA doesn't care if you are tricked into revealing HIPAA information.
Imagine a city with police force of 6,000 combined with country, federal, state, and university LE. You might have a total of 20 neighboring or overlapping agencies ranging from 6 to 6,000 employees.
Personal cellphone numbers are used in LE sometimes, whatever one might think of that practice or implications for discovery and preservation.
The State/Fed have public official websites with this information.
I mean if the registered owner says "TXSTRGCT" is that the "Texas State Regional Court" or something a spammer setup over some VOIP service?
Someone at Verizon should maaaayyyybe have sliiiiiightly adapted that boilerplate response in this particular instance ;D
(Also, yes, no laughing matter really, but still very funny.)
--
FWIW I moonlight at a small community ISP and we've had to deal with the legal system twice. When we first got a request, we scratched our heads trying to figure out how to authenticate it. Our procedure became to discard all contact information from the warrant, find fresh contact from some trustworthy source (ended up being the official state webpage in both of our cases), and call them to verify.
… maybe Verizon should adopt that procedure, sounds like it would've caught this instance:
> The Cary Police Department confirmed that no officer named Steven Cooper is employed by their agency, […]
I mean something as simple as a piece of paper with a password that lets you find an authentication info in the court website. An email. Or even an automated phone or email address that lets you authenticate online
This is why I would rather have profit hungry corporations manage things than governments. Because with government there's always a legion of people rushing to excuse and explain away even the most serious examples of ineptitude and mismanagement.
Would you accept it if Facebook or Google let people login to user accounts via signed letter? So why is a signature enough for a search warrant?
A signature is not an acceptable method of authentication in 2023 for important documents. I don't see how that's not obvious.
There's a large group of the population that has an ideological frenzy to defend government no matter what so they're able to get away with terrible lapses like this
> No it's because in every other area besides government we have standards of security
I guess you never heard of NIST?
I suppose private companies never get hacked and have all their customer's data stolen?
If you mean something else, then you should find a better way to articulate it. People defending against what you are literally calling for is not 'ideological zealotry', it is pushing back against extremism.
But if you agree it's not a system motivated by the public good and want me to join you in pretending it is and helping it grow while it doesn't serve the public good, our values are still too different.
I think the start is fix the system first to make it about the public good. Once we fix it then we can grow it and give it all the unlimited power and influence you want. But we can't do that because a large segment of the population has an ideology that prevents legitimate criticism of the government and will defend any aspect of it
I cannot see how the other poster, observing how corporations work and are treated with kid gloves in the US, could possibly think anything corporations would do here would be better than the system we have in any way.
All that would happen is this...
People in government would be bribed/funded by said groups in private corporations to look past the grift/corruption said private company did. If private company A did too much wrong, then private company B would pop up in its place with all the same actors. Because these are private companies there would be no public records requirements like are on elected officials at this time.
All of the other posters complaints are based around the electorate not being involved in local elections. Why do they suddenly think it's going to get magically better when a company is involved. You're just abstracting the apathy to another degree.
Otherwise, the government uses all sorts of modern authentication mechanisms when dealing with sensitive materials.
1: It really varies; surprisingly enough it's not a felony in all states, and in at least one state, it's only a felony if there is intent to benefit from the authority granted.
Any time I hear a politician say they are going to reduce a particular crime by passing a law, I wonder why existing laws aren’t enforced that likely already cover the behavior being targeted. I suppose that would mean planning, logistics, and execution - things politicians don’t know how to do.
Those that do not fit the above, having no impulse control, or perhaps mental issues, then laws result in stuffing them away.
It's not perfect. Yet every human society does this, and has done this for millenia. Consider that.
Note I was responding to someone who effectly said laws don't prevent crime, and citing ways they do. Understand the context. My statement was not a 200 page dissertation on "those who might break laws" and a deep dive into societal ethics, etc.
E.g. there is a law saying you cant serve alcohol to minors. That in and of itself doesnt prevent beyond threat of punishment if caught.
There is also a law saying you have to check ids. Procedures like that do have a preventitive effect.
This isn't always correct and is rather myopic.
Quite often laws will issue punishments for some behaviors, but also issue things like funding for programs that work on the roots of why particular crimes occur.
Now, laws that punish post ad hoc are always easier to measure and see, because it's much harder to prove that you prevented something that only had a probability of happening in the first place.
That still requires enforcement. The existence of a law does not imply existence of enforcement, much less wide-spread enforcement (see e.g. wage theft, auto breakins, petty theft, etc).
Like if the system can easily be used to exfiltrate information or perform criminal actions but you can do so anonymously without much effort or more generally doing so remotely in a jurisdiction where you can never be prosecuted, then that system is broken.
Systems that rely on a person not wanting to get caught breaking the rules only work when A the person cares and B the person is capable of being punished. If that invariant doesn't hold up then the system is broken.
well good thing emails can only be sent within the USA
I’m not saying that Verizon’s handling of this was anything other than grossly negligent, but let’s not pretend that the sole solution to, well, any problem involve…what? Asymmetric cryptography?
Something being illegal, even in another jurisdiction, is certainly a deterrent for a lot of people.
OK, and what if it was, say, the Saudi government doing it rather than a crazy stalker in the US?
You think that's surprising? Wait til you hear that in 35 states, a police officer can claim that a detainee, in custody, even handcuffed at the time, can 'consent' to intercourse with the officer. (That's even before you get to the lesser issue of why a police officer is having intercourse at work...)
He was hired to find person of interest through a cell number. Impersonated or intercepted NYPD fax line? Forged some document that NYPD uses to obtain data from carriers. Sent the forged fax and just waited for a response.
Definitely more elegant than sending forged doc from a protonmail address. But nevertheless the same method.
edit: found it. https://youtu.be/AdHE5Nss4HI?si=b4Et34pHKx8p1uP9
Looks like he just used some public WiFi to remain anonymous and forged NYPD fax number to make it more legit haha. Have to rewatch this show.
I wouldn't be surprised if the answer is that police routinely use their personal accounts for such things.
> Glauner and the victim met in August or September 2023 on hamster.com, a porn website with dating features, and "had an online romantic relationship," the affidavit said. The victim ended the relationship, but Glauner "continued to contact or try to contact" her, the document said.
I had no idea porn site dating features were not scams/phishint attempts themselves
Especially combined with: urgency (matter of life & death), referenceng laws/penalty if not handled (quickly), reference to kaws/penalties if disclosed.
Now some poor lawyer has to figure out what to do.
Now just heavily increase what you I.agine the scale to be. Those revealed cases are just the tip of the iceberg.
As much as I would like to blame Verizon or any other entity: I think the key point is that the way these warrants get handled is totally unsuitable for the internet age.
Forgery is usually a crime. So sending a warrant (via paper mail) through a country is sorta safe as you can start chasing the criminals, especially through return addresses.
This all changes on the internet. Someone in a different country or a mostly anonymous person can forge and send these warrents at close to zero costs. Enough police stations got hacked to get realistic templates (and sometimes even direct e-mail access). The whole cost/benefit/risk relation shifted in favor of the attacker.
And it doesn't help that most countries want to fast-track these requests even more.
the forms, the fake law school, the fake school website, the fake law website, fake reviews, etc.
It will take more and more resources to verify minor things.x
If you said S/MIME, that'd actually make sense with the X.509 authority system, but PGP with its WoT is just entirely the wrong tool here.
the lack of an eye for such details used to make me immediately think an overworked team in India or the Philippines was responsible, but now I'm not so sure.
wat.
on multiple levels. wat. wat. wat.