FBI confirms it issued remote kill command to blow out Volt Typhoon's botnet
theregister.com
theregister.com
It seems like leaving bystanders alone and removing the threat (what the FBI did) is in everyone's best interests. Nobody wants to get dragged to court over an old Linksys.
Still, this isn't a foreign warzone. These are devices that were presumably owned by Americans, working out of American homes. I wonder under what legal authority the FBI can hack into and modify American devices. What if they accidentally brick something? What if they find evidence of personal illegal activity?
As such, they of course don't have a search warrant, but they have a license to locate and disable a source of threat: a fire, a bomb, a piece of highly radioactive material, etc.
IANAL, of course.
>The FBI will identify a list of U.S.-based routers infected with the malware, as described in Attachment A.
>The FBI seeks authorization under Federal Rule of Criminal Procedure 41(b)(6)(B) to remotely search those routers and seize the evidence and instrumentalities of the hackers' criminal offenses, as described in Attachment B.
>As part of this search and seizure, the FBI will remove the malware from the infected routers and take limited, reversible steps to prevent re-infection.
To GP’s questions, the scenarios would be handled as in any other search warrant. Though I’d presume this is rather unusual and to increase the likelihood of future approval, the agent would try to avoid stumbling into having to decide if some completely unrelated crime needs to be prosecuted.
Aside from this, it’s intriguing that they state the changes they planned to make to the routers would be reversible.
I wonder how practical this might be if needed, given potential shift in IP. Also, when, if ever the owners will be notified of the activity. This may be covered in one of the filings.
But, with that said… If I own a property that I don’t use, and people start making and selling drugs there, without me knowing… to what degree am I liable?
And what do the police/FBI do in that situation?
I would be totally fine with them entering the property, dealing with the specific threat, not looking at more than they need to for that investigation, and letting me know what happened.
It seems like the exact same thing. These people were allowing illegal activity on their property (devices), unknowingly. So the police come in and deal with the threat, only look at what they need for the specific investigation, and let people know afterwards.
- https://arstechnica.com/security/2024/01/chinese-malware-rem...
That story notes that the FBI's actions also prevented re-infection...at least until the routers are rebooted.
I think it should come down to intent. If this is an action purely done for the benefit of end-users with an honest-to-goodness attempt at no snooping around, I fail to see this as a problem. This is an example of government doing it's job to protect it's citizens.
I'd like to see this go a step further. I'd love to get an email or phone call saying that they noticed my router was part of a botnet, they remoted in to fix the issue, and (if applicable) run a software update to permanently apply the fix.
It concerns me that we possess so much skepticism around the idea that government _can_ act benevolently. This is extremely harmful as it prevents us from putting forth any meaningful guardrails around these kinds of activities.
We defer too much to the false idea that we're protected from tyranny by refusing to acknowledge we can have a government work for us.
To many, missing out on the upsides is simply preferable, because they consider those powers falling into the hands of a bad government an unacceptable risk. They recognize that taking power away from the government is infinitely harder than not bequeathing power in the first place and also that they might not trust next year's government - even if they trust the current bunch.
Personally I'd prefer there be so many limitations, checks, and balances, that no trust in my government is necessary at all, but as a German I'm strongly biased.
It is technically frowned upon though for the possibility of it running away with itself -- where is the line drawn once you say the line we have (laws) can be crossed.
https://www.eff.org/pages/playpen-cases-frequently-asked-que...
It was challenged in court, but the courts did a bunch of hand-waving and said it all sounds constitutional. You find that a lot of the time with criminal cases involving bad people, the courts will often find a way to let things slide using the "ends justify the means" tactic.
The article makes it sound like a bunch of consumer-grade routers were infected with Chinese malware, and that the FBI hacked into the hacked routers, logged the malware, and removed it.
This must’ve been so fun for whomever individual(s) working on this from the FBI.
You're saying Chinese spies/hackers are duping real people to facilitate this botnet?
But is this story possibly alluding to the fact that the FBI did NOT disclose the potential 0 days used in these attacks in accordance with responsibile disclosures, and instead is likely retaining these zero days for their own use?
I wonder if the OG Mirai minecraft server wars botnet hackers working for FBI now were part of this task force.
Original story https://www.wired.com/story/mirai-botnet-minecraft-scam-brou...
Fantastic follow up https://www.wired.com/story/mirai-untold-story-three-young-h...
Where did you read that they are not 0 days?
Internet access is a privilege, and being a threat to others in this shared space should lead to said privilege being revoked until the threat is gone.
They all pay their ISP a hefty "rental" fee for their crap modem. It's only fair to hold the ISPs responsible in such cases.
Yes, everyone could be more responsible about their consumption but why should that free the manufacturers from the responsibility of making competent products to begin with?
I don't know how to tell whether my router is vulnerable, or what I could even do about it. If I'm not savvy enough for your proposed rules, which does seem quite possible, I don't think most people have much hope.
It is the job of the techies to fix techie problems. When a bridge shakes beyond specs, it is the job of engineers to fix it, bridge building is not crowdsourced to society.
Car analogies are always fun, so here's one: The catalytic converter on my car is sawzalled off in the middle of the night. I drive around with the missing cat for a couple months. Then I fail a smog check, or get a ticket for loud exhaust. Is it my fault the cat was stolen? No, but I still have a responsibility to everyone else to not pollute (fumes or noise).
If the ISP supplies the router, then of course they should correct it. But if the subscriber brings their own equipment, then they take on the responsibility of maintaining it. Including replacement if it turns out not to be fit for purpose.
Not, it is a fault of thieves. And maybe a police who prefer to generate ticketing revenue rather then go after real criminals.
Car manufacturers are required to do recalls on cars that have airbags that explode rather than inflate. Even 20 year old clunkers. They widely publicize cars they think aren't actually safe anymore so customers can choose to update.
When food is shipped out to customers full of listeria, they don't say "you should have kept a full pcr lab in the kitchen and tested every bite, this is obviously the eater's fault", they flood the news with recall notices and take the food back and offer a refund. (and often are still sued because they too have responsibility).
The firewall stopped doing it's job, if it had done it's job properly the device wouldn't have been owned. Why shouldn't firewall manufacturers be required to have some responsibility when the firewall is shown to not actually firewall?
> Why shouldn't firewall manufacturers be required to have some responsibility when the firewall is shown to not actually firewall?
They should! I'm not arguing against holding companies responsible for their crap products. I'm arguing that the ISP shouldn't be forced to keep an attack vector on their network.
If a shitty home router becomes a bot in a DDOS botnet, that's not the ISP's responsibility. From their perspective, it's on the subscriber. From the subscriber's perspective, it's on the maker of that shitty router. (ISP-provided equipment is obviously different)
Yes, but a lot of the internet is on a shoe-string budget and managed by someone who DGAF, and connected to an ISP who also DGAF.
Global emissions enforcement is just about as good as global internet security enforcement. That's why the internet is full of malware and the earth is getting warmer.
And it was a botnet with "hundreds of devices." That is literally nothing. People who want to live in this world where abuse emails are king and a bunch of Spamhaus type people lord over the Internet always weird me out.
https://www.justice.gov/opa/pr/us-government-disrupts-botnet...
> China’s hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict
Edit: I agree it is important to do takedowns. Qakbot, GameOver Zeus, Emotet, Snake, etc all had actual espionage risk / were cumulatively involved in billions of dollars of theft. But this botnet seems sort of irrelevant.
Give them a remediation time of 24 hours. If that doesn't help, cut them off anyway, as that's the only thing that will force management to give their IT people actual staff and budget. Hospital IT is almost always a shitshow and that won't change until external pressure forces management's hand.
Furthermore, taking it at face value, why shouldn't this condemnation apply to the FBI first ? They've got compromised devices with the out of life software that's causing a bigger problem. So by applying that standard, they should be taken offline first. Which I'd say highlights a deep problematic assumption in reaching for the blame game, whereby some nodes start to be considered "more equal" than others.
Just a quote from a friend.
How about you start your own internet for fragile systems that can't handle the real internet? Then you can be a dictator and require remote attestation or whatever.