SparkFun Gets A Subpoena
sparkfun.com
sparkfun.com
If you end up being contacted by law enforcement for data, I'd recommend doing everything you can to help educate them about the information you carry. It might be tempting to volunteer as little as possible, but you also might be the first willing and knowledgeable technical person they've spoken to in some time, and starting a relationship like that on a good foot can be incredibly useful to your company; maybe even you personally.
It can mean future requirements get handled without hassle, and may never even come to you at all if they know it's information you don't or can't carry. You can also help shape policy around how such things are handled for others in future.
YMMV depending on jurisdiction, but it's worth considering contacts from law enforcement as an opportunity to build a healthy (two way) relationship.
It's not like they showed up in the middle of the night and yanked their entire servers out of the office without a warrant and covered it up under "homeland security" or other nonsense.
They did it the proper way through the courts with a judge and public documentation of their actions, and asked for only a subset of the data (limited to a year and GA).
Kudos to SparkFun for responding with caution.
That said, I think the lead will be useless to them because the person could have bought it anywhere, even outside the USA and brought it into GA. Apparently there are also clones now of sparkfun boards complete with logo.
This is very typical for law enforcement everywhere these days. Luckily SparkFun was diligent enough to negotiate it down to relevant information, but it the "gimme all your data" attitude is a fundamental problem. This also extend to seizures ("gimme all your servers", not just the ones involved). The courts should never allow this, so although this is the proper process, it is failing. There's no point in insisting law enforcement goes through the proper channels if those proper channels don't do their job properly.
I really want the people running the skim operation caught, but I agree with Nate (the sparkfun guy) that it is a very fine line harassing the others that are (most likely) blameless.
Am I reading this correctly that then these 20 people have their info in the public record after this trial closes? wow... not sure I'd want my name on that list.
At first I thought it was this[1] device, but on closer reading of the article it indicates a sparkfun silkscreen on a board, which I don't think the mag reader would have.
Has anyone figured out which board was in the offending device?
But I'm amazed their initial subpoena was for ALL orders from Georgia for a multi-month period. That's an amazingly wide net.
That seems like an overbroad generalization. All else being equal, I'm sure the police don't want to compromise people's privacy. To be sure it's not their top priority, and if they had to choose between missing important data and dragging too many innocent people into an investigation they will probably err on the side of too much data.
Even if the police don't much care about privacy, there are a lot of people who do. For example, there's no way a court would let any of this subpoenaed evidence into the record unless it was specifically relevant to a charge being brought.
This matches up with reality since they seem happen when Sparkfun talks to them and they agree to only get the details for that parts.
Nope. The subpoena is in the public record. The data SparkFun sent in response to the subpoena is not in the public record. It will just go to the investigators who are trying to track down the credit card thieves.
If the investigation leads to someone being charged with a crime, and that leads to a trial, the proceedings of that trial will be in the public record, but there would be no reason for the information for the customers NOT charged with the crime to be entered into the record at that trial.
I doubt that anyone will be harassed over this, unless we use a very loose definition of harassment. Most likely the investigators will take the list of customers, look up these people to see if any of them have a record of prior criminal activity, and concentrate on those.
If they do question the rest, mostly likely the investigators will simply ask them what they purchased the board for. The customer will then enthusiastically launch into a description of the neat gadget they built and insist on showing it to the investigator and explaining in excruciating detail exactly how it works. The investigator will see the SparkFun board, see that the device is obviously not a credit card scanner, and try to figure out how to escape the enthusiastic hobbyist without being rude to him.
Or other things. Was someone who's name was on the list seen hanging around the places where the skimmers were installed lots? Was the money being sent (however roundabouty) to anyone on the list? etc.
"Am I reading this correctly that then these 20 people have their info in the public record after this trial closes?"
Allow me to venture a guess. At some time in the future the county will auction off its surplus assets (old computers). The computer with hard drive, data & all else will be sold to the highest/only bidder for about three bucks.It is also possible that the county has data retention/destruction policy, in which case the county commissioner's brother-in-law will be paid on a contract basis to have his children / some migrant workers remove the drives and feed them into a tree shredder, and then sell the bits for scrap.
Here's hoping for option two.
Can you fail PCI compliance if you're able and do this? What if you use a third party system such as Stripe where you have no access to the full credit card number?
In general, you can not be compelled to produce something which you do not have. This is why you see legislation proposed with mandatory retention policies for various businesses.
There are many ways to achieve PCI compliance. Not having the data is simply the easiest.
That being said, a subpoena can be 'quashed' if you can prove that the agency is over reaching or 'fishing' but if you refuse it you put yourself in a position to be held in contempt by the court.
You know that the police routinely handle & store information that people would kill to get at (hint: mobsters)? Do you not think they know how to protect information like this?
If you were to email it encrypted, you'd have to send a follow email with the decryption key. Encryption would only be a inconvience and would not protect this information at all.
An encrypted mail attachment would be a start -- if you use a second channel to deliver the secret key, e.g. call them up to tell them the password.
https://thepiratebay.se/user/AntiSecurity/
Just because you don't hear about vulnerabilities and attacks, doesn't mean they don't happen.
from Nate down in the comments section
It's also inconvenient for the 99.999% of customers who aren't trying to cover their tracks, because without the info they wouldn't be able to check their order history.
And it's not simply a matter of telling the law enforcement agency "We don't store that information." You most likely have to jump through the hoops to prove that you don't store the information.
https://en.wikipedia.org/wiki/Telecommunications_data_retent... (concerns telcos, e-mail hosts, and web-hosts)
The USA doesn't have a law like that, but it doesn't have a right to privacy either (there is a law about the privacy of correspondence that the NSA and telcos have ignored), so this sort of data retention law is sidestepped by a few large actors “voluntarily” collecting and sharing information. National security letters, gag orders, and whatever power incited AT&T to first do large scale warrantless interception mean that there can be a lot of abuse with little consequences for the participants. This might also apply to smaller actors, although less publicised (I don't know if there's any bad publicity the US government would care about). If you collect it, you might end up sharing it.
Lying to the police/courts and obstructing criminal investigation blatently is, obviously, a crime. You shouldn't do it. Also if they get a warrent you are breaking the law by hiding that information.
Also, protip for criminals: make your own circuit boards without identifying marks.
(http://www.guardian.co.uk/world/2012/apr/27/chris-tappin-den...)
I understand where you're coming from, but think it's entirely ungrounded in this case. We actively work with the DHS on export control. There is a very real risk involved in selling the products we do, but I don't think that should stop us from our goal of education and - right there at the bottom of every page on our site - sharing ingenuity.
Why? This seems like the perfect sort of thing to buy with someone's stolen credit card - it provides a red herring for the police to chase after, and at least in this case, gives the thieves a warning that an investigation is in process.
If the investigator were smart enough, they could ID the other coupled nodes connecting to the BlueSMiRF device. This technique is done to locate a WiFi node.
"Alright, it’s settled. We gotta build a robot to fight crime."