Men who spy on women through their webcams
arstechnica.com
arstechnica.com
First of all, I don't condone this behavior, and using such software for "ratting" should obviously be illegal, but is it really illegal to sell this type of software (or any malware)?
It seems incredibly dangerous to make software illegal based on it's potential illegal uses.
I recall a controversy about a "hacking tools" law in Germany a few years ago, but never in the US. What law would this fall under, if any?
I'd be interested in the definition/ law being used here.
I was just wondering what the law used in this case was.
A lot of activities are incredibly hard to actually catch someone in the act of, and incredibly hard to actually get hard proof of. Possession, on the other hand, is a strong correlation and proof of itself. The reasonableness of this correlation is what draws the line between whether or not possession is illegal, and that's going to be subjective.
It's really easy to forget that the first and foremost reason we defend privacy isn't because its breach is icky. It's because illegality is sometimes the right thing to do. However, usually it's not. This is a natural contradiction that makes writing law difficult.
nmap was one example I remember hearing would be considered illegal under Germany's new law.
This is the problem with these manner of laws. Criminalizing the very method by which entities guarantee their security is never a good idea.
It's a difficult issue to properly address. I think the right method to go about it is to punish actions, rather than possession of tools. On some level, simply having the ability to write software makes one suspect, if you start scrutinizing tools. Actions (compromising boxes and running exploits without permission of the owner of the host, advertising explicitly criminal use of software) are easy enough to define, and it's easier to define an exclusive list of "bad" actions, than to come up with generalizable rules.
For example in NZ, the crimes amendment act 2003 allows for prosecution[1] of anyone who drops or sells 0day.[2]
It's one of those laws which has never been enforced, but probably would be if you made a nuisance of yourself.
---
http://www.legislation.govt.nz/act/public/2003/0039/latest/D...
(Section 251 Making, selling, or distributing or possessing software for committing crime)
[1] "liable to imprisonment for a term not exceeding 2 years"
[2] The requirement is "the sole or principal use of which he or she knows to be the commission of a crime". However, gaining unauthorised or unlawful access to a computer system is a crime meaning exploits qualify.
The one thing you mention that worries me, though, is dropping 0day. Would this include full disclosure? Would this include developing an 0day as part of a pentest? How does this affect things even as far reaching as responsible/coordinated disclosure? If a law makes doing the right (let's use open disclosure, whether full and immediate or coordinated and timed just to mean "right" while selling 0days for ostensibly criminal purposes as "wrong" for the sake of this conversation) thing as difficult (or even more difficult) to do than the wrong thing, then the law will only bolster the black market.
Some relevant quotes: -----
http://www.giac.org/paper/gsec/4001/zealand-information-tech...
"Although most cases of legitimate have been covered, not all have. Section 251 does potentially raise some interesting issues around concepts that many security professionals are supportive of, the sharing of information and full disclosure..."
http://www.bellgully.co.nz/newsletters/03CTM/03CTM_HackersBe...
"On the face of it, such criticisms may be justified. Whether or not the Amendment Act will actually have this effect will only become clear through the passage of time. In this regard, “good” users of such information may have to rely (tentatively) on the police's discretion whether or not to prosecute a particular case."
'In further MSN chats with the FBI, the person alleged to be Hogue answered a question about whether the Blackshades software would automatically conduct key logging or whether it had to be initiated manually. "It auto does, and you can download from all at once, or scan for keywords or digits," came the reply. "And if it detects a credit card is being entered, it can send screenshots to FTP and you can scan for digits that are 16 in a row :P"'
It also had as a feature to encrypt a users files and pop up a ransom notice:
'Blackshades went beyond DarkComet in its support for features that were likely to result in illegality, such as the "File Hijacker" that could encrypt a victim's key files and then pop up a "ransomware" message demanding payment into a remote bank account in order to free the files. (A note attached to this feature said: "However, one thing to put in mind: This feature was made for educational purposes only.")'
In general, even tools that are quite clearly intended for illegal uses seems to be ok. But this one took it much further.
Thing is , you could make a CC sniffing program and then realise "hmm, this might be difficult to defend in court" so you generalise it to something that simply looks for arbitrary strings of numbers. Of course the fact that 90% of your users happen to enter "16" into the box is not your fault.
The generalised program might have useful side effects as a result, but it is no less dangerous than the more specific program.
Yes that is tongue-in-cheek but there is an equivalence here in that the consumer decides how the product will be used. I do agree that advertising use for illegal activity should be quashed (does that impinge on free-speech?).
It could be argued that free speech necessarily has limitations. Depending on where you are in the world, this involves hate speech and incitation to violence.
I would readily agree that distributing (especially SELLING) tools with the expressly stated purpose of criminal use should be punishable. That being said, the same tools are likely useful for legitimate purposes. Heck, I could see an argument for Back Orifice being useful in that one would really like to be assured that their network's egress filtering would raise flags when BO traffic is on the wire. This brings up another important point--these tools are always useful for people who are writing protection and mitigation against the tools' methods.
Selling kitchen knives, and giving tips and instruction on where to stab to inflict maximum damage: I'd be very surprised if you're not legally liable for the actions of the third party. But, IANAL.
EDIT: as for free speech, the "imminent lawless action" [1] test is AFAIK the current standard in the US. I'm sure there's case law around this that I'm not familiar with, but I'd argue giving killing tips is likely to incite "imminent lawless action" in the knife analogy.
Further reading: [What Colour are your bits?](http://ansuz.sooke.bc.ca)/entry/23
Drug paraphernalia could be coffee filters, aluminum foil, a pipe, roach clips. These are all things that are totally legal to purchase yet you can be charged with a crime for having them. To avoid it, you have to avoid being suspected of drug use or being added to the local 'most wanted' list.
1) It is not the software that is illegal, it is the selling of it as your quote clearly shows.
2) If the software has no other purpose than to commit crimes, then yes, the selling of that software should be illegal. It is selling a tool whose sole purpose is to facilitate criminal activity.
I always wondered what that would mean to an email service, since the primary form of email can easily be illegal spam/scams. I would also be careful if I ever contributed to projects like nmap, because how can I prove what the primary usage of such program is? Could it be defined that I was performing a service if I contributed code?
To be honest, i'm semi-impressed this is still a thing. I assumed it had died in the late 90s.
It's also scary of course, that these people seem to have antivirus running and it hasn't stopped it. Seems like a pretty trivial thing to detect?
Malware authors can simply tweak or repack their code until the AV engines don't detect it anymore.
Getting around behavioral detection is harder, but possible. If malware is privileged it becomes an arms race of who can hook lowest and who can disable who.
I tend to notice a correlation between people who have problems with malware/spyware/crapware and people who have AV software installed and it's the opposite of what you might expect. Perhaps people who install it get a false sense of security?
AV software tends to be either ineffective in that it doesn't detect a lot of actual malware or it is constantly generating a lot of false positives which people just learn to ignore "Tracking cookie detected! Your life is in danger!".
I'm more of a firewall guy myself.
That's the difference between Microsoft Security Essentials and commercial AV software. One is designed to just make the more OS secure, the other also needs to advertise its presence and appear to be "doing something".
Also, apparently it was relaunched in 2010 and soon after their site was hacked[1], they also lost their source code - ahaha. No backups, 2010. Christ.
"Weird, my cd drive just opened up."
They are rotten people who do this to innocent girls,they bullied her to death. This same(dark,whatever )service will be used to make these girls slaves for pornography on cam....it must stop,
its being used by human traffickers, who will threaten her and than make her real computer slave.
This needs to stop, we are better human race than this.
> prepare to be sold or traded to the kind of person who enters forums to ask, "Can I get some slaves for my rat please?"
As far as that context goes, the term is accurate for what RATs do: the hacker's "master" device can be used to control what the "slave" machines do. I assume that this is the context in which these people are using those terms. But it is, admittedly, somewhat jarring for people unfamiliar with that context.
"Los Angeles officials have asked that manufacturers, suppliers and contractors stop using the terms "master" and "slave" on computer equipment, saying such terms are unacceptable and offensive." [1].
[1] http://www.cnn.com/2003/TECH/ptech/11/26/master.term.reut/
I'm sure most of us were once 14, and unsupervised and didn't do anything evil.
P.S. Now that I typed the file's name (it was really wolf3d.exe), I suddenly feel old... Not to mention the "floppy" bit :)
[1] I'm an American and love America, but we elevate apologizing for bad things kids do (because we don't have the stomach to properly discipline them) to an art form.
Conversely, the US seems fond of trying kids as adults when they cross some or other threshold of crime. As an outside observer it seems an odd contradiction.
You learn what's wrong from your parents, and your teachers, and society. I'd like to disagree with you on that point. Yes, you get ideas passed down to your by others, but if you do not bother to examine them and act blindly on the premise that these things must be right, because others told you, without putting any deliberation into the truth of these moral dictates, then...how to get this across without seeming as angry and ranty as I am? Because things like this viscerally disgust me. My parent taught me they didn't care (or couldn't), my school taught me I was in the wrong place, and my peers taught me that I was scum. And I didn't act on those morals, or I wouldn't be writing this paragraph, nor living, nor breathing. Of course, this didn't last forever. I recovered, and I learned how to deal with people. But what you just said, that I...I was defective for not leaving a place that obviously didn't welcome me, the implication that I should have crossed hades, that's worse than telling me to "go die", because you said it with moral righteousness.
Now I know you're talking about 14 year olds that spy on girls, and I don't think that's morally right either, but your explanation of why it isn't, it's just...wrong somehow.
Firstof, they're not defective. Don't even say a child is broken. Misunderstood? Maybe. Misled? Maybe. But not broken nor defective nor hopeless. Because when you take a child, filled with expectations and hope, trying to make sense of the things that happen in the world, and you tell them they're broken, you're killing them. Yes, some might recover from it, just as someone shot might survive, but you and I agree that shooting a kid is still a pretty bad thing to do, no matter whether they survive or not, right? So don't do it.
Ok, so after I've vented some of my anger, and proably shared way to personal details with everyone on here, back to business. Society is a pretty bad measuring stick for morals. Define the "average morals" to be the reference point, and Schindler becomes the most amoral man in the third reich. You see how this averaging is a pretty bad idea, right? Ok. Then to the disciplining thing. There's a difference between teaching something to your kids, and threatening them to do something. Teaching leads to moral understanding and a moral code. Threats will only teach that might is right, and the only thing holding together morals is violence. I think this worldview does point towards why religious people often ask atheist why they don't think the world will collapse into anarchy without the concept of a hell. Because hell is violence as the foundation of morals. If you want to affect any of those kids, go out and teach them why it's wrong instead of threatening to hit them if they do it again.
TL;DR: As a past victim of social ostracism, post makes me angry. Average morals are a bad idea. Disciplining kids will lead to obedience from threat, not to morals. Teaching will. So go teach
And if a child is 14 years old and pulling the stuff mentioned in the article, I'm sorry but they are defective. Maybe the sort of defective that can be fixed, but they are committing actual heinous crimes against other people. These are not the actions of kids filled with expectation and hope, these are the actions of little psychopaths with no empathy, and they need to be stopped.
Recording audio and video of people in their homes and then sharing it over the net, using it as leverage to get the victims to do things, harassing them in their homes...
This in no way equivalent to sneaking a look into the girl's locker rooms or rummaging through a bin for discarded porn! It's harassment, it's invasion of privacy and it's downright evil. That's before we even get into computer hacking.
You're right the tools don't matter in the slightest, but you completely miss the scale of the crimes. To throw it back at you - just because these kids are sat behind their computers at home doesn't make it any less heinous, or lessen the effects on the victims.
Statistically speaking, as a 14 year old you're not going to come to any earth shattering conclusions in morality that your parents, society, school, teachers, etc, have overlooked. Critical examination is an important life skill, but so is accepting that adults have a lot of insight into the world that you don't, and that society can teach you a lot without your having to learn things the hard way.
> My parent taught me they didn't care (or couldn't), my school taught me I was in the wrong place, and my peers taught me that I was scum.
Nothing about what I said is meant to assert that parents, teachers, etc, always say or do the right things. I'm necessarily speaking in generalities. I don't think your average teenager doing this kind of thing can raise the defense that their parents and teachers didn't teach them right from wrong. Some parents are terrible at being parents, and don't love and support their kids while also teaching them. But we're speaking in generalities here.
> Firstof, they're not defective. Don't even say a child is broken
A 14 year old is not a child. Not fully an adult, but not a child either. Respecting peoples' privacy should be well within the wheelhouse of your average teenager. And some people are broken. There is a bell curve of ability to function in society, and some people are X number of standard deviations away from the mean in a wrong way. It's unfortunate, but there is no point in not calling a spade a spade.
> Society is a pretty bad measuring stick for morals.
On average, society is a pretty good measuring stick for morals. There's all sorts of things you shouldn't do, that people don't do, because society tells them not to. There is a difference between blindingly accepting things like racisim, because in some contexts it is socially accepted, and acknowledging that even that same society still teaches you not to kick animals or kick little girls in the shins. Contemporary social understanding is a great starting point for your own moral framework, and one which you should lean on more heavily as a child and a teenager until your rationality and experience develop sufficiently to better analyze the world around you.
> Then to the disciplining thing. There's a difference between teaching something to your kids, and threatening them to do something.
Children are not adults. They are not capable of the rational thought of adults. They can be taught, but they cannot always be taught.
Right now, my 3 month old doesn't realize that I continue to exist when she can't see me. From 3 months to 3 years to 13 years, children and teenagers are still partially formed, their faculties of reason not fully in place. Your toddler isn't going to understand your reasoning with her, and while your teenager will usually do so, at the end of the day, sometimes the only thing they will understand is punishment.
You are talking not about the "average teenager" but about the "average teenager doing this kind of thing", yes?
One is a very tiny fraction of the other.
I think, looking at the tiny fraction, it is way more likely that (lack of) guidance by the parents/teachers/society is to blame than the kid being inherently "bad".
Especially since kids with developmental problems, that maybe have trouble developing their own moral compass, can still be raised with proper values, given the right environment. The converse (bad environment+neurotypical kid) however, is very likely to result in bad behaviour.
edit I am NOT trying to excuse any of this behaviour btw. Just saying that environment is a huge factor. And speaking from just over a year's experience teaching kids (computer stuff) roughly this age (a bit younger, 8-12 usually), quite a few of them have impressively well-developed moral compasses :) And the ones that are a bit more .. rowdy, I meet most of their parents at the end of the day, and I do notice some "patterns" (it's none of my business of course and I try to not judge, but little things like some make their kids thank me for helping them this afternoon--absolutely unnecessary for me of course, but it's still a signifier for caring about their upbringing and manners, etc)
Either way it is so 'not cool' that even a 14yo should know this.
They are inflicting real pain on another human being for laughs, and that is evil in my book.
There's a pretty big difference between a peeping tom, and a peeping tom who then mails you pictures taken through your window. One has no sense of boundaries, the other is taking glee in others' suffering and fear.
I'm a lot more concerned about the latter group - the lack of empathy is disturbing.
One interesting tidbit is that people seem to often post stories of interactions with their "slaves". It usually involves them trying to seem powerful and scary, but at the same time there's an undertone of wanting to connect with the people that they spy on. For instance, after one guy intentionally outs himself by posting on his "slave's" facebook profile, he chats with her and keeps trying to convince her (in a threatening way) to skype him so that he can show her how to install an antivirus. There are also a lot of interactions of the "put a shoe on your head and hold this sign and I'll stop hacking you" variety.
Edit: Also, don't miss that bit at the end about the RAT software author quitting in part because of the Syrian government's use of his software against rebels. Scary stuff.
Surely the basis for not being evil, is to not do bad things to other people by the command of your conscience?
I understand that the majority of the offenders are likely children, and I hope that most of them will remember themselves doing this with feelings of shame for a very long time, because these sort of acts are not merely pranks. They may affect their targets in seriously negative ways.
I guess I mostly think of them as dumb and immoral, but I do think that it's evil to have those kinds of interactions with people. I don't understand why people consented to holding up signs that said "pwned by...." - to me, that looks like bullying.
Actually, I guess I do kind of understand. I got prank called regularly on high school, and that felt pretty terrible. But I tried to along with it in the hope of defusing it amicably, and it took me a long time to admit that I was a victim and go to a third party to make it stop (the equivalent here would be to reinstall windows).
It used to be that such people would eventually develop the skills to interact with adult society, but hey why do all that work when you can just put a hacked copy of Sims 3 on pirate bay.
It makes me want to counter hack them (which wouldn't be very difficult) but I won't, because it would be illegal (and would potentially cause harm to third party).
It's that same reason most forum posters go crazy when a girl posts.
Obnoxious, insensitive, but evil? Like axis of evil - evil? Like evil marketing practices of pharmaceutical companies - evil? Nah. Just kids ... of any age. They were bothered by making little kid cry. Can't be that evil.
How would you feel if this was done to your Grandmother?
Actually I'd feel bit better because in computer scenario I would know what to do help her.
I say pure evil. Like holocaust evil, just at a smaller scale.
The (exclusively) peepers are probably just teenagers. The evil ones are those who don't do it for quick, funny sexual purposes.
The evil ones are those who do it for the fun of torturing the "slaves". The evil ones are those who use the collected material for profit (or silly cyber-cred) at the expense of a young girl's mind.
Like holocaust evil? Really? You are comparing moronic teenage hacking and bullying to the systematic, industrialized murder of millions of people?
But a moronic teenager potentially messing with another teenagers lives forever (Amanda Todd like), in a systematic and industrialized manner, just for laughs or some sociopath self-power acertion (not for science, not for profit, not for educational purposes) kinda reminds some nazi pseudo-doctor from the holocaust.
Oh boy, really? Godwin's law still going strong http://en.wikipedia.org/wiki/Godwins_law
It's a order of magnitude worse than looking in through a gap in someone's curtains.
They could be kicked all day and have their glasses broken (metaphorically speaking) at school.
All in all, I doubt the NSA (or any TLA) would hire them.
On that note, Japanese law requires cameraphones sold there to always make a loud shutter sound upon taking a picture, to prevent voyeurism etc. This is why the Nintendo 3DS handheld console's shutter sound can't be silenced.
Which means you'll wind up with the situation we have with TLS: hundreds of CAs, all trusted by default, most not even remotely trustworthy. Users will have no idea about these CAs and so the CAs will never have to worry about being loose with certificates.
You believe an amateur software developer should have to pay to get her app signed by a CA before she is able to distribute it? That someone else gets a say over whether or not a person can build an application?
And what if that CA gets popped? What if that CA makes a mistake? Do you furthermore think that even semi-technical people will think about these things enough to pick individual CAs?
There are a dozen problems with what you're saying, and I think you know it. What I really wonder is why you're coming into this conversation at such an intellectually dishonest angle, like you've never seen the arguments for/against what you're proposing before.
2. If they want to distribute it with that CA. Nowhere did I say CA's must require payments. Yes a CA gets a say in who they will verify. That's the point.
3. If the CA gets "popped" or makes a mistake you remove them from your trust list. I don't expect regular people to know how to do this, but they could ask someone they know.
4. You didn't even read my arguments, you are attacking things I didn't say, so you are being intellectually dishonest, not I.
What is your real motivation here? Nothing you've said is anything a) useful or b) practical.
I like this, and I am a software developer.
(Windows has something like this too. I don't remember the details.)
I don't want to choose between what Apple allows developers to do and "fuck it let it run free and do whatever it likes". Nor do I want the global choice in System Preferences to be between developers that paid $100 to Apple this year and Wild West.
Besides, there are enough legitimate uses for webcam viewing software that you could just take a regular signed program and configure it in a deceptive manner. Modern web-browsers allow camera access without additional software, for example.
I'm all for software being signed as a matter of routine but this is not something that it would help.
A solution to configuration files is to include them in what is signed or not allow your software to have the webcam on without also showing a window explaining what is happening and a button to turn it off. Modern web browsers typically ask for permission to use the webcam beforehand, and you can always close that page.
I guess there would still be shenanigans with signed binaries but there would be far fewer than what is going on here.
In other words, this isn't going away.
Signing does matter. Those may still be exploitable to run arbitrary code, but you cannot write code to disk that will get executed on start-up. The victim would have to open the same PDF every time they use their computer.
How hard would it be to launch an investigation into this ip address once you find it out? Would filing John Doe lawsuit allow you to do discovery on those ip addresses? Does 'an ip address is not a person' prevent you from further investigating who the actual person was?
Of course, the guilty party here is the software developers that are unwilling to do anything about the status quo. Also the vendors, Microsofts, Apples and Redhats.
These days it is getting even more common and acceptable to install binary packages on a system as root and often in unattended manner (OS and package "updates", pray-and-run RPM installs, etc).
More so, there used to be some hope in this area by Apple, where you would just copy an app to install, w/o being an admin. Now even Apple is moving to store apps where every install seems to want an admin.
Linux and Windows people have been always lost in that regard: MSI and RPM/whatnot have always been unquestioned standard (Linux people, however, have a choice to not install software as root and build it locally when necessary).
Until this (admin installs) changes, we are going to have to deal with malware. Fixing this would not solve all the issues, but would help a lot.
In the meantime, enjoy your PC owned by some teenagers overseas.
This is a hopelessly misguided argument. Could you maybe explain your reasoning a bit?
The argument for requiring admin rights to install is that the binaries are not user infectable. Now whether or not this leads to other problems is a different matter, but I don't see how making binaries user writeable on a box which receives automatic updates is going to make everything more secure...
If the OS is intact, the job of checking whether a user environment is compromised is easy and actually doable (as opposed to the case of trying to find malware on a compromised OS).
If, in addition, a user account has limited privileges (which it should of course), then even when compromised the chances of malware being able to do a lot are a lot less. For instance, turning off a webcam light being a root is probably easy, otherwise probably not. Setting up a server, listening for incoming connections and punching a hole in local firewall as root is available, but as a regular user is not.
Stop giving admin rights to your computer to random people (install software as an admin) and live much happier. As an additional benefit, there's never a situation 'I installed this and now computer is messed up, because Joe-the-dev ran "rm -f " with a wrong path as a parameter'.
Why hasn't the Commissioner gone after Microsoft in the same way they went after Google? This is caused by a fundamental flaw in Microsoft's products, and I don't think having to purchase and install security software should be the solution. Fix the software itself.
Then again, if people continue to execute some shady stuff found on the internet, the OS doesnt really matter all that much.
[1] http://cdn.arstechnica.net/wp-content/uploads/2013/03/bs1x.j...
The article itself had several images of male humans.
There were only ~3 screenshots that show the victims OS GUI. OSX usage is what, 8%? .92.92.92 = 78% chance? I hope you're not taking the article as evidence that you are 'safe' on your choice of OS.
The first time I ever felt that my privacy was violated on a computer I was a using NeXT slab.
I love my MacBook and MacBook Pro but... I'm putting a little piece of paper on the webcam "just in case".
Oh and the difference between nowadays and BO in the 90's is that nowadays virtually everybody who has a laptop has a webcam. That's quite a big difference.
* http://www.wired.com/threatlevel/2010/02/school-district-hal...