If You Used TorMail, the FBI Has Your Inbox
wired.com
wired.com
The FBI has copies of the servers TorMail ran on that they legitimately seized in an unrelated investigation (the servers were also hosting child pornography websites).
In the course of another investigation, the FBI found that orders for forged credit cards were being sent to a TorMail account.
The FBI obtained a search warrant for that specific account and then accessed it from their own copy.
This is not trolling the seized database for anything and everything that might be illegal. This is finding probable cause from another source and obtaining a specific search warrant. This is how it is supposed to be done. Why would you expect anything less from competent law enforcement?
The FBI is not the NSA. FBI cases have to hold up in the light of open court.
If you are upset about the fact that TorMail was not in fact secure, well, that's on the TorMail operators and on the users for trusting the entity that controlled TorMail while knowing absolutely nothing about them. Remember, TorMail has nothing to do with the Tor protocol, and is just the name someone gave their supposedly secure and anonymous e-mail service that they hosted on the deep web. For all anyone knew, the FBI could have been running TorMail all along.
The main concern is that something you did today may become a crime tomorrow, so now entire populations are apparently in the situation of Schrodinger's cat: we are both criminals and not criminals, and only the indistinct future will determine where we end up.
If you want a society where an individual is free to pursue their interests as long as they don't hurt anyone, it makes a lot of sense to have a transparent set of rules that are applied equitably to every citizen, regardless of their demographics or background.
If you want a society where the individual is completely at the whims of mysterious and unknown forces that can destroy their life utterly for no apparent reason at all, well then carve out special exceptions for some while reserving harsh punishments for others. Introduce secret courts, evidence and trials... Institute a "permanent record" of someone's behavior that can be used to manipulate them as desired. Break the well-thought out control systems that help avoid abuses all to make "LEO easier."
I'm assuming every experience you've ever had with law enforcement is positive?
What you have said above is correct, however it is not the "main" concern. There are numerous concerns. That is one key one. Since I have not seen others post other key concerns, I will also contribute an additional concern:
Sensitive data left lying around are/is very tempting to use for illegal economic and blackmail gains. The FBI in particular has a pattern of getting indicted for re-selling sensitive data, even before massive amounts of "seize now, convict later" was taking place.
Source?
Ex post facto laws are unconstitutional in the US.
The Fourth Amendment protects US citizens from unreasonable search and seizure. Clearly that is being violated as the recent ruling on NSA data collection has pointed out.
As are you and I. You can't be retroactively convicted of a crime if it was not against the law at the time.
>No person shall be held to answer for a capital, or otherwise infamous crime, unless on a presentment or indictment of a Grand Jury, except in cases arising in the land or naval forces, or in the Militia, when in actual service in time of War or public danger; nor shall any person be subject for the same offence to be twice put in jeopardy of life or limb; nor shall be compelled in any criminal case to be a witness against himself, nor be deprived of life, liberty, or property, without due process of law; nor shall private property be taken for public use, without just compensation
>In all criminal prosecutions, the accused shall enjoy the right to a speedy and public trial, by an impartial jury of the State and district wherein the crime shall have been committed, which district shall have been previously ascertained by law, and to be informed of the nature and cause of the accusation; to be confronted with the witnesses against him; to have compulsory process for obtaining witnesses in his favor, and to have the Assistance of Counsel for his defence.
>Excessive bail shall not be required, nor excessive fines imposed, nor cruel and unusual punishments inflicted
In other words, clearly, The Fourth Amendment does NOT protect anyone from NSA's violations.
There are not a "lot of unconstitutional practices" that are law in the U.S. There are a lot of people who read the words in the Bill of Rights extremely broadly and without historical or legal context, and then put up poorly-designed web pages about all the "unconstitutional" things they have discovered.
If anything, the last 15 years has shown me that 'anything' is possible.
So is warrant-less wiretapping, but that didn't stop NSA.
There are two main problems with the United States, the first is that too many of us are ready and willing to trade personal freedom for economic and physical safety. The second is that we allowed money to control politics.
The only thing that's natural are the laws of nature, otherwise known as physics, and there is no law of physics that prevents me from torturing someone.
Good thing I didn't imagine the idea of rights would physically prevent you from torturing someone. Basically, rights are an idea meant to help us in drawing boundaries between what's acceptable behaviour and what's not. But it's got nothing to do with the government, and everything to do with reason, logic, consistency and common sense. A government or a piece of paper can't grant any rights or take any away, and in fact, governments only violate our rights.
Imagine your the FBI IT guy. How long do you think it would take YOU to walk into an unknown datacenter, locate the specific computer / IP address referenced in the warrant, connect to that computer and copy just the minimum amount of data necessary to prosecute said bad guy (just his e-mail .mbox file? or is this a windows shop..grab the pst? What about backups? What about his contact list? All this just for e-mail!)
Often times he probably doesn't even know the specifics of the case. Maybe just let the local DataCenter guy copy the data off for you right? Well hopefully hes honest and not involved in the crime.
The fact of the matter is, it is 100x easier to walk in, grab the servers of interest and walk out. If the FBI IT guy is smart and prepared he just brings tools to remove the hard drives from the server, copy them and put them back. BUT, if theres child porn, contraband, etc. the FBI is NOT giving that computer back any time soon. Doesn't matter who owns it.
Reductio ad absurdum with your argument and we should just let the FBI run all internet infrastructure, because it is expedient for the FBI, it makes life easier on the FBI, and they can inspect your data to their heart's content. It is a much preferable situation to the one where an FBI agent has to do something complicated.
Nowhere do I see you advocating for the innocent whose rights are infringed upon.
Grabbing the servers is easy, but arguably because so much unrelated data could be on a shared server these days, it's unreasonable to just grab everything. Many other people are affected, and unrelated data is collected and evaluated later for purposes unrelated to the original collection purpose. This circumvents a reasonable expectation of privacy, and strongly shifts the balance of power from the regular citizens to the agency hording the data. Especially in light of the plea-bargaining justice system in the USA, where the data can be and is used to threaten and coerce, this is worrying.
EDIT: missing word
It sounds like your response is based on broad ideological convictions that have little to do with the commenter's argument. He or she is arguing that the NSA is not equivalent to the FBI because the FBI, in this case, did follow established procedures to obtain a conviction.
If you want a society where the individual is completely at the whims of mysterious and unknown forces that can destroy their life utterly for no apparent reason at all, well then carve out special exceptions for some while reserving harsh punishments for others.
In order for this comment to be relevant, you'll have to establish how it relates to the details of this case.
My primary concern is the now known strategy of parallel construction. The FBI could be trolling the emails for crimes then using that illegal evidence to find ways to get a warrant to allow the previously illegal evidence into the case.
If this was Fed Ex distribution center that had been seized it would have been treated very differently. They would collected the mail pertinent to the case and rest would have gone away. If they were to confiscate the whole building holding all of the mail for a later time in case they needed it there would be a huge back lash. But because it was email and we haven't set ground rules most people don't bat an eye, even if it's their mail that's been taken.
As a parent it's really difficult not to be supportive anywhere child porn is involved. It's an issue that is so emotional for me that my first instinct is that I would give up everyone's privacy in the hopes of putting a dent in the abuse of children. Even if it only saved one child, emotionally, it would be worth it to me. Logically I realize that once these systems are in place there is no stopping them, and they will be used for everyone else's emotional/political hot button. I only bring this up because having the reaction I do allows me to understand what other people are feeling when the issue is around terrorists/hackers/fraud/whatever.
That shouldn't have been a surprise, that should have been expected.
Probably because the stories that make sites like HN are all the 'outrage stories' where things have gone off the rails.
It's also not clear to me (maybe it is to others) where the limit on seizures is. In the extreme case, AWS is used for all kinds of criminal activities. Can FBI seize copies of AWS, and then with warrant go back and get evidence for other investigations? I doubt they would try, but somewhere between this extreme and the child porn server extreme is some sort of inflection point, both practically and legally.
Step 2: Seize entire server.
https://en.wikipedia.org/wiki/COINTELPRO
Not necessarily.
There should be legal controls over what information is seized. Requests should need a warrant, signed by a judge. "Accidental" seizures of too much information should be reported to the body who provides scrutiny and oversight.
Some of those accidental seizures should be criminal offences and lead to punishments for the agencies involved. (Or the individuals).
While the UK has a lousy record on this (with bizarre interpretations of law so spies can say they obey the law) the reports from the scrutineers are interesting reading.
Here's a PDF of the latest report: http://iocco-uk.info/docs/2012%20Annual%20Report%20of%20the%...
Some parts of the UK government use statistics carefully and they have real statisticians available to produce and review the charts. This document? I'm not so sure. While the raw data can be trusted the use of pie-charts is usually a flag for me, and this document does include a few of them.
Why are articles like this so shocking?
Have any of you guys had IQT reach out to you, the CIA's investment ARM? They are very active in finding tech companies that can decipher this data, profile everyone automatically, categorize people, and try to predict their next behaviors.
Now the FBI is tapping that vast trove of e-mail in unrelated investigations.
That says pretty much all about their methods.
Any evidence derived from or linked to this trove can AND SHOULD be tossed out of court.
I'm not sure what to think of it; it's just an observation.
Among the reasons I argue so strongly against it is because I've seen how very similar methods work, myself, direct personal experience. Oh, and I was the party benefiting from the disclosure. Turns out that virtually all of what we had was in fact legitimately obtained.
As for the insurance argument: what state do you live in? Do you have your car smogged? Are you aware that your smog data, which comprises a rather detailed data record, is sold in several large states (California and Washington, off the top of my head, along with a few others) to ISO, the Insurance Services Office (descriptive name, no?), a division of Verisk, to rate your auto insurance. See:
http://www.verisk.com/underwriting/
http://www.iso.com/Products/QPC/Quality-Planning-Corporation...
So, the question is: were you made aware of this when you brought your vehicle in for smogging? Did you realize that the dataset was 1) being collected, 2) being sold, and 3) could materially impact your insurance costs?
Moreover: what's the equity here? Yes, as it turns out, miles driven is a significant statistically correlated risk factor in insurance costs. But what is the social purpose of insurance, how should those costs be allocated (often it's the less financially able who drive further to work because they cannot afford to live nearer their jobs), and what are the social equity effects of a hidden pricing and rating factor?
Yes, insurance companies can perform useful functions. They're among the leading business voices for climate change risks, as the underwriting costs directly affect them. Insurance underwriting has either directly or indirectly supported huge improvements in workplace and product safety. Where it used to be possible for companies to argue that negative outcomes were "accidents" and "acts of God", comprehensively compiled incident statistics correlated with causal factors showed that specific patterns of behavior, design, use, etc., were predictably associated with accidents, damage, injury, and/or death.
But gathering that information in a covert fashion strikes me as fundamentally unjust.
So here is a question: the last time I had my car's emissions checked in Washington state, my car reported that it was not ready to report its status because I had disconnected the battery a week before, apparently resetting the stuff that it needed to report. I had to drive around for two hours on the highway before going back to the emissions place to have it re-tested.
Is there any value in unplugging the battery shortly before getting your emissions checked?
http://www.kingjamesbibleonline.org/Psalms-130-3/
> If thou, LORD, shouldest mark iniquities, O Lord, who shall stand?
Also this, from a somewhat similar source, Cardinal Richlieu:
http://quotationsbook.com/quote/19331/
> If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.
And finally, this:
http://online.wsj.com/news/articles/SB1000142405274870447150...
> The average citizen commits three felonies a day.
... I'm not sure anyone can survive perfect application of the law.
I'd deleted my initial account after only a couple of weeks.
I'm now winding down my pseudonymous account and most Google activity.
We don't want a government and law enforcement that route around the Constitution.
Law enforcement is not an end in itself, it is only one of the tools a government has available. There's nothing in the constitution that says "you must prosecute as many people as possible".
For instance, if a friend on Facebooks cross-site posts a photo that they don't have a license to, you've broken copyright law by downloading it too. Again, nominally, convicting you requires "criminal intent", but this has been getting weaker lately too. This is just an easy example; there's a lot more and many worse ways they can get you, but this is an example where probably everybody on the Internet has a record of many of this sort of violation on file somewhere in the government right now.
"Law enforcement is not an end in itself, it is only one of the tools a government has available."
And it was never meant to be a tool that the government had at hand against all of its citizens, but if we aren't there now, we will soon.
US of A already officially admitted that they've lost track of all the federal laws they have, so it's pretty sure at this point that everyone would be found guilty of breaking some obscure, forgotten rule that happens to be in force, if prosecutors would look hard enough.
Citation needed.
- John Oliver
That honestly doesn't sound too ridiculous.
Build case. Apply for warrant.
Oh look, surprise surprise, the warrant turned up something.
Yes, if we trust law enforcement, blah blah blah. The point of having checks on government authority is so you don't HAVE to trust government. Government is not to be trusted; it is to be kept in check. Your safety, your rights, should not be contingent upon trustworthy official.
People with real secrets to hide ought to escalate to steganography + subliminal channel communications.
Almost everyone has hundred thousands of emails laying around. All in your name, all forever stored, all with a legal signature on them binding you, and each with a short text message with no context. It is very often used as evidence, attached with a conjecture provided by the prosecutor. The defended is then forced to try defend themselves both regarding the conjecture, but also having to remember and explain the original context.
It has been used in a profile case to "prove" conspiracy, and has also been used by prosecutors to move public opinion by providing snippets (official sanctioned leaking) to media.
This is why I view running a email server without full disk encryption to be negligence, and that everyone should have their own mail server. Until the legal system have caught up with technology, its not much more one can do.
Wait - can they do that? Why can they do that?! Isn't that like a fishing expedition? Now they're just looking for crimes from that database trove? I've never used TorMail but screw everything about that!
This is why we need to pass some strict laws against mass collection of data, and against using data in "unrelated investigations".
I've been called out by no less than a Linux evangelist, working at Google, for being so rude as to PGP-encrypt my email to him "because it was such a hassle to open".
When the ICIJ was doing its extensive collaborative investigation of offshore banking, the team evaluated using PGP, but ultimately abandoned it:
The project team’s attempts to use encrypted e-mail systems such as PGP (“Pretty Good Privacy”) were abandoned because of complexity and unreliability that slowed down information sharing. Studies have shown that police and government agents – and even terrorists – also struggle to use secure e-mail systems effectively. Other complex cryptographic systems popular with computer hackers were not considered for the same reasons. While many team members had sophisticated computer knowledge and could use such tools well, many more did not.
http://www.icij.org/offshore/how-icijs-project-team-analyzed...
It's little use if I have and use PGP if I can't convince my counterparties to do so.
Sad, too.
What's hard about GPG or S/MIME-encrypted mail? You set up the thing to integrate with the MUA once (in GPG's case, S/MIME are supported out-of-the-box with most common desktop MUAs), then the only hassle is to enter password on startup or when reading the first message. And lock the computer properly when you're getting away.
Write a message, tick "encrypt" (or don't untick it), send, done. Receive a message, see a badge "encrypted, verified", type a password (if key's not cached before), read it as usual, done. I fail to see how anything can be easier and less obstructive than this.
At least, my only problem with encrypting email is that practically no one of my peers have keys published. This could be easily solved if mail client software vendors could make their products ask user to generate and backup a keypair on install.
Oh, right, encryption has problems with webmail. Extension/userscript kludges are insecure (unless they open separate window/tab for anything private) and break with every other update.
I'm with you. I've had mutt set up to use PGP for ages. I've configured a half-dozen or more other MUAs to use PGP/GPG. If I've got an MUA that doesn't support PGP, I can do ASCII armor encryption and decryption easily.
That's you and me, the geek set.
The Google guy I mentioned: he's just as versed. And yet, felt he should give me grief.
If you've got a Linux desktop, odds are that the tools you need are integrated. Congratulations, that's ... about 0.5-3% of all desktops depending on whose numbers you trust and/or like.
And an increasing number of users are now on smartphones and tablets. Yes, I've got K9Mail, but I've received no, and sent very few, encrypted emails.
In corporate environments, you get the tools you've got on a standard desktop and that's it. I've had a hell of a time convincing engineering and dev teams to create and use PGP/GPG keys and/or use SSH key authentication rather than passwords. I've been at shops recently which still use rsh (and had the pleasure of giving the solution to a user creating large numbers of client sessions: oh, yeah, SSH doesn't have the 512 max outbound connections limit that RSH does due to its privileged port use). Sigh.
Key distribution is a huge part of the problem. In large part it's what PGP Corp (now part of Symantec) addressed with its appliance solutions: a box that creates, signs, manages, and automatically applies keys for users. I don't exist, and yet I've got a key published (and embedded in my G+ profile coverphoto). Oh, what the heck, let's add it to my HN profile.
As you note: webmail, mobile, smartphone, and Windows are all problematic. But more than that: people don't fundamentally understand the technology they use (part of a much larger rant and topic), and this stuff confuses them utterly.
Encryption requires everyone in the thread to support it. Need to CC in the C-Level exec on something? Good luck getting them to setup it up in their outlook and use it properly. Even with my help, it took a good 30 mins to set my dad up with GPG on Windows/thunderbird. Have to figure out which software you need, the nomenclature for key generation etc is different in each program.
Encryption breaks search, at least in thunderbird. You can't search through the encrypted messages and they aren't indexed. This makes sense if you're sending very sensitive data perhaps, but for general business correspondence it's reduces productivity. There's an open bug in EnigMail by a user who saves every email in plain text to use regular file search tools. That's useless.
There's the aforementioned webmail. Tons of people only use webmail, and there's no way to interact with them. More importantly in my book, encryption breaks mobile access. Sure, there are addons for gpg on android, but I don't trust my private key on my phone. In the near future there may be some way to use a yubikey with NFC for passing in the private key, but that brings in it's own set of problems.
Lastly, it's the cost/benefit that really keeps encryption use from being wide spread. It costs you time in getting each contact you use to use it, time dealing with being unable to search, time setting up your phone to securely access mail, unable to use webmail at all, and for all this you really only get two benefits: Prevention of e-mail interception by intelligence agencies or internet backbones and access to your mail by your e-mail provider. If I'm not concerned about these, just using proper TLS access for IMAP/SMTP prevents anyone I'm actually worried about (wifi interceptor, bad ISPs) from reading the mail. For mail inside an organization with their own mail server, mails are never anywhere unencrypted than company owned equipment, TLS in transit.
Doing encryption right is hard, for 99% of email the threat model just doesn't justify the expense in time and headaches so the NSA doesn't know there's a conference call at 11am tomorrow or that you should call grandma tomorrow because it's her birthday.
Maybe he has a vested interest in not protecting people's privacy (or just a cavalier attitude towards privacy).
NZ PM John Key famously said: "If you don't want to be spied on, hide under a blanket." http://www.thecivilian.co.nz/if-you-dont-want-to-be-spied-on...
Actually, hiding under a blanket won't help. I don't think Americans get it yet, so let me shout it: YOUR GOV'T IS SPYING ON EVERYTHING YOU DO!
They don't wait for you to commit a crime and then get a warrant: They collect everything!
And not only the US government, but governments all around the world. In fact, the British government spied on users of Angry Birds, along with the NSA. Source: http://www.nytimes.com/2014/01/28/world/spy-agencies-scour-p...
And this is nothing new: "In 1862, Lincoln authorized sweeping control over the American telegraph infrastructure for Edwin Stanton, his secretary of war. Telegraphs were re-routed through his office, and Stanton used his power to spy on Americans, arrest journalists, and even control what was or wasn't sent." Source: http://www.theverge.com/2013/7/6/4499636/how-lincoln-used-te...
There you have it: The US government has been using NSA-style electronic surveillance to spy on its citizens since at least 1862. So do you really think anything's going to change now all of a sudden?
FTFY.
FTFY.
FTFY.
Of course the author seems to disagree, especially when you look at the title, but that seems only because of some odd fascination with gag orders which seem largely irrelevant in real life as several comments have pointed out.
"Strength through unity. Unity through faith."
That's disgusting. "We use the word saga in more than one of our games, therefore it's our game word and it's unfair if other people steal that word from us." ...