Lawyer representing whistle blowers finds malware on drive supplied by cops
arstechnica.com
arstechnica.com
I guess felony hacking charges are only for teenagers changing desktop backgrounds.
It is a catastrophic failure of procedure, that invalidates this, and possibly all copies of this evidence causing it to be judged inadmissible.
From wikipedia[1]: When evidence can be used in court to convict persons of crimes, it must be handled in a scrupulously careful manner to prevent tampering or contamination. The idea behind recording the chain of custody is to establish that the alleged evidence is in fact related to the alleged crime, rather than having, for example, been “planted” fraudulently to make someone appear guilty.
Regarding other comments in this thread about law enforcement being held to a higher standard, they would be. The higher standard is that when they fail to follow proper procedure like this, the effect is the evidence (and often the entire case) is summerly dismissed, and the defendant cannot be tried again for the same crime. the entire US legal system has this built in bias. Whereas a defendant in a similar position of supplying discovery documents would not be held to the same standard risking summery judgement, and might be able to provide replacement copies for discovery, and continue with the definse more or less normally.
Some possibilities:
* if the police computer was itself infected and the malware was trying to propagate
* The data was copied from a drive or computer that was infected
There's really only 4 possibilities, and they're all significant.
1) PD is responsible, and intentionally infecting defense attorneys with malware. Major obstruction of justice.
2) PD is responsible, and has been hacked. At a minimum, all their computer evidence is tainted; who knows if someone has been using their access for ill as well. Access to police DBs is useful for all sorts of nefarious purposes.
3) Defense attorney has faked the whole thing. Noteworthy in its own right; defense attorneys are pretty used to losing as a matter of necessity so for one to go on some kind of intentional crusade against the local PD, especially in such a public and falsifiable way... No judge will sign off on criminal sanctions here without a thorough investigation, so this is extremely unlikely barring a psychotic break (which does happen now again, it's a high-stress job).
4) Defense attorney has been hacked. Who hacked him? Have any of his clients been affected? Is someone, perhaps a technically sophisticated someone, targeting defense attorneys?
Perhaps the proper move would have been to surveil the malware without revealing that you know of it. Could prove/falsify #4, or implicate PD conclusively if #1.
"Additionally, the placement of these trojans, all in the same sub-folder"
All in the same directory! Whoever it was, he certainly was even tidy.
Besides, we're talking about evidence here. Even if it was "just" the case of police computers infected with... three (three!) backdoors, that would be extremely serious.
If you're dealing with malicious people, then that phrase completely loses its already low value.
What's the best way to counteract this? Only plug foreign drives into a dedicated computer, probably running Linux, so you can scan it and copy the files you need before letting them touch other machines?
What's demonstrated in this article is extremely inelegant and clumsy. Truly malicious rootkits and the like are a bit more sophisticated.
The Pi doesn't have a BIOS or EFI on board, it uses a special partition on the SD card to POST from, so there's no worry of the device itself being infected.
The real mode opcodes needed to bring up a kernel are a mess on Arm, with each manufacture using their own instruction set.
What is different is the boot sequence and system register layout. On a PC you can write one bootloader that works across multiple systems because either the peripherals are at the same place or BIOS/UEFI code is provided to sort it out for you. This is not the case on ARM; uboot and devicetree are attempts to fix it.
It might be possible for a malicious script that gains root access to replace the SD card firmware with something that looks clean on the Pi, but delivers malware when some conditions are met.
The SD card is not part of the RPi; there's nothing on the board itself that is writable.
If you're really paranoid, do everything with a separate machine.
I love how they dont have resources for this, but if the plaintiff happens to speak some International language for which they dont have a translator, they fly one in from wherever they are available and pay them huge amounts of money for maybe 2 hours of work (I know its a but more complicated then that, but its still resources), but you cant dedicate a few thousands to verify the how the stuff got on to the hard drive.
[1] Corrected spelling etc: Need more coffee
Police officers take oaths to protect the public on behalf of the US federal & state governments, and to uphold the Constitution. Breaking these oaths and abusing the power they are granted for personal gain or to cover up things that occurred on duty is, to be blunt, treason. It's easy to be a bad police officer who deserves to be fired for egregious negligence or excessive force or poor performance, but premeditated attempts to protect their own from the justice system represent the worst sort of insurrection this country can realistically face. I don't see why a terrorist or a Soviet spy should receive one sentence, and an officer running a corrupt police department should receive another: They are all trying to overthrow our functioning government.
Did that happen here? I don't have any idea. But when internal affairs ceases to act aggressively to investigate this sort of thing, it casts the entire department's fidelity into doubt.
First, the lawyer most likely found the malware via an anti-virus software and did not detect a new malware specifically targeted to him. Second, the police probably used the drive at an unsafe machine.
Is it only me who finds this illogical nonsense? It sounds like if I get a "real world" infection like xyz flu - I have the right to seek criminal action against the person who got me that infection.
Even if you give the police the benefit of the doubt and assume zero malicious intent, the fact that malware appeared on the drive suggests either:
(A) Mishandling of evidence by cycling it through an insecure/unofficial system.
(B) Official systems have been pwned, and they are no longer trustworthy!
And the malware was inside a folder that had been created on the drive called "Bates Court Order". Meaning that the drive wasn't infected already, but somehow -after- the folder copying all the documents for discovery onto there, these several different pieces of malware all decided the best place to load themselves onto this drive was in this particular folder.
EDIT: Ahh yes, downvoted for agreeing. Fantastic guys!
And yes, downvoting into oblivion articulate comments not at all devoid of content really has become endemic here, and many (though certainly not all) of those I read anyway were obviously downvoted for disagreement, often political. The result is a strong hive mind at HN. (I've seen seen that opinion on HN voiced outside of HN more than once.)
Maybe I'm biased, but I personally had the opposite feeling, the majority of the comments I see grayed out are usually somehow aggressive/salty rants that don't really try to bring anything useful to the thread, and the few other ones are comments with technical details that are plain wrong.
I'm not lobbying for changes. The whole up/downvote business is really hard, maybe there's no better way. Just thought people here might be interested in the fact that HN has been getting somewhat of a hivemind reputation, lately.
> Brains, people, brains. Use them, please.
Adding insults to your comment does not make for a better discussion.
Of course, it is a lot harder to prove if you are saying something different than the truth.
I think that's likely to be a lot more difficult than you think: how does an independent observer know what the count of good and bad events is, rather than the count of good & bad published events? The trouble is that if an event isn't published, it's practically invisible to an observer.
This is a related issue to the fact that many sensational crimes are less common today, but perceived to be more common due to over-coverage in the media.
The former. Possibly also the later, but definitely the former.
Edit: the fact that someone saw fit to down vote this comment is proof of idiocy, in and of itself. Just because you don't understand how the criminal justice system works, is no fault of mine.