Thousands of Turks accused of using Bylock app despite never having used it
1–10 of 200 posts
Re: Thousands of Turks accused of using Bylock app despite never having used it
#2Re: Thousands of Turks accused of using Bylock app despite never having used it
#3Even if we ignore the horrible government and bullshit reasons why they're considering installing an encrypted chat app a "crime", they should at least use proper evidence for the convictions, like a dump of the phone's memory with the chat app installed on it, and not a simple DNS lookup/HTTP request to the chat app's domain.
Re: Thousands of Turks accused of using Bylock app despite never having used it
#4As Turkey becomes increasingly alienated from the EU, Putin looks to gain another monster.
Re: Thousands of Turks accused of using Bylock app despite never having used it
#5Re: Thousands of Turks accused of using Bylock app despite never having used it
#6FTFY: a shitty government is putting people in jail. Even if we ignore the horrible government and bullshit reasons why they're considering installing an encrypted chat app a "crime", they should at least use proper evidence for the convictions, like a dump of the phone's memory with the chat app installed on it, and not a simple DNS lookup/HTTP request to the chat app's domain.
Re: Thousands of Turks accused of using Bylock app despite never having used it
#7Re: Thousands of Turks accused of using Bylock app despite never having used it
#8> Beşikçi said it was due to a single line of code, which created a window "one pixel high, one pixel wide" — essentially invisible to the human eye — to Bylock.net. Hypothetically, people could be accused of accessing the site without having knowingly viewed it.
This Bylock.net-accessing code was apparently packaged into other applications, causing people who weren't using the actual secretive chat app to be associated with the group:
> Akif Demir, a self-described conservative nationalist, wished the worst on people accused of using Bylock and being associated with the Gülenists. That is, until authorities said he was one of them...In October 2016, when his wife was pregnant with their first child, Demir was called into his principal's office. He wouldn't be allowed to work at the school — or anywhere else for that matter — anymore. He had been deemed a Bylock user.
The headline isn't inaccurate, but the main problem, or "bug", seems to be the government's hyper-willingness to throw people in jail for having accessed, even pinged, a forbidden server. And it wouldn't be surprising if this "bug" were being exploited by the purported outlaw group behind Bylock to mock the government's oppressive surveillance policies.
edit:
FWIW, previous coverage of "Bylock" focused on how the app itself was cracked in 2015:
https://www.theguardian.com/technology/2016/aug/03/turkey-co...
> Starting in May 2015, Turkey’s intelligence agency was able to identify close to 40,000 undercover Gülenist operatives, including 600 ranking military personnel, by mapping connections between ByLock users, the Turkish official said.
Visiting "bylock.net" currently yields an empty page:
$ curl -IL bylock.net
HTTP/1.1 200 OK
Content-Length: 0
Content-Type: text/html
Last-Modified: Fri, 03 Nov 2017 22:47:45 GMT
Accept-Ranges: bytes
ETag: "4c5039c4f554d31:0"
Server: Microsoft-IIS/7.5
X-Powered-By: ASP.NET
Date: Mon, 22 Jan 2018 13:35:36 GMT
According to WHOIS, bylock.net was created on 2017-11-01. But that seems too small of a timeframe for the trouble mentioned. Not sure how to use the Whois-history lookups, but Internet Archive pinged the server in 2016: http://web.archive.org/web/*/bylock.netedit 2: Googling around for "bylock.net", it appears an IT company (Fox-IT) was asked by Turkish lawyers to analyze the government's methodology. They published a report on Sept 2017 basically saying the government's "argumentation is seriously flawed"
https://foxitsecurity.files.wordpress.com/2017/09/bylock-fox...
Re: Thousands of Turks accused of using Bylock app despite never having used it
#9FTFY: a shitty government is putting people in jail. Even if we ignore the horrible government and bullshit reasons why they're considering installing an encrypted chat app a "crime", they should at least use proper evidence for the convictions, like a dump of the phone's memory with the chat app installed on it, and not a simple DNS lookup/HTTP request to the chat app's domain.
No, it was a single line of code. We should ban codes like this.