Live data from Hacker News

Federal agents seek to loosen rules on hacking computers during investigations

bloomberg.com

11–20 of 53 posts

Re: Federal agents seek to loosen rules on hacking computers during investigations

#11
Out of curiosity- all I see in the news & on the boards is backlash against the government when these sorts of programs come up. Can anyone provide thoughtful suggestions on how the fundamental adaptation the feds are seeking- improved ability to conduct digital espionage- could be implemented in a positive way?

I do think the notion that traditional rules for search & seizure need to be updated for the modern age might hold some water. For example, destruction of evidence has become easier, and catching someone "in the act" is probably harder.

I don't believe in the idea that the feds should have zero access & zero surveillance ability. Unfortunately I am unsure how to give the ability to match (in spirit, not in letter) the functions they have in the real world without incurring a big privacy hazard.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#12
post #9

A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amoun…

> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. > More and more network adapters seem to have DMA access to your computer. With an I…

> This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.

Bingo. Even if you go all-out with security and only browse the web with a pure text web browser through Tor running on a VM that you purge after every use, use full-disk encryption with plausible deniability, fully shut down your computer and wait until the RAM is cool before leaving, inspect your computer for NSA/other implants every time before boot, tape your webcam and mic, never use your real name, and whatever else you can think of, you're just going to go nuts from all the paranoia, as well as from realizing all the myriad ways your security could still be broken (don't forget to check the keyboard for a built-in logger and look inside your case for PCI cards you don't recognize, and hope they don't have any implants that look convincingly like something you'd recognize as yours). Never mind that this isn't a very viable way to do most things most people actually use their computers for, like personal email, online banking, social networking, and so on.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#13
post #9

A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amoun…

> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. > More and more network adapters seem to have DMA access to your computer. With an I…

Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted.

This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion.

Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if hardware becomes compromised, Tails will offer much less protection.

Here's an interesting section of the article:

The department must describe the computer it wants to target with as much detail as possible. For example, an investigator may be covertly communicating with a suspected child molester and know an IP address, and then obtain a warrant to use malware to find the actual location. In the case of botnets, malware might be used to try to free the compromised computers from a criminal’s control.

Imagine if child molestors begin using Tails. The government response may be to try to set up some kind of "Tails dragnet" via compromised network interfaces. It should be possible for a network adapter to detect that Tails is running. At that point, since it has DMA access, and since few people use Tails at any given time, it should be possible to instuct a network adapter to search through a computer's memory for evidence of activities that the government doesn't like. Since Tails offers strong anonymity protection, there's no way to describe a computer "as specifically as possible" other than to say "it's running Tails while watching child porn."

The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught. "If someone is using a strong anonymity tool and GPG to hide their conversation, we should probably configure their network card to monitor their activity."

Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#14

Didn't these folks take an oath to defend the US constitution? This pretty clearly violates 4th Amendment protections against unreasonable search and seizure. Yes, I'm not a lawyer, so I don't know what "doctrine", "touchstone" or "Three Pronged Test" makes the clearly unconstitutional into something lawfully constitutional, but that's a lawyer problem. Beyond practical considerations, like this makes the FBI into an…

Last time I checked, the 4th Amendment was about "due process" and "but upon probable cause".

Everyone seems to forget about the "Probable Cause" line.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#15

A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amoun…

The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to.

The government has always had access to everything if they a) really wanted to and b) had just cause. That's why search warrants, tailing suspects, court-approved phone taps, bank account freezes, etc etc etc exist.

The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#16

A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amoun…

> Perhaps future laptops are going to have 3G access embedded right into them which consumers can subscribe to for some low monthly fee.

We're getting bit off topic here, but my colleague has a 2-year old Sony Vaio laptop that has this. He also has a SIM card for it that came for free with his €50,- internet/tv subscription (incl more monthly GBs than he needs).

Re: Federal agents seek to loosen rules on hacking computers during investigations

#17

A couple weeks ago, when I asked someone how to verify on demand that a BIOS isn't compromised, someone else quipped "Could be the processors too, better forge those by hand." https://news.ycombinator.com/item?id=7609780 In fact, it turns out the future is probably headed in that direction. All mobile phones are already compromised; every phone has a proprietary baseband chip with full remote DMA access that no amoun…

The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. The government has always had access to everything if they a) really wanted to and b) had just cause. That's why search warrants, tailing suspects, court-approved phone taps, bank account freezes, etc etc etc exist. The notion that the government ought to not…

The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent.

I didn't intend to argue that. I'm saying that strong anonymity OS's like Tails will force governments to do dragnet surveillance using compromised hardware in order to track suspects down. There is no way to tailor surveillance to an individual using Tails, because it's set up to hide your IP address at the OS level (assuming Tails is implemented correctly).

Assume child molestors begin using Tails or whatever environment that prevents FBI browser exploits from working. What then? There's one recourse: the government can set up your network card to monitor when you're using Tails for unlawful activity. And since it's very difficult to come up with a "footprint" of an individual Tails user, i.e. some way to monitor or attack one specific individual, this is likely to force the government into monitoring all activity. This can be done via compromised hardware, like a network card, which can be remotely configured to monitor memory for specific trigger conditions like "user is running Tails, and main memory contains specific terms for underage children."

Sure, it sounds unlikely right now. But this is the general direction that technology has been headed in. How much ground should we concede in this debate? Is it ethical for a government to be able to subvert someone using strong anonymity tools if it forces them to broadly target everyone using such a tool?

More broadly, what mechanism should we approve of the government using to inject your computer with code? If the government has DMA access to everyone's computer, then that hardware could be configured to monitor which operating system you're using, and only triggered into actively targetting you specifically when certain conditions arise, such as using a strong anonymity tool, or a certain specialized browser that child pornographers also happen to use. Should the government be allowed to be proactive in its hunt for offenders? Are we comfortable with a hardware device watching which OS we're running? There are a lot of issues that seem worth thinking carefully about.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#18

Earlier quoted context omitted.

The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. The government has always had access to everything if they a) really wanted to and b) had just cause. That's why search warrants, tailing suspects, court-approved phone taps, bank account freezes, etc etc etc exist. The notion that the government ought to not…

The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent. I didn't intend to argue that. I'm saying that strong anonymity OS's like Tails will force governments to do dragnet surveillance using compromised hardware in order to track suspects down. There is no way to tailor surveillance to an individual using Tails, because it's se…

Yeah, it is a damn tough question. Criminals have more tools than ever for operating under the radar, so restricting agents to traditional rules for investigation & surveillance seems like a mistake. But on the other hand, how do you grant increased surveillance capabilities to counter increased covert capabilities, without ruining privacy? Basically, it's like privacy is caught in the crossfire.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#19

Didn't these folks take an oath to defend the US constitution? This pretty clearly violates 4th Amendment protections against unreasonable search and seizure. Yes, I'm not a lawyer, so I don't know what "doctrine", "touchstone" or "Three Pronged Test" makes the clearly unconstitutional into something lawfully constitutional, but that's a lawyer problem. Beyond practical considerations, like this makes the FBI into an…

Last time I checked, the 4th Amendment was about "due process" and "but upon probable cause". Everyone seems to forget about the "Probable Cause" line.

Probable cause is an under-appreciated term. Every American should know what it means. You'll see actors in movies and TV say to other actors posing as police that they can't enter their home without a warrant and that's not true.

Police can enter your home without a warrant, all they need is probable cause.

What is probable cause? Probable cause is when a police officer is 51% sure that a crime is occurring. So if police are 51% sure a crime is occurring in your home, they can enter, and you can't stop them and anything illegal they see in line of sight can be used to prosecute you.

Police can only go to the place where they think the crime is occurring, so if they have cause to think someone is doing something illegal on the first floor of your house, they can't climb the stairs to the second floor to find illegal drugs in your bedroom closet. Probable cause doesn't give police leeway to search your entire house just because they saw someone smoke pot through the kitchen window.

Having said that, when I say police can only go to the 1st floor, that really only means that they'll have a lot of trouble convincing prosecutors and judges that anything they found on the second floor will be admissible, they can physically go up to your second floor and you should not stop them.

What police will do is try to use line of sight to find anchors to get deeper into a house. So if they barge in because a suspect ran into the living room, they'll try to find other things that will give them 51% probable cause to move further through the house.

tl;dr: Probably never try to physically or even verbally stop police from searching your house, car and person and property. They don't need a warrant, they just need to think something is up. The movies and TV are not reality.

Source: Some administration of justice classes in school, experience with police.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#20
post #9

Earlier quoted context omitted.

> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. > More and more network adapters seem to have DMA access to your computer. With an I…

Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if har…

>The unfortunate conclusion is that in the future, someone like Snowden might immediately be caught.

I think that is too naive. Snowden types don't assume they won't be caught, they probably assume that it is only a matter of time until they are caught, and play the cards they have in such a way that you make it really hard to send your garden variety cia/dia/spec ops/defense contractors out on a pick up operation not only only from a feasibility standpoint, but from a geopolitical stand point (e.g. What will Beijing's/Moscow's/D.C.'s response be if we run such an operation in their front yard? What precedents might we be setting?).

Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems which might very well be other nation states (or appearing to originate from such).

Post reply on HN