Live data from Hacker News

Federal agents seek to loosen rules on hacking computers during investigations

bloomberg.com

31–40 of 53 posts

Re: Federal agents seek to loosen rules on hacking computers during investigations

#31
post #28

Earlier quoted context omitted.

Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if har…

> Once hardware begins to turn against you, there seems to be nothing anyone can do to protect themselves. Encryption doesn't work against an adversary that has access to your computer's memory. In the future (or today, depending on your setup), IOMMU. In the present, there is no evidence that baseband backdoors of this type actually exist (as opposed to hacks). When the adversary adds backdoors deeper in the hardwar…

The reason it's good to proactively think of future threats is because so many past concerns have proven to be true. Several months ago, no one on Hacker News really believed that BIOS backdoors were much of a threat. But today it's a well-established fact, for example.

The tools of law enforcement probably aren't going to be revealed, and they're hard to discover. Nobody knew about the zero-day exploit employed against Tor browser, for example, and there are almost certainly many more tricks like that up their sleeve. They already take steps to conceal them; parallel construction is an unfortunate reality. And since there's not much justification for a whistleblower to reveal the techniques, it's unlikely someone will come out and talk about them. We'll probably need to think along the lines of "What's technologically possible, and how is it useful to law enforcement?" It's not a good idea to wait until a weapon is used before thinking about how to react to it.

The history of communications technology and how governments have reacted to the technology is actually quite fascinating. Wiretaps used to be extremely commonplace, and since there's not too much legal protection from the government rifling through your digital life at will (at least compared to getting permission for wiretapping your phone), it seems like it's better to err on the side of caution.

It's also important to realize that even though some governments follow due process, several powerful ones don't. Also, there are other global other considerations. The US has made it pretty clear that their legal restrictions are designed to apply to US citizens, not any foreign person. You may be forced into a situation of choosing which governments you'll trust, especially when cross-nation collaboration becomes even more pervasive. Assuming that other countries adopt a similar attitude of "Our citizens are protected; other citizens are examined," then the US may simply outsource their databases of information to be examined by some other government, like any other member of the Five Eyes.

I understand your concern and skepticism though. It was a question I've often wrestled with myself.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#34

Earlier quoted context omitted.

Also to note that offensive/defensive technical capabilities aren't as asymmetric as they appear for all possible targets of nation states, some yes, but probably not as much to those with the technical knowledge who can create/use such and derivative systems. If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for…

> If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance. Whats DMA access? Direct Memory Access access? That aside, I'm not willing to concede that across every computer than has been/can be built and be exploited by a government out of the box remotely [because dragnet]…

Whats DMA access? Direct Memory Access access?

This is what happens today. Not in some far off distant distopioan future meant to invoke fear in the ignorant/lazy.

Why not talk with me without the snark? This topic seems like it interests you a lot, so it seems like we have some shared ground.

one can clone the sc[1] and go through the source code for what could possibly define one as a Tails user, replace that with something else, build their own image and voila, you just avoided being in the dragnet.

This won't work because it's extremely difficult to analyze your network card and discover its behavior, and without this knowledge you'd be changing things blindly. There are far too many ways to detect an OS to change them all. Tweak-and-recompile would work if they use a naive and brittle heuristic like "look for the first 64 bytes of whatever is loaded into memory when Tails is booting up," but they wouldn't employ such a brittle heuristic in the first place because every time a new version of Tails is released, they'd need to update their entire infrastructure to look for a new pattern. Something like monitoring the network traffic for a unique "Tails signature" is more likely in this scenario; for example, how many computers start Tor immediately after a network card is connected? Detecting that condition would be a decent starting point for detecting Tails, and they'd want to combine it with some other hard-to-evade condition to cut down on false positives without introducing false negatives.

One interesting way to detect that someone is using Tails would be to notice that their system clock is set to UTC time. Most of the computers connected to the internet aren't using UTC, so UTC time plus Tor usage on startup is pretty commonly associated with anonymity OS's. That said, it seems like it might be difficult for the network card to detect whether the system clock is UTC time, but it's just an example of how difficult it is to fully conceal your usage of an anonymity tool. It's not just a matter of tweaking the source code.

This seems to prove the seriousness of this threat, though. Once you agree that it might be possible for your network card to be your adversary, there are endless ways that it can be used to defeat you. Hardware manufacturers have evidently been thinking along these lines, so why shouldn't we try to think of ways to prevent this from happening? As the BIOS exploits have shown, that dystopianic future may be closer than anyone's comfortable admitting.

EDIT: Someone went through and downvote bombed our whole converastion on both sides... I tried to correct it, but it looks like upvotes from Tor users under a certain karma threshold aren't registering, so I wasn't able to help fix it.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#35

Earlier quoted context omitted.

The notion that the government ought to not be allowed into your computer, ever, doesn't seem grounded in either reality or historical precedent. I didn't intend to argue that. I'm saying that strong anonymity OS's like Tails will force governments to do dragnet surveillance using compromised hardware in order to track suspects down. There is no way to tailor surveillance to an individual using Tails, because it's se…

Yeah, it is a damn tough question. Criminals have more tools than ever for operating under the radar, so restricting agents to traditional rules for investigation & surveillance seems like a mistake. But on the other hand, how do you grant increased surveillance capabilities to counter increased covert capabilities, without ruining privacy? Basically, it's like privacy is caught in the crossfire.

Criminals have always had lots of tools available to them; by definition, they aren't restricted by law, which opens up many possibilities not available to the rest of society. Nobody ever said police work is (or should be) easy.

Despite that, the answer to how you grant increased surveillance capabilities is easy: you get a warrant.

It isn't a terribly difficult bar to reach - judges will hand out warrants quite easily. We - the citizens - just ask that those asking for such capabilities ask for them (each time...), and at least show they have some minimal sort of reason to want such easily-abused capabilities.

Requiring the warrant therefor shouldn't slow down legitimate investigations more than a trivial amount. If enforced, on the other hand, it does act as a "limiter" to sweeping abuses.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#36
post #4

“The proposed amendment would enable investigators to conduct a search and seize electronically stored information by remotely installing software on a large number of affected victim computers pursuant to one warrant issued by a single judge” I wonder if we'll start to see researchers/people come across more of things like this in the wild? Which makes me wonder if federal agents are going to be enlarging the attack…

I believe there have already been at least 2 cases of the FBI using the very mass exploitation technique discussed in the article. The 2012 investigation dubbed "Operation Torpedo"[0] and the Freedom Hosting exploit in 2013 dubbed "Torsploit"[1].

There were 25 arrests in the first operation and those suspects are currently fighting the search warrant because the FBI failed to give notice to the those who had the virtual search warrant executed on them within the required 30 days.

Nothing has really come of the second operation (after over 10 months now) except for an arrest of someone the FBI was able to identify without the help of their exploit (they used the same user name on Tor as they did on the clearnet).

[0]: http://www.wowt.com/news/headlines/Fed-Tactics-on-Trial-in-P...

[1]: http://www.propublica.org/nerds/item/is-the-u.s.-government-...

Re: Federal agents seek to loosen rules on hacking computers during investigations

#37
post #9

Earlier quoted context omitted.

> The takeaway is that your children may grow up in a world where it's impossible to guarantee the government can't get into your computer if it really wanted to. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. > More and more network adapters seem to have DMA access to your computer. With an I…

Unfortunately, projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted. This is impossible to guarantee today. Certainly if you run the zero-day magnets known as browsers, and even if not, there is always some possibility of physical intrusion. Today you can use OS's such as Tails to prevent most exploits from embedding themselves into your computer. This is what Snowden used, for example. But if har…

> projects such as DROPOUTJEEP confirm that the iPhone isn't to be trusted

That iPhones used to completely trust physically connected devices without any verification was obvious to anyone paying attention even before it was verified at Black Hat USA 2013 [1]. This was fixed in iOS 7. The evidence we have of DROPOUTJEEP says it is installed via "close access methods" [2]. I wouldn't be surprised if remote vulnerabilities exist that could be used to install it remotely, but I am aware of no public evidence that they are being exploited now.

1. http://www.zdnet.com/researchers-reveal-how-to-hack-an-iphon...

2. http://www.zerohedge.com/news/2013-12-30/how-nsa-hacks-your-...

Re: Federal agents seek to loosen rules on hacking computers during investigations

#38

Earlier quoted context omitted.

> If you concede that your computer has a chip with DMA access which can be used by the government, then you must concede that the same chip can monitor you for activity that triggers active surveillance. Whats DMA access? Direct Memory Access access? That aside, I'm not willing to concede that across every computer than has been/can be built and be exploited by a government out of the box remotely [because dragnet]…

Whats DMA access? Direct Memory Access access? This is what happens today. Not in some far off distant distopioan future meant to invoke fear in the ignorant/lazy. Why not talk with me without the snark? This topic seems like it interests you a lot, so it seems like we have some shared ground. one can clone the sc[1] and go through the source code for what could possibly define one as a Tails user, replace that with…

>Why not talk with me without the snark? This topic seems like it interests you a lot, so it seems like we have some shared ground.

>One interesting way to detect that someone is using Tails would be to notice that their system clock is set to UTC time. Most of the computers connected to the internet aren't using UTC, so something like that is pretty commonly associated with Tails. That said, it seems like it might be difficult for the network card to detect whether the system clock is UTC time, but it's just an example of how difficult it is to fully conceal your usage of an anonymity tool. It's not just a matter of tweaking the source code.

It's not out of snark (I apologize for if it sounds like it, not intentionally seeking to offend anyone), but mainly out frustration about the conversation on how everything seems to be so difficult. Difficulty to whom? Someone who cannot modify sc to a significant extent? Someone who just downloads the program and expects it to just work? Not just some random tweak, I mean going through looking at what the functions actually do, which remote connections do they rely on to connect to at various stages, how data is generated and allocated in memory, what system calls are made, etc and change it according to ones threat model so that the program one complies has the same functionality but is not recognized as the same program. Maybe that involves changing the the system time. Again, trying to target someone doing such is trying to target someone actively adapting, probably faster than it takes for the dragnet to adapt since like I said, dragnets mainly hinge on effectively going after the common denominator that of which is usually of the mind set of someone who downloads/uses a program system and expects it to just work and address all of their concerns without doing anything themselves. In the end, anyone can try all they want to cut down on the false negatives and positives, but they will still exist and that's where the "real" danger comes from for groups/orgs/gov's that go to such extents.

>Once you agree that it might be possible for your network card to be your adversary, there are endless ways that it can be used to defeat you.

If this is really in one's threat model, one is probably throwing away or using shared computers before this point… maybe from within a virtual machine on a large banks network from an exploit one used (remote, or local).

>so why shouldn't we try to think of ways to prevent this from happening?

Few people do this today for themselves, most others do not. People today seem to have come to expect that someone else needs to protect them which must have fmr cyhperpuks laughing. As far as I'm concerned, we are already living in the dystopian future, and the few who take the steps to mitigate based on their threat model do. These issues have been around for a while, and those who cared all along took steps they felt were necessary to protect themselves and still do. Maybe that involves not taking advantage of the latest skinner box of the day, again tradeoffs and threat models to consider. And those now made aware have to learn a lot to put themselves in the same shoes, if they even care enough to learn what they need to start protecting themselves and to continue to adapt to do so. Again, its not like BIOS exploits suddenly became possible because snowden profiteers told us and because all of this I don't think it really is a serious threat (any more than it already was) because your adversaries are opening themselves up at the same time. This has always been an evolving landscape. Such is the world we live in and have always had.

Edit: No worries, as I've learned over time, down-voting isn't really effective for silencing ideas/discussion since it just attracts more interest to those who want to seek such information.

Re: Federal agents seek to loosen rules on hacking computers during investigations

#39

Earlier quoted context omitted.

Last time I checked, the 4th Amendment was about "due process" and "but upon probable cause". Everyone seems to forget about the "Probable Cause" line.

Probable cause is an under-appreciated term. Every American should know what it means. You'll see actors in movies and TV say to other actors posing as police that they can't enter their home without a warrant and that's not true. Police can enter your home without a warrant, all they need is probable cause. What is probable cause? Probable cause is when a police officer is 51% sure that a crime is occurring. So if p…

Conversely, you do not need to give permission to police just because they ask. Even at police checkpoints, they do not have the right, without probable cause or your permission, to search your vehicle. If we don't stand up for our rights, we will lose them.

(Now, realistically, if you say "no", they will bring a dog over that they've trained to signal, thereby giving them "probable cause".)

Re: Federal agents seek to loosen rules on hacking computers during investigations

#40

Earlier quoted context omitted.

Probable cause is an under-appreciated term. Every American should know what it means. You'll see actors in movies and TV say to other actors posing as police that they can't enter their home without a warrant and that's not true. Police can enter your home without a warrant, all they need is probable cause. What is probable cause? Probable cause is when a police officer is 51% sure that a crime is occurring. So if p…

Conversely, you do not need to give permission to police just because they ask. Even at police checkpoints, they do not have the right, without probable cause or your permission, to search your vehicle. If we don't stand up for our rights, we will lose them. (Now, realistically, if you say "no", they will bring a dog over that they've trained to signal, thereby giving them "probable cause".)

If you say no and they say 'get out of the way', you better get out of the way though, you can't physically prevent the police from searching your car if they decided to do it anyway. All you can do is hope your lawyer fights any evidence they get that way.
Post reply on HN