The Secret History of the FBI's Classified Spyware
An anonymous reader writes "A sophisticated FBI-produced spyware program has played a crucial behind-the-scenes role in federal investigations into extortion plots, terrorist threats and hacker attacks in cases stretching back at least seven years, according to newly declassified documents obtained by Wired.com. The so-called 'computer and internet protocol address verifier,' or CIPAV, is delivered through links to websites controlled by the FBI, and it silently reports back to a government server in Virginia. Among other cases, the FBI used it to track a Swedish hacker responsible for cracking thousands of computers at national labs and NASA's JPL in 2005."
How is this not breaking the law?
Breaking the law to enforce the law.. way to piss on justice.
How we know is more important than what we know.
Second Post!!!
When I saw this article i was like wtf no posts ?
argh well, then i refreshed and there was one post, and now by the time i write this there will probably be another post
I wonder if they have a Linux version?
My ism, it's full of beliefs.
"After sending the information to the FBI, the CIPAV settles into a silent "pen register" mode, in which it lurks on the target computer and monitors its internet use, logging the IP address of every server to which the machine connects. "
Let's hope the RIAA doesn't get it's hands on this.
This explains a few things!
The Apple tax! The guberment just doesn't want us to use anything but insecure Windows systems.
Suspicious use of Linux (and friends): They can't p0wn every linux or bsd variation, so they are automatically wary.
The NSA They didn't get in on the NSA's backdoor in Windows NT, and they're still pissed.
Never ask for directions from a two-headed tourist! -Big Bird
Does it work with browsers that are too dumb to run scripts or active content?
Does it work with browsers that have scripting and active content disabled?
What useful information does it provide if someone is using a proxy-router-boot-cd environment, besides other web sites visited during that session and perhaps traceroute-type information?
What useful information does it provide if someone is using a boot-cd environment behind a router that connects to the proxy? Traceroute-type information won't be helpful there.
Using dumb/old browsers, disabling active content, using proxy boot cds, and using boot cds behind routers are all things an unsophisticated user can do using turnkey solutions. The only skill required is "download and install software" for the first two, "download and burn a CD image and boot with it" for the third, assuming of course your computer BIOS boots to CD by default as most do. For the 4th, add the step of "go buy a computer and have them install a second network card, and download and burn 2 CDs, one for each computer." Not hard. I don't know if there is a turnkey set of CDs for #4 out yet but I wouldn't be surprised if there is. If there is not today, there may be one tomorrow.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
having read the story and seeing that one target hit the site 29 times without it dropping its payload due to a 'compatibility issue'.
Here in France, we're close to having to install a spyware on our computer NOT to go in jail and pay a huge amount of money after 3 unproven accusations.
But as you read down, some interesting details. :) ???
"The software's primary utility appears to be in tracking down suspects that use proxy servers or anonymizing websites to cover their tracks."
The feds note your interests as you type, not your proxy for the day 1/2 around the world.
What was once a hardware logger install is now your clicking on a link.
"alarmed when the hacker he was chasing didn't get infected with the spyware after visiting the CIPAV-loaded website."
Seems like someone was using a Mac or Linux/other OS?
What do people think? A deep dark federal/MS approved/AV hidden effort?
Or in house/turned/tame spyware author ?
Would Tripwire save you
The MAC address part reminds me of hints about the anti p2p software called "Operation Fairplay"
http://news.cnet.com/8301-10784_3-9920665-7.html
Domestic spying is now "Benign Information Gathering"
CIPAV, is delivered through links to websites controlled by the FBI, and it silently reports back to a government server in Virginia.
But if it works based on clicking links that presumably take you to the installer, how on earth can you guarantee that your target is going to click on it at all? You'd either have to direct it specifically to the Mark, and hope that he responds, or you'd have to put it someplace so completely mainstream that hundreds of other people click on... oh, shit. I think I'm having an OS reinstall party this weekend.
Support the EFF and Creative Commons. The war is coming, and they're supporting you...
As previously stated, it's not really different from bugging the home or car of a suspected Mafia boss/drug dealer/etc... As long as it's backed up by a court order, of course. It obviously interferes with the right for privacy, but that's why there are mechanisms which should take into account all factors before allowing such interference (i.e. courts and judges). If the system is malfunctioning, it should be fixed - but this doesn't mean that it isn't right. BTW, this CIPAV isn't really news - it's wikipedia page is 2 years old...
...carrots.
My guess is that the "system incompatibility" was Linux and/or Firefox.
I'm surprised no one has mentioned Inslaw or PROMIS.
Predecessors to this FBI spyware.
http://en.wikipedia.org/wiki/INSLAW
Actually if you aren't an idiot about it and have proper security settings/practice this thing would never have gotten installed in the first place......
The right term is "if you aren't ignorant or stupid", not "if you aren't an idiot."
The vast majority of computer users haven't been told or refuse to believe that their OS and web browser are not only insecure, but in practical terms, inherently insecure. Ignorance can be cured.
Maybe, after enough people know someone who has been ripped off by bank or other fraud or had porn dropped on their PC, people will start demanding and using hardened web browsers.
Unfortunately, I have little doubt the US-based commercial web-browser and security-software vendor(s) have or will leave a "back door" for the feds.
I wonder how many Americans have been snooped on by totalitarian governments using similar tools? You'll know you've been targeted if, the next time you are on vacation in such a country, you don't come back.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Are these documents available?
Tried to search but no luck.
It seems strange that no one has managed to catch this in the wild yet, if it has been in use for that long. Would indicate they are using it in a fairly limited scope (perhaps), if for no other reason to keep from defeating their own tool.
Living in Chile
And a Mac version too.
The really interesting question is, are there OpenBSD versions?
Best Slashdot Co
The Constitution is QUITE clear that a search of private property requires a warrant.
From the fine article, emphasis added by me: "But the documents released Thursday under the Freedom of Information Act show the FBI has quietly obtained court authorization to deploy the CIPAV in a wide variety of cases, ranging from major hacker investigations, to someone posing as an FBI agent online."
And from further down in the article: "The FBI obtained a warrant to use the CIPAV on February 10, 2005, and was apparently successful."
The so-called 'computer and internet protocol address verifier,' or CIPAV AKA Bonzi Buddy, is delivered through links to websites controlled by the FBI, and it silently reports back to a government server in Virginia
Or at least doing the more discreet browsing from a VM.
I will not be pushed, filed, stamped, indexed, briefed, debriefed or numbered. My life is my own.
If CIPAV has been so widely deployed, one might wonder if it has not been released to black hats already and analysed to death...
"Breaking the law to enforce the law.. way to piss on justice." - by WCMI92 (592436) on Friday April 17, @08:25AM (#27610127) Homepage
I think the episode of STAR TREK (original series) called "The Savage Curtain" sums it up well, when a race of silicon beings who have NO CONCEPT of "good" or "evil" trap the Starship Enterprise & crew, & put them into a battle vs. the MOST notorious villains in the history of the human race:
----
YARNEK (the silicon being):"Our world is called 'EXCALBIA'... countless who live on that planet, are watching... before this drama unfolds, we give welcome - to the ones called 'KIRK', & 'SPOCK'..."
Capt. Kirk:"We know nothing, of your world... your customs. What do you mean, 'The drama about to 'unfold'...?'"
YARNEK (the silicon being):"You're an intelligent lifeform - I am SURPRISED you do not perceive the honor we do you - have we not created on this planet a stage IDENTICAL to your own world?
Capt. Kirk:"We perceive that we were invited to come down here, and we came in friendship... and you have deprived us of our instruments to examine your world, to defend ourselves, to communicate w/ our vessel..."
YARNEK (the silicon being):"Your objection is WELL taken: We shall communicate with your vessel, so that your fellow beings can enjoy, and profit... from the play... behold!"
(click, click)
The statement was explicit:
YARNEK (the silicon being):"Capt., Mr. Spock - some of these you MAY know thru history - Genghis Khan, for one, & Colonel Green (who led a genocidal war early in the 21st century on your earth). Zora - who experimented with the body chemistry of subject tribes, on Tiburon. Kalas, the 'unforgettable' (The Klingon, who set the pattern for his planet's tyrannies)... We welcome the vessel, ENTERPRISE, to our solar system (and, to our spectacle): We ask you to observe with us, the confrontation of the 2 opposing philosophies, GOOD, & EVIL - since this is our 1st experiment w/ earthlings, our theme is simple - survival, life & death. YOUR philosophies are ALIEN to us, & we wish to understand them, AND DISCOVER which is the stronger (we learn by watching such spectacles)..."
Capt. Kirk:"What do you mean... survival?"
YARNEK (the silicon being):"The word is explicit - If you & Spock survive? You return to your vessel... if not? YOUR EXISTENCE IS ENDED!
YARNEK (the silicon being):"It seems that evil retreats, when forcibly confronted: However, YOU have failed to demonstrate the difference between your 2 philosophies (good & evil) - Your 'good' and your 'evil' use the SAME methods, & achieve the same results... Do you have an explanation?"
Capt. Kirk:"YOU established the methods, & the goals..."
YARNEK (the silicon being):"For YOU to use, as you chose..."
Capt. Kirk:"What did you offer the others, if they won?"
YARNEK (the silicon being):"What they wanted MOST: Power..."
Capt. Kirk:"You offered me the lives of my crew!"
YARNEK (the silicon being):"I perceive... you have won their lives!"
Capt. Kirk:"HOW MANY OTHERS HAVE YOU DONE THIS TO? WHAT GIVES YOU THE RIGHT TO HAND OUT LIFE... & DEATH?"
YARNEK (the silicon being):"The same right that brought YOU, here - THE NEED TO KNOW, NEW THINGS..."
Capt. Kirk:"We came in pease..."
YARNEK (the silicon being):"And, you may go in peace..."
APK
P.S.=> I'd say the BOLDED portions of the dialog above, especially from "YARNEK", about sums it all up... &, especially THIS line from it:
Your 'good' and your 'evil' use the SAME methods, & achieve the same results..
(I.E.-> There's almost NO WAY to 'play the nice guy' & win - nice guys DO finish last, because THEY OBEY RULES... whereas 'bad guys/scumbags', often don't. So, t
How would the FBI get the spyware loaded on major sites? Well, here's a likely sceanrio. Say you're the head of a major US bank. The FBI approaches you and says they'll load this tiny app on your site.... all in the name of security. Some might just go for it.
Electronic rebellion is a bad thing when the other guy does it.
But in all seriousness the ability of any government to fight electronic crime and rebellion sound fine at first but think about it. Perhaps there will come a day when our government is not in control of the situation. Other powers may infiltrate and seize control. This happens frequently all over the world. At that time the very same tools that aid us in catching thieves online or other negative personalities such as terrorists can be used to track down loyal Americans who are doing nothing more than trying to maintain liberty and our form of government. We need to have a really hard think about allowing governments to possess such spying tools.
I also wonder if the browser creators are in on creating the vulnerabilities that the FBI uses for their exploits.
Anyone that clicks the article link automatically gets the spyware installed.
FBI Spyware ? I thought that was Windows XP ?
An FBI agent became alarmed when the hacker he was chasing didn't get infected with the spyware after visiting the CIPAV-loaded website. Instead, the hacker "proceeded to visit the site 29 more times," according to a summary of the incident. "In these instances, the CIPAV did not deliver its payload because of system incompatibility."
Is that FBI-speak for antivirus? Or for Linux?
"The Secret History of the FBI's Classified Spyware" This reinforces the meaning behind.. All Your Base Are Belong To Us bitches. Apparently, welcome to NWO. http://www.youtube.com/watch?v=qItugh-fFgg
Couldn't this be easily circumvented by using a decent open source firewall that blocks outgoing connections?
It's time to use Lynx for all nefarious web browsing. On another note, it would be interesting to see some packet captures of CIPAV installing itself. I wonder if you could develop signatures for Snort or other IDS/IPS systems to recognize CIVAP installs.
Several problems with CIPAV that are not well known. 1.) is that some spyware dectors can detect and remove CIPAV immediately upon detecting. 2.) CIPAV doesn't work well with pooled or shared IP addresses, 3.) CIPAV doesn't works at all with IPv6, IPv8, or the Chinese IPv9, and 4.) Any evidance CIPAV collects does not assume that the IP it is tracking could have been hijacked to begin with and inserting web page addresses, MAC addresses, ect., ect. But of course the FBI will never tell anyone this nor will they easily admit same if challanged. Regards, Spokesman for INEGroup LLA. - (Over 284k members/stakeholders strong!) "Obedience of the law is the greatest freedom" - Abraham Lincoln "YES WE CAN!" Barack ( Berry ) Obama "Credit should go with the performance of duty and not with what is very often the accident of glory" - Theodore Roosevelt "If the probability be called P; the injury, L; and the burden, B; liability depends upon whether B is less than L multiplied by P: i.e., whether B is less than PL." United States v. Carroll Towing (159 F.2d 169 [2d Cir. 1947] Updated 1/26/04 CSO/DIR. Internet Network Eng. SR. Eng. Network data security IDNS. div. of Information Network Eng. INEG. INC. ABA member in good standing member ID 01257402 E-Mail jwkckid1@ix.netcom.com My Phone: 214-244-4827
Spokesman for INEGroup LLA. - (Over 284k members/stakeholders strong!) "Obedience of the law is the greatest freedom" -