The FBI Has a Trojan To Watch You
G_of_the_J writes "A man who had cut 18 cables affecting Verizon and Comcast was blackmailing them. He had demanded bank accounts be set up and information be provided on web sites that he specified. Although he used anonymous access to get to the web sites, the FBI had planted a trojan which was downloaded to his computer. The trojan then sent his IP address and other information to the FBI."
Crap. Too bad that website was the top rank on a google search for comcast verizon cut cable blackmail.
I suppose posting anonymously won't help now.
http://en.wikipedia.org/wiki/Computer_and_Internet_Protocol_Address_Verifier
... if he was stupid enough to visit the "private" website they created for him with such a lax security setup that his computer willingly installed the FBI's trojan.
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
There is one important aspect missing from the summary. The FBI got a warrant first. It's not an extension of illegal wiretapping.
He can spoof ips yet he can't install software to detect unwanted outbound traffic?
Idiot.
I don't know... Seems to me like another reason not to cut 18 cables and not know how to hide your identity.
About the party responsible for infiltrating government and military computers.
In case you've been living in Richard B. Cheney's spider-hole, this F.B.I. system is called Ghostnet.
Yours Seditiously,
Kilgore Trout
... reason to not use Microsoft products.
What makes you think they don't have a variant for Linux? User stupidity (i.e: bad/no security) isn't unique to Windows. Off the top of my head, if they are relying on the web as an infection vector combined with user stupidity, why not write it into a Firefox extension?
Yeah, it wouldn't get your typical /. geek, but most criminals aren't known for their foresight or intelligence. "Oh, the private website with the bank account information needs me to install this software! Ok, what could possibly go wrong?"
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
"This website requires additional ActiveX components to be installed."
Hmm...
*click*
...
Oops.
I am the lawn!
First read Slashdot and understand all the technical details needed to hide your identity. Then go ahead cut the cable and demand ransom.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
If this guy had had half a brain, he would have wiped the computer's hard drive clean by overwriting it with zeroes, and then done everything by using a Linux distribution on a bootable CD that could run entirely in RAM. Instead, he ran Windows and got nailed by a Trojan. Somewhere in the afterlife, J. Edgar Hoover is laughing his panty-clad ass off.
I write sci-fi for metalheads
Always use noscript when doing nefarious shit....
TFA says the FBI had a warrant. When that is the case, I *want* them to be able to own a suspect's machine.
[Sir Garlon] is the marvellest knight that is now living, for he destroyeth many good knights, for he goeth invisible.
Dude was a bad guy. FBI's job is to catch bad guys. FBI uses technology to catch bad guy. I'm not feeling the outrage here...
In a related story, local law enforcement shot a criminal who tried to hold up a 7-11 when he resisted arrest and brandished a knife. Reports say police used their "gun" technology to do this.
Point being, we know the FBI has the tech to do this stuff. It's only really a rights issue when they use it against non-criminals, or suspected criminals.
So we can assume that the right to keep and bear arms can include the use of trojans for personal reasons. Perhaps the Fed would like to tax and license the use of trojans. Only after an approved trojan safety course has been passed, of course. Other permits would be required to use a trojan outside of ones home and some public venues could ban the use of trojans in their facilities.
Requiring a permit to use trojans outside of the home wouldn't seem consistent with the Democrats position on sex education ;)
I want peace on earth and goodwill toward man.
We are the United States Government! We don't do that sort of thing.
What incredible insight.
Greta: He knocked over another ATM. This time at knife point. He needs your legal advice.
Fletcher: [picking up phone and shouting] Stop breaking the law, asshole!
Whale
If you get a call from someone who refuses to identify themselves asking you if you'd be willing to edit a couple hidden configuration files and restart your system, then you have the Linux version.
Bear arms are fine if the bear in question is still attached to them, and in a fit state to fight and clued in enough to the cause to fight FOR you. If not, then the right to bear arms is pointless, you may as well have the right to shit on the moon.
Something is seriously wrong when you have to explicitly state, "The FBI did not commit any crimes in this story." When I read the summary, I felt that the warrant was implied, but with everything that has happened, I also feel that you are completely justified to think that that info was missing.
Someone once said "I never meta dupe I didn't like."
That someone was not me.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
I think it's an interesting story, but sure ... if a warrant was obtained first, the FBI actually did this the RIGHT way, and that makes me happy.
That's how law enforcement is supposed to work. Sometimes it seems like we completely forget that, these days, with all the stories of "the law" just doing whatever they please, secretly.
Actually, the FBI can't tell the difference between a criminal and a suspected criminal. In the U.S., it takes a jury (or a guilty plea) to do that.
I think your point though is that it's not a violation of someone's rights if the FBI has reasonable evidence *before* they install the Trojan, and it appears they did in this case (because they had a warrant).
[Sir Garlon] is the marvellest knight that is now living, for he destroyeth many good knights, for he goeth invisible.
Nice ideas. Here is all I had: Demand that the info be in ASCII text, and download it with wget.
"What makes you think they don't have a variant for Linux? User stupidity (i.e: bad/no security) isn't unique to Windows."
This is an excellent statement. Stupidity knows no bounds. Its also dangerous to assume that the FBI doesn't know what it is doing. When I worked in law enforcement, the FBI computer crimes agents I knew were well versed in operating systems other than Windows. The two I worked with most often had a solid knowledge of Linux and Cisco IOS.
Or am i just a European speaking to an American ; ).
No, just an asshole acting smugly superior.
That's MY IP address too! Is the FBI hacking my computer as well?
Remember kids, only criminals use proxies. And only criminals use "an alternate operating system, with a black screen and white characters".
I want to delete my account but Slashdot doesn't allow it.
Don't you watch the movies? They would've backtraced his IP address through their firewall with a Visual Basic program within seconds. You need to bounce around the world through at LEAST 15 anonymizing proxies for that to work and give you a minute or two of time to taunt them before you disconnect at the last minute just as the blue blipping blob on their VB.Net trace program is about to pinpoint your location in North America as the program starts zooming in on your location with Google Maps.
Click! All they know is you're in the northeast, but you told them that already right before you disconnected when you said you were calling them from a payphone across the street. When they rush out of their building all they find is an empty payphone with an acoustic coupler attached to the handset and interfaced to some kind of prepaid cell phone. You put down your binoculars that you've been using to watch the situation from the 5th floor of your hotel down the street and press a button on your computer which detonates the C4 conveniently hidden behind the payphone. Did they really think a silly god damn Windows spyware program was going to take you down so easily?
They could do it without a trojan, if they had the right signing key. I forget which worm it was, but a few years back there was a major vulnerability that Microsoft patched, which triggered the automatic reboot. The issue was the patch went ahead and updated the machine even if you had the system set to "download, but notify" rather than automagically patch. Similar deal here where an update did something it should not have.
Were I the FBI, I'd make Microsoft 'digitally sign' such a beasty, and then send it via an unannounced update.
Always helps to have stupid criminals, however.
+++ UGUCAUCGUAUUUCU
Yeah, it's sad that law enforcement actually doing their job the RIGHT way is news.
Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
here are some facts...
1 - criminals are typically dumb as hell.
2 - smart criminals are still dumb.
3 - it is incredibly RARE to have a very smart criminal, when you find one and they do a lot of criminal acts and get away with it, they get cocky and then become a dumb criminal. Example? Kevin Mitnick. he got cocky, then did some really REALLY dumb things to get caught.
Real professional computer criminals DO exist. and you will never hear about them because they dont get caught. Computer Crime forensics pros are not as good as they all want you to think they are, they may be WIZZES at computers but they are not Wizzes at encryption, obfuscation and stenography, let alone secret squirrel stuff. It is really easy for a 13 year old punk to get and use the same technology that the biggest nations are using for their spies. If a kid is talented enough and has enough self control he can easily elude the entire FBI and NSA together online. it's not technically or technologically hard, it's simply being able to NEVER EVER get sloppy. because the second you get sloppy, you're nailed. The longer you go the harder it is not to get sloppy or accidentally give them a pattern. to the FBI, it's a matter of time... you will screw up, they will get you.
Do not look at laser with remaining good eye.
Is it just me, or does it seem rather contrived that the FBI would (successfully) use a trojan to catch a criminal who is at least someone technically proficient ? Presumably the con would be surfing through a proxy at the very least, and is probably not the kind of user who runs unsolicited downloads from public web sites.
Call me crazy, but I'd say this smells like a piece of theatre. Now I'm not saying the FBI hired the con, but sometimes I wonder... In an increasingly complex tech world, maybe they feel the need to put on a show, to make people believe the FBI still has things under control.
-Billco, Fnarg.com
> Reason for requested leave: Starting an evil empire
Trust me, it's not as great as it sounds. The overhead is a lot more than you expect. Everyone figures they'll just steal a couple nuclear warheads and they're in business, but they never think about the essentials. Do you know how much toilet paper your evil lair will go through in a week? Even though you have the contribution jar next to the coffee maker, no one ever pitches in unless you happen to be standing there. With the downturn in the economy, you don't have the same staffing issues as you normally do, but finding decent henchmen is always a chore. The ones you do find are all, "We want dental!", "We need flex time!", "Respect me as an equal!", and "Oh God, no, save me, IT BURNS!!!" I mean, come on, what am I your mommy?
You go through all that, then in the middle of one of your best speeches, some moron running around in a tuxedo blows it all up with a can of hairspray and a laser beam built into a wristwatch.
Seriously.
Well, there are ways to be about 99.99% anonymous on the internet. One way is to set up a nym account, that bounces through serveral remailers like Mixmaster...and basically have the final hop on those to be one of the anon groups on USENET. That way, they don't know who it is reading one of thousands of pgp encrypted emails out there.
However, when it comes time for the internet to intersect 'meatspace', like when you want to get money. Well, now that part is gonna be a little tougher to do...much easier to track the money.
Light travels faster than sound. This is why some people appear bright until you hear them speak.........