Slashdot Mirror


FBI Dismisses Child Porn Case Rather Than Reveal Their Tor Browser Exploit (arstechnica.com)

An anonymous reader writes: Federal prosecutors just dropped charges against a child pornography suspect rather than reveal the source code for their Tor exploit. Of the 200 cases they're prosecuting nationwide, this is only the second one where the FBI has asked that the case be dismissed. "Disclosure is not currently an option," federal prosecutors wrote in a court ruling Friday. The Department of Justice is still prosecuting 135 different people believed to have accessed an illegal child pornography web site. Before shutting it down, the FBI seized the site and operated it themselves for 13 more days, which allowed them to deploy malware to expose the users' real IP addresses.

244 comments

  1. Which is more important? by Anonymous Coward · · Score: 5, Funny

    Secrecy or Child Pornography...

    We report, you decide.

    1. Re: Which is more important? by PoopJuggler · · Score: 4, Insightful

      I posit that it's unethical and treasonous to not disclose the vulnerabilities because those exact same vulnerabilities can be used against our own citizens and government agencies by foreign agents. Imagine if foreign hackers brought down the banking industry causing massive economic devastation using an exploit that the FBI knew about but didn't tell the banks?

    2. Re: Which is more important? by ShanghaiBill · · Score: 4, Insightful

      using an exploit that the FBI knew about but didn't tell the banks?

      How many banks rely on Tor?

    3. Re: Which is more important? by HornWumpus · · Score: 1

      Be fair, there aren't going to be more than a few banks operating on Tor. They will likely be operating bitCoin to real cash services, be somewhat less law abiding than average and charge exorbitant fees.

      At least a decent sized minority part of government would actually be for taking those banks down, with exceptions of course.

      --
      John McAfee 'It was like that time I hired that Bangkok prostitute; to do my taxes, while I fucked my accountant'
    4. Re: Which is more important? by gravewax · · Score: 1

      Government Agencies? Banks? really? since when the fuck did they start using Tor for Business?

    5. Re: Which is more important? by Anonymous Coward · · Score: 1

      It should be none if there is a known Tor exploit.

    6. Re: Which is more important? by Pseudonym · · Score: 5, Informative

      Bank infrastructure is typically less secure than Tor.

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    7. Re: Which is more important? by Anonymous Coward · · Score: 5, Informative

      I'll counter, how many CIA agents rely on TOR? "The core principle of Tor, "onion routing", was developed in the mid-1990s by United States Naval Research Laboratory employees, mathematician Paul Syverson and computer scientists Michael G. Reed and David Goldschlag, with the purpose of protecting U.S. intelligence communications online. Onion routing was further developed by DARPA in 1997."

    8. Re: Which is more important? by aztracker1 · · Score: 1

      It's likely a exploit with Firefox, not your specifically that they don't want patched

      --
      Michael J. Ryan - tracker1.info
    9. Re: Which is more important? by gweihir · · Score: 3, Interesting

      The FBI does not care about prevention. They care about locking up people. Hence this is exactly as they want it.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    10. Re: Which is more important? by gweihir · · Score: 5, Interesting

      This is not a "Tor" exploit. It is a Firefox exploit against the version of Firefox used in the Tor browser bundle. It may well still be exploitable in current Firefox versions, including the one used in the current Tor browser bundle versions. Otherwise there really would be no point in keeping it secret.

      Hence the FBI is actively and knowingly endangering anybody using Firefox. That seems to be legal, but it is hugely unethical.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    11. Re:Which is more important? by Anonymous Coward · · Score: 1

      It's not about secrecy, it's about the government being able to crush dissent that it doesn't like. If you act against the interests of the US deep state and use TOR, you will be found. If you upload video of you torturing your 4 year old stepdaughter to death and raping the corpse, well, they don't give a fuck.

    12. Re:Which is more important? by guruevi · · Score: 1

      You mean, which is more important: being allowed to manufacture allegations or being exposed for manufacturing evidence.

      I hope the judge and the defendant doesn't just let this go, you can't just go around accusing people of doing CP and then totally drop it when you have to come up with the evidence.

      In other news: Obama and the FBI also say they never wiretapped US citizens using FISA courts.

      --
      Custom electronics and digital signage for your business: www.evcircuits.com
    13. Re: Which is more important? by MightyMartian · · Score: 2

      I'd argue the misuse of the term "treason" is a sign of mental health issues.

      --
      The world's burning. Moped Jesus spotted on I50. Details at 11.
    14. Re: Which is more important? by BronsCon · · Score: 2

      It's not just about Tor; if they won't disclose the Tor exploit they're using, there are certainly others they're holding on to, as well. How many do you think they're keeping to themselves that affect services you use every day? I'll tell you with absolute certainty that the number is not zero.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    15. Re: Which is more important? by BronsCon · · Score: 0

      The US Government developed Tor for its own use in securing its own classified communications. Not disclosing the vulnerability so that it can be patched (and alternate modes of transmission used in the interim) puts those communications at risk.

      I won't weigh in with an opinion on Hillary's actions, but perhaps this is why the FBI dropped their investigation into her committing the exact same offense through different means. If they charge her with treason for putting classified communications at risk, they open themselves up to the same charges for doing the very same thing.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    16. Re: Which is more important? by lucm · · Score: 4, Insightful

      Bank infrastructure is typically less secure than Tor.

      Bullshit. I have worked for three banks and they all had the best IT security money can buy. One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot.

      Meanwhile Tor has been the source of many incidents, especially once people started putting up fake nodes.

      --
      lucm, indeed.
    17. Re: Which is more important? by Anonymous Coward · · Score: 1

      If you are going to blame Tor for how users willingly send their identifiable info over it and *shock* they get identified, then under the same logic, is it not the banks fault for the trillions of phishing email scams that trick users into giving fake websites their banking passwords?

      If that is the comparison you are making, then you should realize it is *because* of banks that the term "phishing" even exists in common usage. They most certainly lose that battle.

      Of course here in the real world, no one blames either in the way you are doing.

    18. Re: Which is more important? by lucm · · Score: 2

      Government Agencies? Banks? really? since when the fuck did they start using Tor for Business?

      Since never. This was complete bullshit coming from someone with obviously no experience in this industry.

      Blockchain is getting traction in big business. It's even available on the IBM cloud platform (Bluemix). But this has nothing to do with Tor; for secure networking IBM is working on their own protected network, which will be similar to good old VAN for EDI.

      --
      lucm, indeed.
    19. Re: Which is more important? by spineboy · · Score: 1

      I guess the exploit is not too well known, or someone else would have found it, and possibly reported it.

      So if it's not very well known, I guess the FBI feels that the information it can obtain is worth the risk to others who might possibly be exploited by it.

      --
      ..........FULL STOP.
    20. Re: Which is more important? by Anonymous Coward · · Score: 0

      A system is only a good as i.t engineers set it up to be,it can have every bell and whistle possible,but if someone does something wrong or stupid,then possibly all the bells and whistles etc are no use..

    21. Re:Which is more important? by spineboy · · Score: 1

      I'll take the optimistic route here and say that the FBI isn't using this on people without cause - e.g. they've found people with CP and are bringing them to court. That should scare them hopefully into stopping. Yes - I'd prefer that they were punished.

      Call me naive, but I don't think they are using this as a smear/insinuation tactic against those who aren't looking at child porn.

      --
      ..........FULL STOP.
    22. Re: Which is more important? by gweihir · · Score: 2

      It may also be known to criminals that use it sparingly and carefully. Or to foreign intelligence agencies that are allowed to do industrial espionage (for example, the French). It may also be become widely known but patching it may require a few weeks. And so on. I think the FBI just does not care.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    23. Re: Which is more important? by Anonymous Coward · · Score: 1

      of course there is a point in keeping it secret.
      hacking random dudes computers is illegal even for FBI.
      running cp websites is illegal even for FBI (probably).

      the reason they want to keep it secret is that it would cause them to get sued and for the cases to be dropped.

    24. Re: Which is more important? by lucm · · Score: 3, Informative

      A system is only a good as i.t engineers set it up to be,it can have every bell and whistle possible,but if someone does something wrong or stupid,then possibly all the bells and whistles etc are no use..

      When it comes to high-end hardware, be it storage or networking, the vendor sends its own team to install and configure the device, and keeps monitoring and patching it. And guess what, that's what they do for a living and they're usually very good at it.

      Horror stories can and do happen. I've seen IBM wiping out huge SAN subsystems by mistake during an upgrade, or an HP engineer tripping on a power bar and pulling out a handful of optical fibers, disrupting networks in a whole building.

      What I have never seen or heard about is someone putting a misconfigured 1/2 million dollar core switch in production and nobody noticing the problem. Could it happen? Maybe. But that's not "typical".

      --
      lucm, indeed.
    25. Re: Which is more important? by Anonymous Coward · · Score: 0

      You are naieve. Child pornographers are not going to be scared into stopping. Changing tactics perhaps, but never stopping. Their need is a compulsion. They cannot be rehabilitated, or intimidated into stopping the behavior, because it isn't coming from a place of reason.

      Most assuredly, they will repeat their actions, and I hope the FBI is right there waiting for them with better means to put them away forever.

    26. Re: Which is more important? by Anonymous Coward · · Score: 0

      I worked almost two decades in the security department of a company that provided Internet Banking for ~2000 banks and credit unions, I've seen what the banks and credit unions had on their own and the huge increase in security that we provided.

      It was FAR from "the best IT security money can buy", it was the best security we could provide with the allocated money. There were lots of things that we knew that we wanted/needed to do that we were unable to do.

    27. Re: Which is more important? by cavreader · · Score: 2

      "They care about locking up people"
      This is the FBI organizational mandate and their reason for existing.

    28. Re: Which is more important? by Zontar+The+Mindless · · Score: 4, Insightful

      "Treason" has a very clear definition under US law, and you apparently do not know or perhaps even do not care what this definition is. My guess is that this is because it's a word you like to use purely for effect, rather than for actual communication.

      --
      Il n'y a pas de Planet B.
    29. Re: Which is more important? by Anonymous Coward · · Score: 0

      They may have developed it but if you think they still use it you are fucking clueless.

    30. Re: Which is more important? by BronsCon · · Score: 0

      Treason is the actual charge with which the FBI intended to charge Hillary Clinton. Whether it is a correct or incorrect use of the term lies with the agency, not with me. They did the very same thing they were investigating her for doing; therefore, to continue investigating her for that thing and risk having the act legally labeled as treason by way of a conviction against Clinton, the FBI would have been risking their own investigation and potential treason charges for those in charge of the Clinton investigation.

      Again, I'm not the one who said "treason", that came from House Homeland Security Chairman Mike McCaul. That is what the FBI investigating Clinton for.

      If McCaul and the FBI misunderstood the definition (notice how I'm not arguing over the legal definition here), that's on them, not me. It still doesn't change the fact that, and I'm purposely repeating myself to drive the point home, that is what they were investigating her for re: her email server while they were (and still are) doing the same thing, themselves re: the Tor exploit. That might indicate logical reasoning as to why they did not pursue the legal precedent of having such actions labelled as treason.

      Of course, if could also be any number of other reasons, including the fact that liability for leaking any classified documents would fall on the individual(s) who sent them to Clinton's personal server knowing that her server was not vetted for such communications (e.g. the person(s) who actually leaked the communications). That, of course, is my opinion; I also feel that she may share in that liability if she requested such documents to be sent to that server and, especially so, if she misrepresented the status of that server in the course of any such requests.

      Do I think she's innocent? I honestly don't know; it doesn't seem like she immediately deleted the emails and informed the sender not to send classified communications via that channel in the future, nor did she report and such breaches, though there were many of them. For that, I believe she bears liability to an extent. Treason? Perhaps not, but, again, I'm not the one who said it in the first place.

      Do I think a large number of military, law enforcement, and intelligence agents and analysts, along with many members of Congress and a slew of other government officials would have burned had charges been brought? Definitely. That, also, may or may not have had anything to do with the FBI dropping their investigation. Just as likely, in fact, as their knowledge that they were putting classified communications at risk just as much as Clinton was, and that it would eventually come to light; thus they may not have wanted to set a legal precedent.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    31. Re: Which is more important? by BronsCon · · Score: 1
      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    32. Re: Which is more important? by StevenMaurer · · Score: 2, Insightful

      Treason is the actual charge with which the FBI intended to charge Hillary Clinton.

      The FBI never intended to charge Hillary Clinton with treason. If they had, they would have recommended exactly that. They didn't even intend to charge her with mishandling classified information. If they had, they would have done so as well. The only thing that happened was that in deciding that she had done nothing worth an indictment over, Director Comey decided to violate protocol and offer critiques about her email practices. Presumably because he was Ken Starr's right hand man all during the 1990s, trying to pin something - anything - on the Clintons. And failed. Because they hadn't done anything illegal then, either. (With the exception of Bill lying under oath about an affair in a nuisance lawsuit.)

    33. Re: Which is more important? by mSparks43 · · Score: 1

      This and more is almost certainly already known to the FSB. Its one of the reasons they have been so successful keeping the CIA out of Syria.

      Keeping it secret undoubtedly helps he russians more than anyone. but given the lack of love between the FBI and the CIA, they wont have a problem with that.

    34. Re: Which is more important? by Anonymous Coward · · Score: 0

      *cough* terrorism *cough*.

      Words do not at all have clear meaning, not even in law. It's hugely context dependent, and lawyers prosecutors and judges routines make use of that. That's not to say that there may not be *some* statute proscribing an activity described as treason, but it's a fallacy to therefore assume there is no *other* activity that can be described as treason.

    35. Re: Which is more important? by BronsCon · · Score: 1

      That's all well and good, but the point still stands that it was McCaul who said "treason".

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    36. Re: Which is more important? by Anonymous Coward · · Score: 1

      That's not to say that there may not be *some* statute proscribing an activity described as treason

      Yes, there is "Some statute" known as the US Constitution.

    37. Re: Which is more important? by Anonymous Coward · · Score: 1

      Bullshit. I have worked for three banks and they all had the best IT security money can buy. One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot.

      I bet that on the customer side, the requirements for online banking required Java, a dead browser plugin from a dead company, which has been known to be insecure at least since 2004. And probably required it to be running on an old insecure version of Internet Explorer too.

    38. Re:Which is more important? by The_Revelation · · Score: 1

      We all knew that "Childporn" is merely a smokescreen for "We want to spy on lots of people". This is really just the proof that convicting CP offenders is a vastly distant priority to what they actually want to be doing.

    39. Re: Which is more important? by TheRaven64 · · Score: 2

      They care about locking people up so much that they're willing to drop a case rather than present evidence?

      --
      I am TheRaven on Soylent News
    40. Re: Which is more important? by MrKaos · · Score: 0

      The problem is, many people have access to it.

      Not in my experiences and I've designed and implemented security policy for banks you have heard of. ISO standards for security were beefed up and bank security policy for infrastructure is designed to exclude people who then have to justify access to a piece of equipment. No one even knows what a root password is because it is stored in pieces, in separate safes accessed by separate managers. People on holidays have their access revoked, plus other cumbersome but necessary procedures.

      Throw $100k at the admins and you'll likely find one who will help you out.

      If you can't even negotiate to the half way mark you undervalue all IT people everywhere. This is why you need unions, not because you're a special skillful snowflake but because you don't have a clue how to negotiate properly. Not because you're a socialist, because you want to see the money before you touch a keyboard. Not because you want to picket, because you want to have a group of technologists so powerful that no one will dare legislate against our interests.

      Instead most of us act like pussies begging to be treated fairly and complaining about a H1B visa bill that most of us were probably too apathetic to even write a single page letter to protest. This is not a criticism of you Mr. AC, merely an observation of how we got here.

      --
      My ism, it's full of beliefs.
    41. Re: Which is more important? by gweihir · · Score: 1

      You should have a look at their official mission statement. That says something different.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    42. Re: Which is more important? by gweihir · · Score: 2

      Given that one of the FBI's mandates is to stop foreign spying, I think it would be treason if they knowingly do nothing about that. Not that I think the FBI is above treason. A brief look at their history is pretty illuminating.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    43. Re: Which is more important? by geekmux · · Score: 1

      Bank infrastructure is typically less secure than Tor.

      Bullshit. I have worked for three banks and they all had the best IT security money can buy. One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot.

      Meanwhile Tor has been the source of many incidents, especially once people started putting up fake nodes.

      And yet with all that technology, Tor can't even hold a fucking candle to the global impact Greed and Corruption have caused in the banking industry.

      You can stop your bragging now, since it's clear no amount of security can detect or prevent that insider threat.

    44. Re: Which is more important? by AmiMoJo · · Score: 1

      The exploit doesn't target Tor though, it targets the Tor Browser, which is a fork of Firefox. So it is very likely that the exploit exists in Firefox too. We don't know how severe it is, but potentially some bank employee could be compromised by it.

      It's easy to imagine hospitals or air traffic control being hit by ransomware, or foreign powers gaining access to high ranking members government's computers this way. It's unlikely that they would have the kind of extreme IT security in place to avert that kind of attack, i.e. a router that does MITM attacks to inspect HTTPS streams with suitable certs installed on all client devices and even then apps with pinned certs scream at the user.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    45. Re: Which is more important? by Anonymous Coward · · Score: 0

      I just got a letter with a free year of credit monitoring because someone left an e-mail account laying around with the entire banks database in it. Thanks.

    46. Re: Which is more important? by Tranzistors · · Score: 1

      Perhaps FBI are not that greedy to win one case to loose evidence gathering tool, that can win them many more. Fixing a vulnerability will not limit crime done, so there is little incentive for them to disclose it.

    47. Re: Which is more important? by Anonymous Coward · · Score: 0

      The cia uses TOR outside the US. FBI's role is to stop spying within the US.

    48. Re: Which is more important? by Anonymous Coward · · Score: 0

      You cannot negotiate when you are not in a position of power, which 99% of IT is not due to globalization.

    49. Re: Which is more important? by haruchai · · Score: 2

      Every org has a propaganda statement

      --
      Pain is merely failure leaving the body
    50. Re: Which is more important? by CrimsonAvenger · · Score: 2

      I posit that it's unethical and treasonous to not disclose the vulnerabilities

      You posit wrong. Treason is defined in the Constitution, and the legal barrier for treason is so high that only 13 people have ever been so convicted, and two of those were pardoned by the Pres later....

      --

      "I do not agree with what you say, but I will defend to the death your right to say it"
    51. Re: Which is more important? by Zontar+The+Mindless · · Score: 1

      An AC who didn't sleep through high school Civics class--who'd've thunk it?

      --
      Il n'y a pas de Planet B.
    52. Re: Which is more important? by MrKaos · · Score: 1

      You cannot negotiate when you are not in a position of power,

      It would be interesting to see what would happen if IT workers everywhere stopped working for two weeks, just took a break. IT professionals did not seize power of our own destinies when we could and we have ourselves to blame. People are uncomfortable with that reality because it means having to take personal responsibility for their own careers and the state of the industry they work in.

      which 99% of IT is not due to globalization.

      Globalization was a series of trade agreement and the reality is that we may be very smart, however we haven't been very wise, so their is no one watching our backs at a political level to moderate those trade agreements at the time they were being framed.

      If we had more foresight the legal frameworks that dictate the behavior of our industry would strike a better balance between competing and co-operating. Taking personal responsibility might mean not watching TV for a week while you write letters to politicians and make sure your interests are being served. That's the price of living in a democracy. That's what it takes to effect transformation, facing uncomfortable truths and figuring out what to do.

      That's the difference between being a leader or being a follower and people think the governments are their leaders, they don't think that they are their leaders.

      --
      My ism, it's full of beliefs.
    53. Re: Which is more important? by AlanObject · · Score: 1

      Bullshit. I have worked for three banks and they all had the best IT security money can buy.

      I would agree with this and when is the last time you heard of a major U.S. bank being compromised?

      However I wouldn't attribute this to just expensive gear they buy. Banks have had a culture of secrecy and security long before the tech equipment we use today was even thought of let alone deployed. This involves how the carbon-units in the system behave with regard to things about how they save and use their passwords and what the process is before they hook up a new cable.

      The Tor software may or may not have an exploit in it but I would bet money it is actually not the software but the ability of the FBI to put up probing and taping stations around the net that uses it. It is easy to imagine that just analyzing the timing the entry/exit of packets over long term would be enough to nail it.

    54. Re: Which is more important? by Anonymous Coward · · Score: 0

      "One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot."

      That's the networking equivalent of "I'm running AVG, Symantec, and Avast!".

    55. Re: Which is more important? by weeboo0104 · · Score: 1

      The bar may not be as high as you think.
      https://en.wikipedia.org/wiki/...

      --
      It is easier to build strong children than to repair broken men. -Frederick Douglass
    56. Re: Which is more important? by gnasher719 · · Score: 1

      The FBI does not care about prevention. They care about locking up people. Hence this is exactly as they want it.

      Not in this case. The caught a fish, a nasty fish, but a little fish, so they rather throw him back into the lake to have a chance to catch bigger fish.

      In this case, a known pedophile isn't going to jail, but on the other hand, it's very unlikely that he does the same thing again.

    57. Re: Which is more important? by DamnOregonian · · Score: 1

      I'm unsure what that has to do with treason. He was tried under UCMJ martial law, a code that in ye olden days has been used to execute people for taking a horse.

      While I agree it doesn't make much difference to the guy who got hanged, for the rest of us, there is a distinction between terrible shit the military does when it is in control of an area, and the constitutional laws of our country.

    58. Re: Which is more important? by Arkham · · Score: 2

      Bank infrastructure is typically less secure than Tor.

      Bullshit. I have worked for three banks and they all had the best IT security money can buy.

      When we are interviewing mobile developers, the ones that come from banks are the worst. They never know how anything works, they have no concept of security, certificate pinning, encryption, buffer overflows or at-rest protection of data. Inevitably the explanation is that they are given a library which "does all that for us". I am not sure what this magical library does, but blind faith is not security and doesn't lead to security. I'm very wary of mobile banking apps as a result. Ever tried to MITM a banking app? It's trivial.

      --
      - Vincit qui patitur.
    59. Re: Which is more important? by Anonymous Coward · · Score: 0

      Oh look, a fucking political temper tantrum in a technology forum. Is that you ShariaBlue?

    60. Re: Which is more important? by Anonymous Coward · · Score: 0

      Nothing like giving the vendor backdoor access to your data.

    61. Re: Which is more important? by Anonymous Coward · · Score: 0

      You're wrong. My house cost more than your shiny BlinkyLichten

    62. Re: Which is more important? by Obfuscant · · Score: 1

      The only thing that happened was that in deciding that she had done nothing worth an indictment over,

      That's not what Comey said. Here:

      Although there is evidence of potential violations of the statutes regarding the handling of classified information, our judgment is that no reasonable prosecutor would bring such a case.

      Earlier in that statement he says that there is good evidence of mishandling of known Top Secret material. But finding a prosecutor who would prosecute would be hard.

    63. Re: Which is more important? by gweihir · · Score: 1

      And where did you miss that this is about a vulnerability in Firefox, not in Tor?

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    64. Re: Which is more important? by StikyPad · · Score: 1

      On top of that, what use is a tool that can never be used for it's stated goal: finding and prosecuting criminals?! Presumably they would dismiss any charges where a defendant performed due diligence in discovery, which should be all of them. The FBI seems to want to have their cake and eat it too.

    65. Re: Which is more important? by Anonymous Coward · · Score: 0

      You should have a look at their official mission statement. That says something different.

      I just read it and going after child porn doesn't even seem to be part of their missing.

    66. Re: Which is more important? by Anonymous Coward · · Score: 0

      It's almost like there's a reason they are looking for a new job...

    67. Re: Which is more important? by lucm · · Score: 1

      Bullshit. I have worked for three banks and they all had the best IT security money can buy. One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot.

      I bet that on the customer side, the requirements for online banking required Java, a dead browser plugin from a dead company, which has been known to be insecure at least since 2004. And probably required it to be running on an old insecure version of Internet Explorer too.

      No, but one of them had an interesting password policy for eBanking: 5 characters (exactly), only numbers and letters. To be fair they had a decent MFA but still. The reason? Make the password phone-friendly so people could use the same when dialing in.

      --
      lucm, indeed.
    68. Re: Which is more important? by lucm · · Score: 1

      I agree, but please keep in mind that there is more to Tor exploits than this one. For instance:

      The hacker group appears to be attempting to dominate Tor's relays to the point where it can comprise anonymity. Tor keeps you anonymous by bouncing your communications around a network of volunteer nodes. But if one group is controlling the majority of the nodes, it could be able to eavesdrop on a substantial number of vulnerable users. Which means Lizard Squad could gain the power to track Tor users if it infiltrates enough of the network.
      So far, they have already established over 3000 relays, nearly half of the total number. That's very not good.

      https://pando.com/2014/12/26/i...

      --
      lucm, indeed.
    69. Re: Which is more important? by lucm · · Score: 1

      Banks have had a culture of secrecy and security long before the tech equipment we use today was even thought of let alone deployed.

      Totally agree. For instance I remember years ago, a client of mine had a policy of wiping printers memory before junking them, in case confidential documents were still in memory. That's not high tech but that shows how those people think.

      --
      lucm, indeed.
    70. Re: Which is more important? by Anonymous Coward · · Score: 0

      A mission statement doesn't list every possible crime the FBI is in charge of investigating. Roll all the details up and at the end of the day the FBI's end game is putting criminals in prison.

      You need to read the NSA and CIA mission statements. Their mission statements do not hide the fact that their purpose is to run covert intelligence and counter intelligence programs in defense of the country. Roll everything up and they are spies. I don't know why this came as such a surprise to people but it did. These same morons act also behaved like the US is the only country running foreign intelligence operations on friends and foes.

    71. Re: Which is more important? by Archfeld · · Score: 1

      That is my experience as well. As a sysadmin I had root access to my devices while the programmers who actually knew what to do with them and how the code worked had to seek access from info security. Check and balance. When I worked at a bank the security modules made by tandem had 3 keys, one in Ops hands, one in a locked double access key cabinet and one in info security possession. It often took longer to get access to the devices than it did to update or repair them.

      --
      errr....umm...*whooosh* *whoosh* Is this thing on ?
    72. Re: Which is more important? by Anonymous Coward · · Score: 0

      Then why do attack vectors target card numbers and such instead of directly stealing from the banks?

    73. Re: Which is more important? by Pseudonym · · Score: 1

      Tor has been the cause of more incidents, but I'd be willing to bet that more peoples' personal data was leaked by bank data breaches than by Tor.

      Having said that, you do have a point. Banks do typically go to a lot of trouble to keep their information secure, especially from regulators.

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    74. Re: Which is more important? by david_thornley · · Score: 1

      And, according to you, McCaul is not part of the FBI. Clinton did nothing resembling treason, and anyone in a governmental role who said so was being irresponsible.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    75. Re: Which is more important? by david_thornley · · Score: 1

      I've been told that the law doesn't require intent, but when I checked cases it turns out that prosecution does. Unless there is an intent to violate the law, there is no prosecution. Whether or not the defendant intended to do anything bad with deliberately obtained classified material doesn't matter.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    76. Re: Which is more important? by AutodidactLabrat · · Score: 1

      It is "unethical and treasonous" (sic) for the FBI to intercept private communications without a warrant.
      Taking over a server in order to observe private communications is therefore a criminal act.
      So SCREW you and the security state you admire!

    77. Re: Which is more important? by lucm · · Score: 1

      I'd be willing to bet that more peoples' personal data was leaked by bank data breaches than by Tor.

      Please name three recent instances of US banks data breaches.

      --
      lucm, indeed.
    78. Re: Which is more important? by Pseudonym · · Score: 1

      Fair enough. I don't live in the US and wasn't thinking about there specifically.

      --
      sub f{($f)=@_;print"$f(q{$f});";}f(q{sub f{($f)=@_;print"$f(q{$f});";}f});
    79. Re: Which is more important? by Anonymous Coward · · Score: 0

      I don't think you know what a switch does.

      And I think the person was referring to local bank branches. For example, the offices in my local branch have office windows visible to the outside world, and all their monitors can be seen from the street. They don't even rotate their desk/monitor to display away from window.

      Though, having a $400k core router at each branch would explain why my fees go up and services down each year.

    80. Re: Which is more important? by joemck · · Score: 1

      I would imagine and sincerely hope the internal and interbank stuff is pretty secure. Many banks' user-facing systems aren't though.

      My bank forces me to use a password between 8 and 32 characters long. If I log in from a different machine, they quiz me on things that an attacker could easily look up in public records, like which people I've lived with or which small street I've never heard of is closer to my home. Some banks even ask for selected characters from your password as verification -- which at the very least means they're storing some characters of your password and subtracting from its entropy, and likely means they're storing passwords rather than hashes of them!

      Compare to something as relatively unimportant as my Tumblr blog, where I can use longer passwords and proper two-factor authentication using Google Authenticator. And when I was locked out of Facebook, they asked me questions that I could actually answer without referring to Google Maps, yet ones that an attacker would have a harder time answering.

    81. Re: Which is more important? by eric_harris_76 · · Score: 1

      I posit that it's unethical and treasonous to not disclose the vulnerabilities because those exact same vulnerabilities can be used against our own citizens and government agencies by foreign agents.

      I posit that it's unethical and treasonous to not disclose the vulnerabilities because those exact same vulnerabilities can be used against our own citizens by U.S. government agents.

      --
      There's no time like the present. Well, the past used to be.
    82. Re: Which is more important? by Anonymous Coward · · Score: 0

      How the fuck are letters phone friendly? Is it also case sensitive?

      - me, to the person who thinks up such stupid things.

    83. Re: Which is more important? by BronsCon · · Score: 1

      He is the Homeland Security Chairman. If the FBI was investigating Hillary after his remarks (hint: they were), they were doing so under his direction. If they were investigating Hillary under his direction, they were investigating her for his reasons. His reasons were as stated: Treason.

      Again, he may have been using the word incorrectly; but it follows that, by investigating Hillary under the direction of McCaul, who suspected her of Treason, the FBI was investigating Hillary for Treason.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    84. Re: Which is more important? by david_thornley · · Score: 1

      Assuming Clinton didn't confess to treason, the only way to convict would be witnesses to some overt act that provided aid and comfort to an enemy. That's a very high bar, and deliberately so. I'm about as anti-Trump as you're going to find, and I don't suspect him of treason. Anyone who used the word to describe Clinton's activities in any sort of official capacity was very irresponsible.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
    85. Re: Which is more important? by BronsCon · · Score: 1

      Anyone who used the word to describe Clinton's activities in any sort of official capacity was very irresponsible.

      Notice how I am not disagreeing. I'm merely pointing out that this is the word that was used. You know, stating facts.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    86. Re: Which is more important? by Anonymous Coward · · Score: 0

      I have worked for three banks and they all had the best IT security money can buy.

      I have worked for a Finical Services company that serves over a 100 banks and the security is crap. Your money is better off in a wet paper bag.

      One of my current clients has a core switch that's worth more than your house, it's crammed with IDS and IPS modules and whatnot.

      Sure they have one but the big question is "Is it properly configured?". If it is not set up right you are worst off than having it.

    87. Re:Which is more important? by syntotic · · Score: 1

      OR... they have no case. They find the people and people say: WHAT? Bugger off my life! And the girl is already a grown up (or was not even a girl but a midget), and that is very inconvenient for the law they want to enact, legal age, which is in fact an off stem of Indian influence and really deleterious in terms of population dynamics and genetics. So they come up with the excuse that those cases have to be dropped because of software used illegally! Not because of actual rejection. In any case the whole issue is embarrassing, what about having a computer infected and it happens to be the person who IS looking for the girl because the mother is missing? THAT is even more embarrassing! Raining over wet soil, going against the victim and further victimizing his computer!

    88. Re: Which is more important? by lucm · · Score: 1

      How the fuck are letters phone friendly? Is it also case sensitive?

      - me, to the person who thinks up such stupid things.

      It's not case sensitive (on the phone), but the interactive voice menu is so annoying that hackers would probably give up before they could achieve something nefarious anyways.

      --
      lucm, indeed.
  2. Deploy malware? by Anonymous Coward · · Score: 0

    Apart from the stupid "run this executable to view videos" (wink-wink), how are people getting malware from visiting a website?

    1. Re:Deploy malware? by cdsparrow · · Score: 1

      You think the FBI doesn't have access to browser exploits that haven't been patched? That is what we pay our FBI/NSA folks for.

    2. Re:Deploy malware? by TWX · · Score: 4, Interesting

      You do know that javascript, java, and flash exploits are still a thing, right?

      I would not be surprised if the FBI has learned of an exploit for one of these or in the Tor implementation itself, and has chosen to not disclose it because they can continue to use it for parallel-construction cases, or because their knowledge of it came from another agency that still wants to use it for international crimes.

      --
      Do not look into laser with remaining eye.
    3. Re:Deploy malware? by Dunbal · · Score: 2

      Adobe.

      --
      Seven puppies were harmed during the making of this post.
    4. Re:Deploy malware? by AHuxley · · Score: 1

      Depends on what the browser is:
      A modern browser will respond to a to more than http and https. A well crafted request to different media or peering support in a browser might result in the correct IP been sent due to default settings.
      Also given what a modern OS had at the time to make the internet work.
      The next issue would be a browser in a VM using onion routing?
      Finally a full onion routing OS as a computer.
      The ability to send commands to a browser expecting it to be working in a normal OS might be all that was needed.
      Would an outgoing software firewall help if it was the browser? Software to detect changes to the OS? The browser is running as allowed and expected.

      --
      Domestic spying is now "Benign Information Gathering"
    5. Re:Deploy malware? by Ramze · · Score: 4, Interesting

      Tor disables javascript, java, and flash by default... so the exploit must have been in the mozilla firefox code base or the onion routing protocol -- unless they run and/or spy on all the Tor nodes to figure out where things are really being routed.

      I've read stories where the feds attempted to shake down libraries to get them to close their Tor nodes, yet the feds run their own. If you control all the nodes, it's easy to figure out the real routing through the onion network.

    6. Re:Deploy malware? by Anonymous Coward · · Score: 4, Informative

      Tor does NOT disable Javascript by default. It ought to, but it doesn't. The last official statement was they felt nobody would use Tor if it shipped with Javascript disabled, because so much of the web depends on it.

    7. Re:Deploy malware? by Anonymous Coward · · Score: 2, Informative

      > Tor disables javascript, by default...

      It absolutely does not. It has noscript by default, but you have to make that change. With javascript disabled by default, many websites simply fail to function.

      Tor project seems to assume that javascript is simply vulnerable permanently, which is generally what all sane computer users should assume at this point. Their solution seems to be to put some kinda sandbox around it, which should at least give them a bit of a race to run versus attackers.

      Your other assumptions are totally reasonable however- run a bunch of nodes and you can break a lot of the assumptions about tor.

    8. Re:Deploy malware? by Anonymous Coward · · Score: 1

      Thank you for using our malware, courtesy of Windows since Win95sp1.

    9. Re: Deploy malware? by Andy+Smith · · Score: 2

      In the 30+ years that I've been using computers, I've had 4 viruses. Two of them came through Adobe exploits. (Both were served by web ads on mainstream sites, which downloaded and auto-opened PDF files which in turn deployed and opened executables.)

    10. Re:Deploy malware? by Ramze · · Score: 4, Insightful

      Good catch! You're right. It instead has NoScript installed, but not even configured properly.

      I'm frankly surprised anyone there would even argue to leave it on. Better to have a web site break than have a malicious site track you when the purpose of using it is to NOT be tracked.

    11. Re:Deploy malware? by Pentium100 · · Score: 1

      Run the browser in a separate VLAN and only allow that VM to communicate with a VM that runs the node. There would be no way for the browser VM to find out the real IP. The node can also be made to use a VPN service or something to complicate matters more.

    12. Re:Deploy malware? by nosfucious · · Score: 1

      The earliest browsers also responded to more than HTTP and HTTPS. Ever heard of gopher?

      Now git off er my lorn!

      --
      Q:I was listening to a CD in Grip and it sounded horrible! What's up? A:Perhaps you are listening to country music
  3. So 135 more dismissals in queue? by Anonymous Coward · · Score: 5, Interesting

    Sounds like there is a very simple formula for defense now and forever for any of their tor tapping. Smart, very smart.

    1. Re:So 135 more dismissals in queue? by Anonymous Coward · · Score: 0

      They could have decided that the "threat" of an exploit will reduce the use of Tor.

      Even if an exploit is patched in tor / firefox, you will never know if that is the FBI's exploit.

  4. for the good of by Anonymous Coward · · Score: 0

    don't worry, its for the good of the children.....

  5. Now we know where the moral compass is pointing. by MrCodswallop · · Score: 5, Interesting

    Interesting, albeit disturbing, insight into the moral compass of the FBI. Secrecy trumps child pornography.

  6. Wrong focus. by Gravis+Zero · · Score: 5, Interesting

    The question is if the FBI is actively seeking the child abusing producers of child pornography or if they are really only interested in catching the people who download it. It's all very distasteful but I'm more interested ending the abuse than throwing every twisted individual in jail for a period of time. I understand that it's a global problem which is why governments should work together to stop the madness.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:Wrong focus. by Anonymous Coward · · Score: 0

      can't be "ended" since for every investigation that is concluded more kids have just started being abused, police just go through the motions like drug enforcement

    2. Re:Wrong focus. by oic0 · · Score: 1

      Their logic is that the people who pay to view it incentivise its creation. They aren't wrong. It doesn't incentivise it here so much, but in foreign countries where enforcement is null and money is scarce. Honestly though, they need to do research and come up with a real strategy if they want to have an impact. While they're at it, they need to stop publishing names before they have convictions. That's total BS.

    3. Re:Wrong focus. by Anonymous Coward · · Score: 1

      Their logic is that the people who pay to view it incentivise its creation. They aren't wrong.

      And THAT is why they prosecuted for possessing or making cartoon drawings of underage children?
      You'd think if that was their logic, they would run a clinic where one could get all the (drawn) child porn cartoons they needed. To minimize the harm to actual live children.

    4. Re:Wrong focus. by Anonymous Coward · · Score: 0

      With that question in mind, a rational explanation I can think of is that they are dropping these cases because it's not worth revealing the flaws they exploit just for downloaders, and that they are saving their disclosure for when they believe they have a producer.

    5. Re:Wrong focus. by gweihir · · Score: 5, Interesting

      Well, judging from their tactics in "fighting terrorism", they would produce child pornography themselves, if they legally could. They have been producing "terrorists" for a while now. Hence my take would be they have zero interest in in actually doing anything real about the problem because that could dry up the ready supply of downloaders that they can catch and prosecute easily. And with that supply drying up, their funding and power would get reduced. If that is not a perfectly fine motive explaining what they are doing, then I do not know what is.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    6. Re:Wrong focus. by gweihir · · Score: 3, Interesting

      Actually, it seems that they are wrong. First, most child abuse obviously does not end up on film. That part they are completely ignoring. Second, even if they are not saying it loudly, there are statements by law-enforcement in different countries that there is no "industry" behind child abuse, it is mostly amateur stuff and it is mostly traded without money involved. Incidentally, follow-the-money is something law-enforcement is very, very good at, so if this really was mostly commercial, they would long since have stopped the whole thing with ease.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    7. Re:Wrong focus. by Anonymous Coward · · Score: 0

      If you want to "deincentivise" producers, the most obvious logic is the direct threat of law enforcement. Catching a thousand Johns might dent the industry. Catching a few producers will dent it immediately, and discourage the rest. Even the persistent ones will change protocol/security, which we all know costs convenience (and profits).

      Impoverished places will see it as high reward, it's always going to be high yield. Better to mess with the idea that they're safe from the law's eyes, that LEOs are satisfied with the low-hanging fruit. Which isn't baseless, being able to show arrests and flashing "captured child predators" is prime material.

      Even so LE wants the big fish; didn't RTFA but my blind guess is they let a small fish (with big lawyers) escape to preserve the tools.

    8. Re:Wrong focus. by quantaman · · Score: 0

      Actually, it seems that they are wrong. First, most child abuse obviously does not end up on film. That part they are completely ignoring. Second, even if they are not saying it loudly, there are statements by law-enforcement in different countries that there is no "industry" behind child abuse, it is mostly amateur stuff and it is mostly traded without money involved. Incidentally, follow-the-money is something law-enforcement is very, very good at, so if this really was mostly commercial, they would long since have stopped the whole thing with ease.

      That might be a big reason why they do go after the downloaders.

      In general, people who look at child pornography are people who have a sexual interest in children. And if you're trying to find people who are sexually abusing children then finding people with a sexual interest in children is a great way to start.

      Obviously that's not the only motive, or they wouldn't charge people just for downloading. But I doubt they'd be very interested in the downloaders if they didn't have a huge overlap with abusers.

      --
      I stole this Sig
    9. Re:Wrong focus. by Anonymous Coward · · Score: 0

      The free market at work. In this case the FBI's raw materials are criminals, their product is convictions, their customers are the US tax payers.

      Why would the FBI possibly want to eliminate the materials they need to stay in business?

    10. Re:Wrong focus. by gweihir · · Score: 3, Insightful

      That argument cannot hold water. The "big" law-enforcement actions against downloaders in Europe in the last few years have yielded no or nearly no children to be freed of their abusers.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    11. Re:Wrong focus. by Anonymous Coward · · Score: 0

      > They have been producing "terrorists" for a while now.

      Pro tip: if anyone asks you if you want to commit a crime, the best answer is "no." Whether it's a sting operation or not, you can be busted. The people they bust think they're taking part in real terrorist plots. And they would be if they'd have gotten in touch with real terrorists and not an FBI sting operation.

    12. Re: Wrong focus. by Anonymous Coward · · Score: 0

      Your a fucking idiot

    13. Re:Wrong focus. by TheRaven64 · · Score: 2

      In general, people who look at child pornography are people who have a sexual interest in children. And if you're trying to find people who are sexually abusing children then finding people with a sexual interest in children is a great way to start.

      By the same argument, anyone who looks at porn involving adults is a potential rapist. It's pretty obvious that anyone who sexually abuses children is going to enjoy child pornography (though it's not clear that they're going to successfully find any). It's far less obvious that child pornography is some kind of gateway to child abuse, especially given that the vast majority of cases of child abuse are by the child's own parents.

      But I doubt they'd be very interested in the downloaders if they didn't have a huge overlap with abusers.

      Why? Both groups are about as unpopular in the media, one is a lot harder to catch. If I were setting priorities in a highly politicised law enforcement agency, I know which group I'd target.

      --
      I am TheRaven on Soylent News
    14. Re:Wrong focus. by gweihir · · Score: 1

      But the point is the were no danger because they had zero chance of pulling it off alone. If you start to lock up anybody that would do a crime but cannot and claim them to be a real danger, then you are massively inflating the perception of the problem. And that is the issue here.

      Your argument fails, BTW, because if they had been in contact with real terrorists, then real terrorists would have been in the picture and there would hence have been a real danger. There was not.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    15. Re:Wrong focus. by quantaman · · Score: 1

      In general, people who look at child pornography are people who have a sexual interest in children. And if you're trying to find people who are sexually abusing children then finding people with a sexual interest in children is a great way to start.

      By the same argument, anyone who looks at porn involving adults is a potential rapist.

      Nope, because two adults can have a consensual sexual relationship.

      --
      I stole this Sig
    16. Re:Wrong focus. by edtice1559 · · Score: 1

      I wish I hadn't commented so that I could mod parent up.

    17. Re:Wrong focus. by Anonymous Coward · · Score: 0

      fail

    18. Re:Wrong focus. by Sumus+Semper+Una · · Score: 1

      That might be a big reason why they do go after the downloaders.

      In general, people who look at child pornography are people who have a sexual interest in children. And if you're trying to find people who are sexually abusing children then finding people with a sexual interest in children is a great way to start.

      Obviously that's not the only motive, or they wouldn't charge people just for downloading. But I doubt they'd be very interested in the downloaders if they didn't have a huge overlap with abusers.

      Your argument is that observation and fascination often leads to mimicking the action? If that were true, then the FBI should be investigating ISIS by lurking on the Counter-Strike forums... Or, if you want to stick purely to sexuality, then insurance companies should be raising premiums on anyone who they have data on that shows they've been watching porn that includes unprotected sex, as they are obviously spreading STDs...

    19. Re:Wrong focus. by Anonymous Coward · · Score: 0

      They don't care about catching real predators, just attacking the activists who've called them out their hypocrisy in distributing child porn, which they argue is hurting children, so in other words, the FBI HURT children by their messed up logic:

      Raid of Free Talk Live studio's (not the first time either, last time it was over dead or missing batteries in a smoke alarm, of course they didn't know that before the raid):

      http://freekeene.com/2016/03/22/free-talk-lives-press-release-about-fbi-raid/

    20. Re:Wrong focus. by lars_stefan_axelsson · · Score: 1

      Well, judging from their tactics in "fighting terrorism", they would produce child pornography themselves, if they legally could. They have been producing "terrorists" for a while now.

      Yes. And I was troubled by what seemed like ineptitude in addition to all other moral problems that that approach entails.

      But then I dug a bit deeper and found Al Queda training material that explicitly warned would be home made jihadists from seeking like minded and forming a cell with the motivation that any like minded you find will most likely be law enforcement or an informant.

      That puts the tactic of trying to trap everyone and his brother and doing so very publicly in another, more effective light. While the moral and ethical problems with such an approach remain, it suddenly looks both effective and down right sneaky. Denying your enemy the well known effectiveness of organising and acting in a group, having him commit his forces piecemeal is good for your effort, and hinders his. (Its not for nothing that the military always fight in teams or groups, and almost all of the training is devoted to how to work as a team and part of a team.)

      From that perspective you can almost see the powers that be thinking that finding and stopping "black swan" self radicalised terrorists is almost impossible, so the second best thing is to limit their effectiveness by denying them the advantage of organising. And this is something that has been borne out in e.g. in France. The Charlie Hebdo terrorists were brothers, and hence difficult to isolate with such a strategy. They'll trust each other implicitly. The other organised attacks were by groups that had been put together and trained abroad. Those are more dangerous but also much more vulnerable to traditional police and intelligence efforts (even though they obviously failed here).

      So, from that perspective, i.e. pure effectiveness without trying western sensibilities too much (they even follow established law and everything), there could be something well thought out behind this approach. And Al Queda and its ilk has obviously taken notice themselves, so whether thought out in advanced and executed, or just a haphazard happy accident, it has had effect.

      And isn't that a scary thought? They may not be wholly incompetent, but actually good at their jobs... :-)

      --
      Stefan Axelsson
  7. Re:Now we know where the moral compass is pointing by Harlequin80 · · Score: 1

    Or catching 10 trumps catching 1.

  8. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 3, Interesting

    There's also a possibility that they haven't got anything as much to disclose as they'd like us to believe. Maybe some of the evidence supposedly gathered through the exploit, was instead obtained through another, possibly illegal, method or fabricated.

  9. Re:Now we know where the moral compass is pointing by rtb61 · · Score: 4, Insightful

    Or letting one more child be raped and murder equals what the fuck exactly? Those child porn rings require content and every time a content producer is exposed, an arrest and rescue should immediately occur, 'IMMEDIATELY', fuck future prosecutions.

    --
    Chaos - everything, everywhere, everywhen
  10. Re:Now we know where the moral compass is pointing by MrCodswallop · · Score: 1

    That reinforces the banality of technology being a double-edged razor.

  11. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Well it was federal prosecutors that dropped the case - so it's not entirely clear why. The reason stated is that the FBI doesn't want to expose the browser exploit. But now everyone knows they have one that is probably undocumented. Or they don't want to compromise other investigations into maybe terrorism or other crimes that would be problematic at this stage. Or there is a FISA court decision that can't be publicly exposed so they made another excuse. Who really knows. But given how the federal bureaucracy has grown so expansively over the last several decades, and especially their behavior over the last decade and a half, I would not be surprised about anything at this point. This is a good reason why the federal budget needs to be slashed about 50% and these cretins removed from power.

    I don't think the FBI is condoning it anyway. But as made famous in a quote from a film, it's not about what is true, it's about what you can prove that matters in court.

  12. Re:Now we know where the moral compass is pointing by ewibble · · Score: 1

    Of course it does, even if consider child porn the worst crime imaginable (I would consider going around killing children worse), disclosing this would mean the vulnerability would be fixed and they would no longer be able to use it to find more offenders. You could still identify them this way and then gather other evidence.8

  13. Ran it for 13 days by Anonymous Coward · · Score: 3, Insightful

    First I heard it was a month.
    But anyways, they got zero producers.
    Distributed over a million images, which means they revictimized children over a million times. This is their own logic on sharing these images btw.
    None of this is effective. None of this is okay. Get the producers FFS or keep the op going until you do.
    This doesn't feel right at all.

    1. Re:Ran it for 13 days by gweihir · · Score: 2

      Indeed. But if they go after the producers (which I have no doubt they could do), they would stop the ready supply of easily identified consumers. And that would cut into their convictions, and hence into their funding and power. It is rather obvious why they do not do that.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    2. Re:Ran it for 13 days by Anonymous Coward · · Score: 0

      This is probably the least conspiratorial reasoning that exists and probably totally true.

    3. Re:Ran it for 13 days by gweihir · · Score: 1

      Unfortunately, yes.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  14. FBI refuses to think of the children by Anonymous Coward · · Score: 1

    Next time they bring out that tired old line this will be one more thing to point to. Just more do as I say not as I do.

    1. Re:FBI refuses to think of the children by Anonymous Coward · · Score: 0

      this is the exact opposite though, instead of thinking purely about slamming the piece of shit in Jail they are more concerned with being able to save more children by being able to actively monitor and shutdown others. So this really is a case of them thinking of the children.

    2. Re:FBI refuses to think of the children by sir-gold · · Score: 1

      Except they just gave the other 135 people a free pass with this. All they have to do is demand the source code as well.

    3. Re:FBI refuses to think of the children by Anonymous Coward · · Score: 0

      still comes down to what is more important, punishment or stopping them. I think it is better to let the lot of them go (and monitor them) then lose access to information that is helping them shutdown these sites and maybe even save some childrens lives. Not sure there is a right or wrong answer here, FBI have chosen what they think will do the most good.

    4. Re:FBI refuses to think of the children by gravewax · · Score: 1

      Have they really been given a free pass though? unless the statute of limitations has expired they can cream as much information out of this for the next year or 2 and then proceed to prosecute everyone once the vulnerability is discovered and closed. Unless you have already been through a trial there is no double jeopardy issues with reinstating the charges later

    5. Re:FBI refuses to think of the children by sir-gold · · Score: 1

      I suspect that they are hiding some fatal flaw in the evidence collection method, which will invalidate the evidence (or at least violate the warrant) if the full method is revealed.
      Other sites have mentioned that the malware may have been loaded too early, before the target had actually broken the law (which takes it beyond the scope of the warrant)

    6. Re:FBI refuses to think of the children by gravewax · · Score: 1

      More likely they are still chasing down suspects, providing information may make it easy for suspects to check if they have been stung and rapidly cleanup the evidence. Not sure how you can load the malware too early when you are accessing an illegal child porn site!

    7. Re:FBI refuses to think of the children by Anonymous Coward · · Score: 0

      Quite simply because malware by its very definition is not something one knowingly and willingly put on their computer.
      It's one thing to have it packaged IN the child porn, so that anyone who accessed the site and has the malware on their computers can be said to have downloaded child porn.

      But if it's installed beforehand, and if this is discovered, then one could easily argue there was no intent or attempt at downloading child-porn; the malware did this without the user's knowledge or consent.

      Given the FBI's track record, it's entirely possible much of the child porn they've "caught" anybody with was placed there by themselves in the first place. I'd be surprised if they caught any legitimate perverts; catching criminals has nothing to do with what they do these days

    8. Re:FBI refuses to think of the children by sir-gold · · Score: 1

      It was loaded as part of the login screen, before the person had actually gotten into the site (and onion addresses are intentionally nonsense, so there is no way to know what site you are actually going to end up at when you click a link).

      They are charging people on the basis that the presence of the FBI spyware alone is proof of guilt, whether or not they find any child porn on the persons computer, and more importantly, whether or not they had actually accessed anything illegal.

      It's like setting up a camera at the door to an illegal brothel, and charging everyone who goes through that door with soliciting prostitution, even if they were just drunk and lost.

  15. Re:Now we know where the moral compass is pointing by Gravis+Zero · · Score: 3, Insightful

    If you look at it rationally, you will see it's the best approach for getting the highest quantity of jailings versus the highest quality of cases. That seems like the most likely justification. This doesn't address whether they are doing more or less harm than good by withholding the information but I think their view should be obvious.

    --
    Anons need not reply. Questions end with a question mark.
  16. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Let me guess, you also think Sandy Hook was a hoax, gay frogs are the next big threat to America, Trump is doing a great job, and Microsoft Edge is the best web browser.

  17. Re: Now we know where the moral compass is pointin by slick7 · · Score: 1

    A moral compass that begs realignment. Is the FBI capable of sustaining a fifth amendment plea? If not, then burn them at the stake.

    --
    The mind conceives, the body achieves, the spirit manifests.
  18. Doesn't this make it trivial by rsilvergun · · Score: 2

    to get these cases dismissed now? I suppose there's lots of folks that can't afford the lawyer needed to file the motions to request the information correctly (two-tiered justice system for the win). But assuming you're not just bullied into a confession you'll be able to use this to get off scot-free...

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
    1. Re:Doesn't this make it trivial by Anonymous Coward · · Score: 0

      Either that or the FBI will be more careful in parallel construction.

    2. Re:Doesn't this make it trivial by Anonymous Coward · · Score: 0

      Seeing how this guy was being served by a public defender, I think it also speaks to the myth that you have to pay a lot to get a decent lawyer. Props to this defense attorney for supporting concepts of freedom and fighting oppression, even if he's being paid by the oppressive system.

    3. Re:Doesn't this make it trivial by Anonymous Coward · · Score: 0

      No. I have never heard of a law enforcement agency disclose an exploit in order to secure a conviction. The value of the exploit in future investigations is much greater than the value of the conviction. They use these exploits in their investigations, and then they hope that those investigations will turn up admissible evidence. They can also use the exploit in parallel construction efforts without disclosing it. If the charges were dropped in this case, it just means that no other evidence was discovered, and it is not worth it to continue the case. Every case is going to be different.

  19. Re:Now we know where the moral compass is pointing by gravewax · · Score: 1

    I think it is more of a case that they realise the information they have access to is far more valuable than prosecuting one pervert and losing that access to prosecute just one is not a good use of that resource, at least I HOPE that is the reasoning.

  20. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    whether he is prosecuted or not he has already been shutdown. While I believe they should make sure he is locked away the lesser evil is to let him go so they can continue to shutdown more of this sick fuckers. I am certain regardless of him going free he will be closely monitored going forward.

  21. Re:Now we know where the moral compass is pointing by ShanghaiBill · · Score: 5, Interesting

    Or letting one more child be raped and murder equals what the fuck exactly?

    There are many myths about "snuff films" that record actual murders, but none have ever been verified. In the most famous case Ruggero Deodato was prosecuted for murder, but was acquitted when the actors and actresses that he had allegedly murdered showed up to testify in his defense. It is hard to imagine how some scenes in his films could have been made without killing someone, but they obviously were, since the people "killed" were still alive and healthy.

  22. Compel by Anonymous Coward · · Score: 0

    Compel disclosure due to unprecedented precedent.

  23. What authority is FBI using to NOT disclose? by Anonymous Coward · · Score: 2, Insightful

    Simply dropping the charges is not enough. The only exception for not divulging method to the courts is National Security. The accused, even if charges dropped, should be able to pursue disclosure of methods. The government should not be able to pick and choose after filing charges unless a valid national security claim.

    1. Re:What authority is FBI using to NOT disclose? by gweihir · · Score: 5, Insightful

      Child abuse, horrible as it is, does not qualify as "National Security". Also, because they did disclose the name of the accused, they should be sued into the ground after dropping the charges. While it is not pretty, civil liberties need to be defended, even if it means defending scumbags. Otherwise they can just destroy anybody in the future by first publicly accusing them and then dropping the charges, possibly without ever providing any evidence or only fake evidence they then withdraw when asked to prove that it is genuine and how they obtained it. Not good at all.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  24. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Let me guess, you also think Sandy Hook was a hoax,

    Guess wrong!

    gay frogs are the next big threat to America,

    Pepe is doing fine.

    Trump is doing a great job,

    When the firings of the globalist fifth-column are done and he's able to do what he was democratically elected to do, we should be able to figure that out.

    and Microsoft Edge is the best web browser.

    Lynx is the best browser motherfucker... Lynx!

  25. Old news by Anonymous Coward · · Score: 0

    This is the second time this has shown up on slashdot. I'd assume the same level of comments.. if not less. Sure this was another example of how detection needed to be masked... but seriously how many of these deviant ass-clowns need to be allowed to skip prosecution before there is another way to present the evidence that allows all of them to be put in the same cage?

    1. Re:Old news by Anonymous Coward · · Score: 0

      This is the second time this has shown up on slashdot. I'd assume the same level of comments.. if not less.

      Uh, what? Did you mean "if not lower" or "if not fewer"?

  26. Re:Now we know where the moral compass is pointing by gweihir · · Score: 3, Insightful

    Or rather locking people up trumps protecting children. That is also why they kept running the site for 13 days. By the very definition of the DoJ, they committed child abuse for 13 days. Seems to me the FBI is part of the problem now.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  27. Re:Now we know where the moral compass is pointing by gweihir · · Score: 4, Insightful

    There is actually some genuine "murder porn" out there: You get to see it on the news, perfectly legally. Think for example, the footage exposed by Manning. It even comes with mocking comments by the murderers while they kill innocent civilians.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  28. Crime? by no-body · · Score: 0

    By knowing about a crime and not pursuing it, does that make you not an accomplice?
    And then this with a federal agency and child porn!

    Some people have very twisted minds.

    (don't tell Donald Rumpelstiltskin, he won't get it and start lying about something else again to avoid the issue ;-)

  29. Force it by Anonymous Coward · · Score: 0

    File Amicus Briefs demanding the exploit be dislosed on the basis of public interest using the jurisdiction of the pending case,.

  30. So, it's okay for the FBI to spread child porn? by Anonymous Coward · · Score: 0

    So, what I'm getting from this is that, if the FBI wants to operate a child porn service, it's perfectly okay if it's under the guise of catching a very small percentage of their users for looking at child porn?

    Sounds fishy to me... or maybe it's just run-of-the-mill American corruption?

    1. Re:So, it's okay for the FBI to spread child porn? by Anonymous Coward · · Score: 0

      So, what I'm getting from this is that, if the FBI wants to operate a child porn service, it's perfectly okay if it's under the guise of catching a very small percentage of their users for looking at child porn?

      Do some Googling, the FBI is the biggest importer of child porn in the US.

  31. It can be anything by Anonymous Coward · · Score: 0

    Did anyone think that it doesn't even have to be a TOR exploit? What if, for example, they target an omnipresent system service, install malware with a unique UUID and wait until a suspect disconnects from TOR to report his real IP? To me it sounds possible and (very) easy enough and everyone likes simple and effective solutions.

    1. Re:It can be anything by sir-gold · · Score: 1

      That's how they did it. They didn't exploit TOR directly, all they did was planting a 'tracking beacon' on the target computer, then wait for the target to reconnect outside of TOR

  32. Re:Now we know where the moral compass is pointing by joe_frisch · · Score: 4, Insightful

    Considering that the argument for why distributing and owning (as opposed to producing) child porn is that the images actively harm children, I do not think there is any way to justify the FBI's behavior. I think its been generally established that law enforcement cannot commit felonies in order to gather evidence. Otherwise we could have police informants carrying out gang hits in order to capture higher level crime bosses. This is not the start of a slippery slope, it is well down the slope.

    They can't have it both ways. If the images don't do actual harm to children, the people who posses the images are only guilty of a minor crime. If the images do harm children, then the FBI should destroy them as soon as they are discovered to prevent continuing harm .

    On the central topic there need to be clear rules about what capabilities we want law enforcement to have. It is probably technologically possible for law enforcement to scan all of the records of the great majority of citizens to look for criminal activity. Is that what we want?

    Personally I would vote to reduce surveillance and accept a higher rate of criminal activity.

  33. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Catching one Trump is enough.

  34. That's one way to spin it by Anonymous Coward · · Score: 0

    Another way is: "Tor use causes FBI to drop child pornography case"

    Meaning, if child porn consumers weren't using Tor this case wouldn't have been dropped.

    Further: what is more important? Winning one child porn case which forces you to reveal your hand, or prosecuting hundreds of others in the future that do not require you to do the same?

    I'm with the FBI on this one. It's a very unfortunate ending, but they chose the lesser evil.

    1. Re:That's one way to spin it by Anonymous Coward · · Score: 0

      THAT FUCKING INTERNET!!!!! Honestly, if the internet wasn't so freely available for criminals to use, the cybercrime rate would drop to zero.

      Lessor evil? When faced with two evils, choose neither. Also, how about winning NO CASE EVER because you make demanding to know how the evidence was obtained (the discovery process being a fundamental tenet of the legal system) a bulletproof way to get your case withdrawn.

    2. Re:That's one way to spin it by Anonymous Coward · · Score: 0

      FYI, a "lessor" is someone who leases or rents out something, e.g. a landlord. Did you perhaps mean "lesser"?

  35. Nothing to do with tor by Anonymous Coward · · Score: 0

    The exploit is probably at the OS level. Thus they don't want the public to know they scanned every machine to find anyone using tor...Backdoor viewed machines and watched them all until they went to site,..oops

    1. Re:Nothing to do with tor by ZeRu · · Score: 1

      Not every OS could be vulnerable. If you use Tor, make a Linux VM for it. Even before the spyware knows as Windows 10 has been released, it has been known that using Tor on any version of Windows isn't the best idea as Tor cannot be more secure than the OS its running on.

      --
      If you post as an AC, don't expect me to spend a mod point on you.
  36. Re: Now we know where the moral compass is pointin by Anonymous Coward · · Score: 0

    The individuals of the FBI are quite capable of claiming fifth amendment protections. That they did so cannot possibly be hidden from the jury. The case probably loses on that basis alone.

  37. Re:Now we know where the moral compass is pointing by Harlequin80 · · Score: 5, Insightful

    This guy was charged with accessing and possession, not creation. If he had been a content creator then prosecution would not have been stopped.

    Lets put this a different way. Would you grant pardon to a person who viewed child porn if it meant you could catch someone who made it? It's the same as offering deals to a street drug dealer to catch their supplier.

  38. FBI Distributes Child Pornography by Anonymous Coward · · Score: 1

    That should be the headline in the media.

    I wonder how much money they made from distributing Child Porn, and if it was as lucrative as when they sold and distributed hacked Conditional Access cards for the DirecTV system?

    Inquiring minds want to know.

    (And also why they are not in prison for the crimes they have admitted to committing?)

  39. ATTN: all defendants by Anonymous Coward · · Score: 0

    I'd hope even Lionel Hutz would be able to pick up on this. Demand disclosure of the "alleged exploit" that the authorities illegally used to ensnare you in one of their tor related busts, and you too can see the charges go away.

  40. Re:Now we know where the moral compass is pointing by gweihir · · Score: 4, Interesting

    Exactly. Freedom always includes the freedom to do wrong and a realistic chance to get away with it (depending on the magnitude of the crime). I believe freedom is of critical importance and the only purpose of law-enforcement is to keep crime at a level that society continues to function reasonably well. They are clearly not doing that, or the banksters would all be in prison now for a long, long time. Nobody on recent memory did this much damage to society and individuals.

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  41. To avoid public scrutiny by Anonymous Coward · · Score: 5, Informative

    https://arstechnica.com/tech-policy/2015/04/fbi-would-rather-prosecutors-drop-cases-than-disclose-stingray-details/ April 7, 2015

    The FBI actually has a policy to drop cases instead of revealing their detection (spying) methods, to avoid public scrutiny of what they're doing.

    The new document, which was released Tuesday by the New York Civil Liberties Union (NYCLU) in response to its March 2015 victory in a lawsuit filed against the Erie County Sheriff’s Office (ECSO) in Northwestern New York, includes this paragraph: "In order to ensure that such wireless collection equipment/technology continues to be available for use by the law enforcement community, the equipment/technology and any information related to its functions, operation and use shall be protected from potential compromise by precluding disclosure of this information to the public in any manner including but not limited to: press releases, in court documents, during judicial hearings, or during other public forums or proceedings."

    That has to do with their 'Stingray' technology, but I'm sure it applies to any kind of digital surveillance.

    Besides, if they didn't drop the case the court would have probably ruled against them, like what happened in a case that slashdot mentioned last year: https://yro.slashdot.org/story/16/07/13/0411255/us-judge-throws-out-cell-phone-stingray-evidence-for-the-first-time

  42. What's going on here? by lewistown · · Score: 1

    If you have something with high discover-ability like a Firefox exploit(high because a couple have already been found, patched, and people are presumably actively looking), why would govt need to hide this evidence? Seems to me that it doesn't matter how they identified and took control of a given hidden service, what should be relevant to the case is the bit of JS sent to the perpetrator's browser that pings the government server revealing the user's real IP.

    What am I missing? Is it that that exploit has somehow gone unnoticed and is so valuable that it can't be released? Is it that using exploits to gain evidence is not admissible? Seems weird to me.

    1. Re:What's going on here? by sir-gold · · Score: 2

      From what I read, the FBI's real problem is that the malware was sent to every visitor to the main login screen, BEFORE they had a chance to log in, and BEFORE any child porn had actually been viewed.

    2. Re:What's going on here? by lewistown · · Score: 1

      Wow, that's quite the screw-up for an operation like this. Thank you for clarifying.

  43. Re:Now we know where the moral compass is pointing by Ramze · · Score: 3, Interesting

    Maybe, maybe not. Having charges dropped doesn't mean they can't file charges again later as long as it wasn't dismissed with prejudice.

    I think either they are currently using this exploit for other active investigations or they used an illegal exploit and don't want to implicate themselves.

    More likely they're still using the exploit and don't want to tip their hand. They could be monitoring another ring, terrorists, etc. If they give up the code, Tor would release a patch, and they'd be done. Stating that they can't offer up the code "at this time" is their key phrasing... as if there's something important riding on this code remaining a useful tool. Or, I could be wrong and they just want to keep using the tool when and where they can and manufacture alternate evidence to point the finger to the bad guys without disclosing the true source of intel.

  44. Re:Now we know where the moral compass is pointing by hairyfeet · · Score: 3, Informative

    Uhh there was one busted in Australia not too long ago who was raping, torturing, and murdering kids on a private darknet PPV. I can't remember the guy's name but they gave the "genre" a name..."hurtcore" because it was as much about causing pain and suffering as it was the rape. The article I read about the case said it was shit that made "A Serbian Film" look tame and it was all real.

    I don't want to search too actively for the terms that would bring up the article for obvious reasons but I did find an article about their web admin being busted where they mention hurtcore.

    --
    ACs don't waste your time replying, your posts are never seen by me.
  45. It would be interesting to see the tipping point by mykepredko · · Score: 5, Interesting

    Where is the point where the crime is so egregious that the FBI is willing to publish the exploit? I presume their keeping the exploit secret because once it's known, it will be fixed and they will no longer be able to monitor the "deep, dark, black, web"?

    What if there was a terrorist attack and the FBI knew about it and sat on it because they thought the expected value of the property and lives lost was less than the value of the exploit and the intelligence received from it?

    Would the FBI (and the US government) be liable for damages because they could have prevented the crime?

  46. Think of the children... by GuB-42 · · Score: 4, Insightful

    It's funny how often child porn is used as a justification for more spying.
    But when actually dealing with child porn goes against more spying, well, fuck children, literally.

  47. I was just wondering... by Anonymous Coward · · Score: 0

    Kiddie porn is a hot button topic, the kind which generates knee jerk reactions and blind outrage. People are so willing to surrender their freedoms in the name of "saving the children." For the record, I'm not, but that's not the point of this post.

    Let's say that "authorities" receive expanded hacking powers, which is certainly the way the current administration and the ones that came before it in the US are leaning. Will those of us who take steps to make it harder for them be branded criminals? Will it be illegal to try blocking unwanted access, even if it's from an "authorized government source?"

    Will those of us running locked down firewalls, aggressive IDS rules, lots of virtualization, encryption, and maybe some proxies be singled out because their Windows 10 or FF 0-days don't work on our systems, or the ones that do only lead into a templated VM that never keeps its state?

    What do I have to hide? Nothing, other than the fact that what I do is my own fucking business and nobody needs to be looking at me without actual cause because they want to make sure I'm not "doing something wrong." I hope this case sets a huge precedent and that the FBI has to dismiss every single case where they gathered data using this method until they actually start to respect the legal system in the country they claim to want to protect.

  48. wat by lucm · · Score: 2

    Don't get your panties in a bunch. The point is not about blaming people, the point is that Tor is not more secure than a typical bank infrastructure.

    --
    lucm, indeed.
  49. Three things by Anonymous Coward · · Score: 0

    This clearly shows three things.

    1. Federal prosecutors have no interest in serving the public good, only their own private agendas.

    2. Federal prosecutors have no interest in protecting the victims of criminal activities. "Think of the children" is a lie and always has been.

    3. Federal prosecutors know that if the FBI's surveillance/hacking techniques come under the scrutiny of the courts that they will be declared illegal and the case dropped anyway for lack of evidence.

    I suspect that federal prosecutors will wait a month and then reopen the case in an attempt to "judge shop" and get someone more interested in listening to the prosecutor's lies and less interested in the defense's inquiries to the questionable surveillance methods of the FBI.

  50. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    > Those child porn rings require content and every time a content producer is exposed, an arrest and rescue should immediately occur, 'IMMEDIATELY', fuck future prosecutions.

    I think there's good cause to let some of the consumers of CP roam free if it means they can bust the people molesting children to produce it.

    Can you explain why you would disagree with that?

  51. Re:Now we know where the moral compass is pointing by ShanghaiBill · · Score: 4, Informative

    Uhh there was one busted in Australia not too long ago who was raping, torturing, and murdering kids on a private darknet PPV.

    Peter Scully. He is accused of murdering one girl, but he didn't film it. The things he did film were horrific, but did not include any killings. So no "snuff film".

  52. Re:It would be interesting to see the tipping poin by LeftCoastThinker · · Score: 1

    "Where is the point where the crime is so egregious that the FBI is willing to publish the exploit? "

    Probably prosecution of a live, thwarted US citizen terrorist that they couldn't deport to Gitmo or rendition and could only deal with in US courts.

    They probably looked at the kiddie porn guy and decided he wasn't a high threat based on a propensity of evidence. It makes sense to save this exploit (which all the CIA/US assets already probably have a workaround for) and keep using it against significant criminals who are attempting to conceal their identities on the web.

    --
    If you disagree, please post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like
  53. Odd by Archfeld · · Score: 4, Interesting

    Should the FBI have the ability to not prosecute in a child porn case ? In California there are several types of cases that failure to pursue result in criminal liabilities for the prosecutor's, among them spousal abuse, child abuse, child porn. It is one thing to lack the evidence or documentation to pursue, or to continue to investigate but to dismiss with jeopardy attached should be a crime in itself.

    --
    errr....umm...*whooosh* *whoosh* Is this thing on ?
  54. Re:It would be interesting to see the tipping poin by Imrik · · Score: 1

    Or rather, does that point even exist? They may feel that it is worthwhile to keep using it to catch as many as they can and just dismiss the cases with competent defense.

  55. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    So they would disclose the vulnerability that allows them to catch more producers in order to prosecute one producer?

  56. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Of course this was done with the idea of disrupting internet distribution as a whole. The same way undercover cops will allow crimes to occur, with the goal of unraveling the larger organization. Even if you disagree with the argument, not even admitting it exists is either being stupid or intellectually dishonest.

  57. Re:It would be interesting to see the tipping poin by TheConway · · Score: 1

    We did it during WW2 and it seemed to work out fine. As soon as we'd broken the enigma code we had the chance to prevent attacks we were learning about but couldn't unless we wanted the Germans to know we'd cracked their code. We let people die so we could save more down the line. A great man once said, "The needs of the many outweigh the needs of the few". I'm willing to assume this is what is happening here.

  58. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    There are many myths about "snuff films" that record actual murders, but none have ever been verified.

    LiveLeak is full of films where somebody is executed, generally quite brutally. There are all of the ISIS films out of the Syrian civil war, several stoning incidents from Iran, Afghanistan and other backwards Arab countries and then there are the Mexican drug cartel killings. You might say that these films have not been "verified", but considering the context and the relatively primitive conditions and backwards people making them, it's unlikely that the killings are elaborate fakes.

  59. Pathetic by Anonymous Coward · · Score: 0

    All these fuckin pedophiles arguing about whats more secure n want to protect there privacy so they can be just that, fucking pedophiles. Kill youself. Childrens lives worth less then peoples internet privacy fucking disgusting. You dont need privacy if your not a fucking pedophile. The internet is also not a "right" its a priviledge.

    1. Re:Pathetic by Anonymous Coward · · Score: 0

      All these fuckin pedophiles arguing about whats more secure n want to protect there privacy so they can be just that, fucking pedophiles. Kill youself. Childrens lives worth less then peoples internet privacy fucking disgusting. You dont need privacy if your not a fucking pedophile. The internet is also not a "right" its a priviledge.

      *** Parse Error ***

  60. Re:Now we know where the moral compass is pointing by No+Longer+an+AC · · Score: 2

    There was this guy too:

    Luka Rocco Magnotta (born Eric Clinton Kirk Newman; July 24, 1982) is a Canadian murderer, convicted of killing and dismembering Lin Jun, a Chinese international student, before mailing Lin Jun's limbs to elementary schools and federal political party offices.[9] This act gained international notoriety. After a video depicting the murder was posted online in May 2012,

  61. Re:Now we know where the moral compass is pointing by Zocalo · · Score: 1

    That was the first thought I had after reading the headline too. I hope everyone keeps that in mind the next time the FBI trots out some variation of the "Won't somebody think of the children..." line to justify some over-reaching surveillance programme they are pushing, because they clearly don't believe it themselves.

    --
    UNIX? They're not even circumcised! Savages!
  62. Re:It would be interesting to see the tipping poin by SethJohnson · · Score: 1

    Many scientists have postulated that there is a bigger truth being hidden here-- the existence of a time machine used by future revolutionaries to undo the Third Reich's tyranical word dictatorship after Germany won World War 2.

    Traveling back in time to "kill Hitler" has become so synonymous with time travel fantasies that it's unlikely future time travelers would actually do it for fear of divulging the existence of their powers and contaminating their preferred timeline. If people in current time knew they were at the mercy of time travelers, they could protect themselves by destroying records and implementing pervasive anonymity (ala technologies like Tor).

    Thus, time travelers prefer to be more discrete and control history through lower profile nudges, like using future quantum computers to brute force the enigma machine and bring back the solution to the chaps at Bletchley Park.

  63. Re:Now we know where the moral compass is pointing by houghi · · Score: 1

    Comer on. This has nothing to do with Trump or any other president. This has to do with how policing worksa. They want to have as high numbers as possible and this is not just for the FBI.

    I live in Belgium and I saw some childporn. I reported it to both the provider and the police.
    After a few weeks, nothing had happened, so I informed a newspaper. That day the childporn was gone. So good, so far,

    Well, that is what I thought. I had done this at work. So suddenly the COO stands at my desk and asks me why the police wants to have my details concerning a chgildporn investigation. I explained it and luckily he was a smart person and understood.
    I then went to the police. They wanted me for distribution of childporn, obstruction of the law and falsification of writing as I had used a free email addres and my info was not correct.

    The reason they left the account open was so they could get more people to watch it and go after more people. They already had the kid who had done it. They already had all that they needed, yet they decided to let the child porn spread more, even though they knew this was just a stupid kid doing a stupid thing.

    Obviously I have never ever seen anything illegal anywhere.

    So yeah, this has absolutely zero to do with politics unfortunately, because that would make it easier to fix. This has to do with catching as much criminals as possible (which is good) and that means the more there are, the better (which is bad).

    --
    Don't fight for your country, if your country does not fight for you.
  64. Re:Now we know where the moral compass is pointing by qbast · · Score: 1

    If every producer can get off the hook just by demanding they disclose the vulnerability, it is not worth anything.

  65. Re:It would be interesting to see the tipping poin by AmiMoJo · · Score: 5, Interesting

    There is another explanation. They might not want to release it because it might not stand up in court. If it gives them the ability to run arbitrary code on the target machine, if they can places files on that machine, the defendant will claim that the FBI planted those images. I'm no expert on US law but it seems like there would be some issue with the evidence being tainted too, and then everything else i s fruit of the poisoned tree.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  66. Re:Now we know where the moral compass is pointing by AmiMoJo · · Score: 4, Interesting

    Even better would be to stop the victimization happening in the first place. The only way to do that, which was suggested in the UK recently and shot down by the majority of reactionary commentators, is to decriminalize viewing such images. Instead focus on helping people who feel attracted to children to get help, discreetly and without threat of prosecution or persecution, to prevent the future crimes they might otherwise commit.

    In the current atmosphere, if someone did feel that way, what are the chances they would go to their doctor and ask for help with a mental illness? No, more likely they will turn to the internet, where there are sites normalizing and justifying their feelings and where the community of fellow paedophiles will accept them.

    The way to protect children is not to catch the offender after they already hurt them, it's to stop them breaking the law in the first place.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  67. Encryption by Anonymous Coward · · Score: 0

    What happened to "think about the children"?

    Pretty sure that this means that we should have no opposition to encryption now, since even the FBI values secrecy over the children.

  68. Case dismissed now sue by Anonymous Coward · · Score: 0

    Now that the have admitted to running an illegal porn site and refusing to disclose evidence in a criminal case, the defendant can sue for malicious prosecution and bring charges against them for conspiracy.

  69. Tor by Anonymous Coward · · Score: 0

    Tor is primarily used by criminals and perverts.

  70. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Lets put this a different way. Would you grant pardon to a person who viewed child porn if it meant you could catch someone who made it? It's the same as offering deals to a street drug dealer to catch their supplier.

    Yes I would. But they're not catching the supplier are they? They're catching the users of a given darknet website that no longer exists due to having been busted.
    Even if they can use the exploit against more CP sites in the future, how does this translate to catching the suppliers? At best they're just going to compromise more sites and *maybe* catch more users. Meanwhile they're alerting all other sites/users/distributors and they're letting criminals escape trial because their methods can't survive scrutiny.

  71. Screw Child Porn by retroworks · · Score: 1, Insightful

    And anyone here defending it. Most of the arguments against the FBI that I see here follow the logic that "if FBI does X to stop a crime, FBI or some other person might do X for bad reason". So no one can own a software exploit, a gun, or a computer, or a sandwich, if it sets a 'precedent' that someone else could posses such an exploit, gun, computer, etc. Seems to me FBI is making a judgement call, how much they can damage the child porn industry through the prosecution and disclosure of method, and how much they can damage it by having people know they aren't immunized by Tor. See header. I'm for giving the FBI that discretion, and if and when it's power is abused, object to THAT, rather than to FBI doing their job correctly.

    --
    Gently reply
  72. Re:It would be interesting to see the tipping poin by johanw · · Score: 1

    There is a well-known historical case where this decision was made: https://en.wikipedia.org/wiki/...

  73. Re: Now we know where the moral compass is pointin by Anonymous Coward · · Score: 0

    https://en.m.wikipedia.org/wiki/Luka_Magnotta

  74. Re:Now we know where the moral compass is pointing by edtice1559 · · Score: 1

    No, the ideal scenario is that the only things that are crimes are those that harm others. And your chances of getting away with those ought to be exactly zero. The goal should be to maximize freedom. The reason that we don't (and shouldn't) target zero crime is that crime prevention techniques that we have infringe on freedoms. It doesn't make sense to use a technique that destroys more freedom than it creates. The world is advancing. At some point we may be able to eliminate more crime with lower cost to freedom in which case we should. I have no idea what a technology that prevented all crime without taking away freedoms from innocent people would look like. But should such a thing be discovered, it ought be deployed. And somebody's "freedom to maybe get away with a crime" should not be a factor in the decision.

  75. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Do tell me more about Trump's child pornography.

  76. Re:It would be interesting to see the tipping poin by dcollins117 · · Score: 1

    A great man once said, "The needs of the many outweigh the needs of the few".

    A prominent Vulcan once said "Logic clearly dictates that the needs of the many outweigh the needs of the few." FTFY.

  77. Re:It would be interesting to see the tipping poin by Anonymous Coward · · Score: 0

    Also, if you go back and kill Hitler then it's likely Hiroshima and Nagasaki were never bombed, and people didn't learn the lesson of using nukes in combat in the 1940s. Russia/USA tensions would be lessened, there'd be no Cold War, and it's debatable how long it would take us to develop a nuke. But world populations would still be analogous to what we have today. There wouldn't be nuclear non-proliferation pacts, and it's possible nukes end up in the hands of more nations. So then a nuclear war does happen (this alternate history's World War II) and the 60 million deaths we know of our WWII start to look paltry compared to the 100+ million wiped out in the first volley of nukes. Even without nukes, and assuming it all scales linearly there would be over 120 million deaths in a WWII that happened today.

    Or maybe the entire planet would be full of peace and there'd be no wars and killing Hitler solves every major problem for the last 70 years.

    Killing Hitler is the wet dream of amateur time travelers, who can't look past their own nose. For all you know, Hitler was planted by the time travelers in order to avert a more heinous history from unfolding.

  78. Good to know by PontifexMaximus · · Score: 0

    Nice to know the children exploited here will continue to be exploited and abused just because the Feds won't release their source code. Dropping those cases means evil bastards go free to continue their abuse of children.

    Nice work FBI. Fucking morons.

    --
    Pax Vobiscum
  79. Re:It would be interesting to see the tipping poin by gnasher719 · · Score: 1

    Traveling back in time to "kill Hitler" has become so synonymous with time travel fantasies that it's unlikely future time travelers would actually do it for fear of divulging the existence of their powers and contaminating their preferred timeline. If people in current time knew they were at the mercy of time travelers, they could protect themselves by destroying records and implementing pervasive anonymity (ala technologies like Tor).

    1933: Time traveller arrives in Germany, kills Hitler.
    1960: German nuclear bomb destroys New York.

    That's actually a logical possibility. The same things might have happened in Germany, but at a slower speed and with less madness at the top.

  80. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    Peter Scully. He is accused of murdering one girl, but he didn't film it. The things he did film were horrific, but did not include any killings. So no "snuff film".

    You are in fact wrong. Scully was indeed charged with murder during the commission of these vile acts and will most likely be executed by the Philippines.

    Per wikipedia:
    "On 20 February 2015, Scully was arrested in his rented house in Malaybalay City after investigators discovered the remains of a teenage girl, Rosie, buried under an apartment he had rented. He allegedly strangled her to death according to police who were led to the apartment by Scully's partner, a 17-year-old Filipino girl, who was also his girlfriend and a prior victim of his abuse."

  81. Re:Now we know where the moral compass is pointing by Jack9 · · Score: 1

    > No, the ideal scenario is that the only things that are crimes are those that harm others

    Since that's impossible (while continuing to have a society) since harm is relative, this sentiment serves no purpose.

    --

    Often wrong but never in doubt.
    I am Jack9.
    Everyone knows me.
  82. The FBI is a RICO conspiracy by Anonymous Coward · · Score: 0

    Start with Teddy Deegan. Follow the thread to James Comey. That fucking organization should be disbanded, and people with integrity put in charge of it, they are little more than the political wing of the current government.

  83. Cue the #PIZZAGATE theories expanding by Anonymous Coward · · Score: 0

    More than a thousand child porn arrests since the elections. Now we see the FBI (same group accused by BOTH sides of being corrupt) throwing out cases rather than reveal how they busted someone. This entire fucking thing stinks. How about we start attacking child porn like we attacked terrorism, communism or anything else we threw all our efforts behind in the last 50 years.

    How can the people that work for us make these decisions and not answer for them?

  84. Sooo by Anonymous Coward · · Score: 0

    Our government operated and distributed Child Pornography online for 13 days
    I thought that was illegal.
    Our government holds multiple 0-day exploits for multiple software platforms and uses them to violate the rights of our citizens
    I thought that was illegal too.

    Im just curious, did Trump make this a reality or was it made possible by the person who spent the last 8 years in office expanding every single Bush-era program that was put in place..

  85. Re:Now we know where the moral compass is pointing by edtice1559 · · Score: 1

    Given that we have a very strong (albeit not perfect) correlation between criminal statue and harm, I'm not sure that I understand this comment. It's not illegal to sleep late on a Sunday. It is illegal to murder the people who live upstairs so that they don't wake you up in the morning. There are some cases where it is very difficult to decide where to draw the line in terms of what should or should not be a crime. In those cases, we typically treat them as civil infractions which isn't a perfect answer but it's at least reasonable. When there is a mismatch between what is criminal and what *should* be criminal, having the activity go underground and not get caught is the worst possible answer. Better to either change the laws or change behavior.

  86. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    I live in Belgium and I saw some childporn. I reported it to both the provider and the police. After a few weeks, nothing had happened, so I informed a newspaper. That day the childporn was gone. So good, so far,
    [...]
    They wanted me for distribution of childporn, obstruction of the law and falsification of writing as I had used a free email addres and my info was not correct.

    Here is the problem. Logic and rational behavior go out the window when someone cries "child porn." You got bent out of shape and pursued your discovery like a bulldog until it was gone, only to be accused and investigated for your trouble. People go totally nuts and lose all sense of proportion or reason. That's how we get teenagers with criminal records for taking nude selfies. The whole point was to protect children from harm, and now we harm children for life (whom we readily claim do not have the capacity to make adult decisions) and lock up people for decades for the crime of looking at a picture.

    And we deride anyone who disagrees with this senselessness as being for child porn.

  87. Re:Now we know where the moral compass is pointing by Anonymous Coward · · Score: 0

    You are in fact wrong. Scully was indeed charged with murder during the commission of these vile acts and will most likely be executed by the Philippines.

    Per wikipedia:
    "On 20 February 2015, Scully was arrested in his rented house in Malaybalay City after investigators discovered the remains of a teenage girl, Rosie, buried under an apartment he had rented. He allegedly strangled her to death according to police who were led to the apartment by Scully's partner, a 17-year-old Filipino girl, who was also his girlfriend and a prior victim of his abuse."

    I don't see anywhere in your quote that mentions that Scully filmed the murder. GP did not say that Scully did not include killings as part of his crimes. GP said that Scully didn't included them in his filmed activities.

    This is a thread about whether snuff films exist, not about whether perpetrators of child sexual abuse are also sometimes murderers.

  88. so for 13 days the fbi admitted by Anonymous Coward · · Score: 0

    they ran an active child pornography ring == charges to follow surely?

  89. Re:Now we know where the moral compass is pointing by Harlequin80 · · Score: 2

    I agree whole heartedly with this. But I think we are a long long way away from that kind of rational discourse.

    I have 2 young kids and so am involved in lots of conversations around safety, paedophiles and murderers from other parents and their compass for risk assessment is so far off it's scary. They genuinely believe that every public toilet has a child molester waiting inside for the chance to grab their kid. The fact that where I live there are almost no cases of strangers attacking children (it's always a family member or close friend), Point out that putting their kids in the car is several orders of magnitude riskier and they will argue it or say that that risk doesn't matter because apparently being killed or seriously maimed is so much less worse than being molested that it doesn't even count.

    While people's mindset is like that even having a constructive conversation is impossible.

  90. different focus by lucm · · Score: 1

    What you describe sounds like the mid 2000s to me, but still. Just for fun, get that MITM running on the banking app of a decent bank, and then try to do many transactions. You'll quickly understand the security features.

    See, this is a side of the industry people don't get. It took the credit card companies almost two decades to start slowly rolling out chips. You know why? Because the odds of a massive fraud versus the cost of implementing those features were not computing in the actuaries spreadsheets.

    Same goes for banking. There's this weakness on the network: the end user. Option 1: you force them to have military-grade security policies and annoy the hell out of them. Option 2: you slowly evolve as a laggard on the security adoption curve and in the meantime you mitigate the risk by making the other end smart enough to spot and terminante major breaches.

    This said, you'll always find banks with idiotic systems in place, but that's not the norm, that's the exception.

    --
    lucm, indeed.
  91. Baby steps by lucm · · Score: 1

    You can stop your bragging now, since it's clear no amount of security can detect or prevent that insider threat.

    You may not be aware of it, but just a few decades ago it was common (legal) practice for banks to openly sell insider information to their clients. It was also perfectly normal for a bank to have no liquidity whatsoever, and to simply go bust if their investments went bad. And not so long ago, it was also common practice for CEO and CFO to report their "expected" revenue as if it was real or to move losses off the balance sheet. Guess what, for all of these things you can go to jail now.

    Are things perfect? Not at all. Just google "Carmen Segarra" to see the extent of the complacency in the federal banking system.

    Things evolve. Not fast, but they do evolve. And this has nothing to do with network security.

    --
    lucm, indeed.
  92. this won't work by Anonymous Coward · · Score: 0

    The Catholic Church relied on the Psychological Industry to reform their bad priests. The psychologists collected three figures per hour and the priests still did their nonsense.

    Psychology = pseudoscience when it comes to this. There is no cure for pedophilia and no treatment that is effective.

    1. Re:this won't work by LienRag · · Score: 1

      The Catholic Church relied on the Psychological Industry to reform their bad priests. The psychologists collected three figures per hour and the priests still did their nonsense.

      Psychology = pseudoscience when it comes to this. There is no cure for pedophilia and no treatment that is effective.

      Behavioral Psychology = pseudoscience when it comes to this. Behavioral Psychology is no cure for pedophilia and not a treatment that is effective.

      FTFY

  93. Re:Now we know where the moral compass is pointing by LienRag · · Score: 1

    I saw the footage, and it"s not mocking comment: it's people who just killed children who then try to rationalize their act.

    And as I wrote on an earlier slashdot post, I certainly consider that the people who decided that it was OK to police a city with missile-armed helicopters (after illegally invading a country) should be brought to an international trial, the soldier who appear on the video just did their job (they did ONE mistake - I mean apart than enlisting in the US Army to wage an illegal war - indeed, but a mistake that many psychological studies established people will routinely make).
    "Just doing their job" is not a valid excuse for killing children, I concur, but they should not be portrayed as monsters (apart, again, for accepting to police a city with missiles in a country they invaded illegally).

  94. Re:It would be interesting to see the tipping poin by david_thornley · · Score: 1

    Actually, it appears that Coventry was not such a case. Read your link.

    There was a case in WWI where the British deliberately didn't warn a French cruiser about a U-boat. The French later asked if the decision would have been the same if it had been a British cruiser.

    The coverup was not completely successful. Doenitz, the overall U-boat commander and later head of the Navy, thought their Enigma messages were being read somehow, but his technical people said that was impossible (IIRC, that's in Clay Blair's book on the U-boat war).

    --
    "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  95. Core switches are such a mystery by lucm · · Score: 1

    I don't think you know what a switch does.

    Maybe the problem is worse than that! Maybe Cisco themselves don't know what a switch does, since they offer an IDS module for their flagship core switch:

    http://www.cisco.com/en/US/pro...

    And this seems like a serious problem in the networking industry. Apparently Alcatel-Lucent doesn't know either, since there's a built-in IDS in their core switch.

    http://enterprise.alcatel-luce...

    And - OMG - even HP is completely confused about this technology, since they also have IDS on their core switch.

    Or maybe, just maybe, you vastly overestimate your understanding of enterprise networking.

    --
    lucm, indeed.