French Officer Caught Selling Access To State Surveillance System On the Darkweb (zdnet.com)
An anonymous reader writes: "A French police officer has been charged and arrested last week for selling confidential data on the dark web in exchange for Bitcoin," reports ZDNet. French authorities caught him after they took down the "Black Hand" dark web marketplace. Sifting through the marketplace data, they found French police documents sold on the site. All the documents had unique identifiers, which they used to track down the French police officer who was selling the data under the name of Haurus.
Besides selling access to official docs, they also found he ran a service to track the location of mobile devices based on a supplied phone number. He advertised the system as a way to track spouses or members of competing criminal gangs. Investigators believe Haurus was using the French police resources designed with the intention to track criminals for this service. He also advertised a service that told buyers if they were tracked by French police and what information officers had on them.
Besides selling access to official docs, they also found he ran a service to track the location of mobile devices based on a supplied phone number. He advertised the system as a way to track spouses or members of competing criminal gangs. Investigators believe Haurus was using the French police resources designed with the intention to track criminals for this service. He also advertised a service that told buyers if they were tracked by French police and what information officers had on them.
the next guy will be smarter and not too worried about the risk/reward balance.
My complete surprise. NEVER saw this one coming.
Let's see. About 10 million Slashdot posters have been predicting this.
for these kinds of crimes... you have to give credit to a China-like approach: swift bullet to the head to deter all future people in power who might be tempted.
Breakdown of trust in the government strikes at the heart of society. Some things you can't be tolerant of.
You are an idiot. How shall I approach? Two wrongs dont make a right? That is likely your level. 3rd grade reading comprehension level.
Everyone else can figure out on their own the adult reasons you are a clown.
He advertised the system as a way to track spouses.
Ah oui, but we are French! We love freely and let our spouses roam, but we will not accept corruption in our peace officers. Away with you. Monsieur!
But governments can be trusted with built-in encryption backdoors. Hmm.
This is the future.
Criminals can be made, and busted by the same service.
It seems like the perfect use.
Truth isn't Truth - Guliani
This is why we can't abide backdoors. Their existence presumes that all government and law-enforcement members are trustworthy people.
They are not. And people like this guy will abuse backdoors for his own profit.
They save Torture for people they Really don't like.
Fuck.
Truth isn't Truth - Guliani
He was only charged and arrested for, effectively, embezzlement. He was making money from selling state surveillance data without sharing the profits, thus criminally depriving his organization from their own take of the criminal proceeds.
No one, nor their immediate families, of that surveillance system should be allowed to continue existing.
is what happends with backdoors and survailanve..
Here's where the "government only" backdoors to your industry's R&D end up. Doesn't even take North Korea to kidnap spouse and kids of the ones you entrust with sensitive access, all it takes is fucking money!
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Go home, David Brock. You've had too much to drink again.
to hide.
So be sure to vote for politicians who will pass laws to give state access to every aspect of your digital life.
And if a policeman passes your location on to your ex partner who has raped and beaten you, it is your fault for having had something to hide.
Quattuor res in hoc mundo sanctae sunt: libri, liberi, libertas et liberalitas.
Christopher, my love, I recognized you my sweet love because you often talk to me about David Brock :)
Never mind those "hump leg" trolls.
I am deeply sorry. I didn't feel well lately but I am better now since I had my meds adjusted. I am sorry that I called you all sorts of names on Slashdot and I feel truly ashamed of myself but somebody keeps re-posting my nasty post.
The python click script you wrote for me my sweet love for my pheromone revenue stream web site suddenly stopped to work.
Could you come visit me in my studio so we could look at it?
Signed:
Ethell, Your sweetee who will love you for ever.
P.S. when I posted there was a funny form that asked me to retype the word "shoulders" in a text field. That's funny, I did a double-take and I went to look at your new picture again and got turned on. Please contact me ASAP.
They say decade after decade. We need encryption backdoors and such they have said. It will be 100% super, military grade super save. They have said, NOT :-/ !!!
Sounds like the documents contained unique identifiers in anticipation of this sort of thing. I wonder if there would be a way to embed invisible identifiers in docs in fonts, line spacing, punctuation, hyphenation etc. that could withstand modification to a greater or lesser degree.
No, that's not what was going on.
10 million Slashdot posters were busy advertising how they were going to pile on to the issue with a big "said so" at the first sign of human fallibility (as infallibly projected), despite the original prediction having a zero value add.
In the he-said/she-said fiasco now playing out on the national American stage, you can pretty much bet that the loudest voices in the camp of "well, if the accusers aren't perfect in every way, if there is ever any abuse at all, then we shouldn't listen hardly at all" are the ones with the haziest, alcohol-infused recollections of their own youthful misdeeds.
Systems theory has a name for loud voices demanding perfection concerning non-traditional door #2, while tolerating rampant imperfection in traditional door #1.
You see, the only reason you'd ever improve a working system (flawed though it might be, as we all know from long experience) is if the replacement system achieves outright perfection. And I can personally predict, right now, that the replacement system will have failure mode X, and when that day comes, 10 million voices will join in unison to proclaim that 10 million voices having collectively predicted the inevitable surely can't be wrong.
That's the not terribly charitable view.
The slightly more charitable view is that this is an exercise in proof by induction, basis step only.
You see, it happened once, and by the lemma stating that every bad that can happen does happen, QED. Because if it happened once, it can surely happen again.
You see, in human systems, that's how induction properly works.
The answer most be to add more rules and regulations, to do this we must increase the size of the government and in turn taxes.
Because he is a suspect. Suspect's names are never released.
While I believe that police and intelligence agencies certainly should be paying attention to our digital interactions and activities, I believe it needs to be more selective and carefully targeted than is usually the case. In IT security one fundamental principle is the least amount of access needed to do a job. The police surveillance equivalent would be only looking at a persons traffic after a warrant has been issued. But what seems to be done instead is getting the most sweeping powers they can get away with at the time legislation is passed, then pushing slightly beyond that limit on the down low afterwards. (see parallel construction)
An analogy that might be helpful is looking in trash bags. In many places, looking in your trash does not require a warrant because it is considered to be placed into the public domain. So, in theory, a police dept could set up an inspection station at the dump and household waste transfer stations looking at everyone's trash. From there, if anything of interest is found, they would then start to backtrack that item through the collection network to identify the house it came from. The biggest reason they don't do this I think is because the expense in capital equipment and manpower is just too high for the number of clues they would get. So for trash, our privacy is respected by the logistical concerns.
However, in digital surveillance, the equipment to do the searching is already there and paid for by the ISPs. There is far less manpower required, but what there is of it is split between the ISP and the police. All a cop needs to do is send a letter to the ISP, demanding logging of all traffic with a certain signature (IP address, web protocol, key words or destinations etc). One of their admins fires up his management console and starts the logging process. The difference in cost between tracking one individual of interest and tracking an entire community is trivial compared the the scaling costs of real world surveillance.
If we want the same level of privacy and protection from unreasonable search and seizure, we need to find a way (possibly a multi-prong approach) to make it hard for authorities to cast wide nets without a damn good reason. My suggestions are:
1) All interception done at the behest of law enforcement should require a warrant, not simply a letter.
2) All interception done at the behest of the intelligence community should require the approval of elected officials on a case by case basis.
3) regardless of who requests the surveillance, the ISP's should be paid a reasonable amount for their services.
4) All warrants and National Security Letters must be required to state the expiration date and any other limiting factors.
5) Authorities must be held accountable when cases of over-reach, misuse or abuse are identified. The penalties must be meaningful. Someone, possibly several someones have to lose their job, it has to be possible to put someone in jail if the abuse was severe enough. Corporations must be fined heavily enough to affect the bottom line.
6) It has to be possible for an ISP to refuse a request if they have reason to believe the request fails to meet the legal criteria. When that happens, they will record the requested data, but not hand it over to the police until the matter can be reviewed by a judge or impartial panel. Requiring people to cooperate even when police are in the wrong supports the authority of the legal system, but also gives people the classic "I was only following orders" excuse for participating in a crime.
I need a wheelchair van for my son. Help me get the word out. https://www.gofundme.com/wheelchair-van-for-jj
what does it matter? Republicans have been raping women since high school. It's the way they be.