Friday, August 10, 2012

In Paypal DDOS case, government reprimanded for failure to analyze and return data in a timely fashion

If you recall, I wrote earlier about the E.D.N.Y holding that the government's failure to examine data after 15-months was a seizure under the Fourth Amendment - see: Federal court holds that 15-month delay in reviewing electronic evidence was an unlawful seizure. Well, it appears the government continues to have issues in this regard.

In United States v. Collins, 2012 U.S. Dist. LEXIS 111583 (N.D. Cal. Aug. 8, 2012), the government's motion to reconsider an order to return evidence was denied. The evidence was data that "fell outside the scope of the 27 warrants by which over 100 of the defendants'computers and other digital devices (including storage media) were seized."

The defendant, Collins, is part of a large group of people that were rounded up last year after the DDOS attack on Paypal. The attack was allegedly perpetrated by Anonymous, and used the Low Orbit Ion Cannon to achieve its goal. You can see the DOJ announcement, here: Prosecution of Internet Hacktivist Group "Anonymous," and some of the proceedings of the case, here (including a description of what allegedly occurred, and the criminal charges).

The facts are somewhat similar to Metter (the case my article above is on), in that in an extraordinary amount of time the government failed to deal with seized data. In the courts words:
almost a year and a half after presenting the warrants, the government has yet to take any meaningful steps to isolate non-targeted from targeted data
The government's arguments for reconsideration of the order on March 16, 2012 (nearly 5 months ago, and many months after the original seizure) are that:
(1) identifying non-targeted data might be difficult; (2) certain non-targeted data might be useful in understanding data that is clearly targeted; and (3) disaggregating non-targeted from targeted data might be unduly burdensome and expensive; (4) allowing only the defendants to keep a complete copy of the seized data might deprive the government the ability to challenge exculpatory non-targeted data and thus would be unfair.
The court was unconvinced by the governments justifications, and essentially chided the government for arguing a position that would essentially allow them to keep data they were not authorized to seize (possibly indefinitely) and which would nullify the government's pledge in search warrants to return such data. In the courts words:
If separating non-targeted data from targeted data and devices lawfully retained as criminal instrumentalities is too hard here, it presumably is too hard everywhere. In what case where a storage device is seized lawfully could a defendant or other subject of a search warrant ever secure return of data that the government had no right to take? Just about every storage device can be searched more easily with automated scripts than manually. Just about every storage device has non-targeted data that might prove useful to understanding the data that was targeted. Just about every storage device has deleted files in unallocated space. If the government's argument were accepted here, so that it need not return even one bit of data that is clearly outside the scope of the warrant, the court thus would render a nullity the government's pledge in just about every search warrant application it files in this district that it will return data that it simply has no right to seize. 
To me, it's hard not to wonder if there is a systemic problem going on with how the government is handling cybercrime cases and the plethora of evidence that they tend to produce - according to this transcript, there were at least 9 terabytes of data that had to be analyzed.  That is certainly a lot of data, but as the court in Metter stated, there has to be a line drawn somewhere when retention of data transforms from investigatory to a violation of the Fourth Amendment.

Illinois Supreme Court classifies images of minor during legal, sexual activity to be child pornography, dissent applies Stevens

In People v. Hollins, Docket No. 112754 (Ill. 2012), the Illinois Supreme Court held that images taken of a 17-year-old during sexual activity were to be classified as child pornography. A dissenting opinion argued that the Supreme Court's decision in Stevens requires otherwise as the sexual activity was legal under Illinois law.

The defendant, a 32-year-old man, was convicted of violating the Illinois child pornography statute after taking photographs of his 17-year-old girlfriend while the two were engaged in sexual activity. The girlfriend's mother found the images and reported them to police.

On appeal, the defendant argued that because the age of consent for sexual activity in Illinois is 17, the child pornography statute extending until the child turns 18 does not protect children such as his girlfriend from sexual exploitation or abuse. The court, however, found held:
[T]here are rational, reasonable arguments in support of having a higher age threshold for appearance in pornography than for consent to sexual activity. The consequences of sexual activity are concrete, and for the most part, readily apparent to teenagers.... The dangers of appearing in pornographic photographs or videos are not as readily apparent and can be much more subtle.
The defendant also argued that the statute violates due process because it does not provide fair notice of this "illogical inconsistency." The court, however, held that "ignorance of the law is no defense," and regardless, the defendant is a convicted sex offender and "has prior experience with the legal system and sex offenses in particular."

Another argument presented was that the law violates equal protection as it prohibits "the sex partners of such people from photographing such otherwise lawful, private, sexual activity." Again, the court found that only a rational basis is required and that one exists here.

In a dissent, Justice Burke wrote that the Supreme Court's 2010 decision in United States v. Stevens (click here for a casenote on Stevens) held "that there is no first amendment exception for child pornography, per se." Stevens found unconstitutional a statute banning the creation of depictions of cruelty to animals, primarily targeting "crush videos."

Thus, applying Stevens, Burke argued that because the defendant's sexual conduct was legal, the photographs should be deemed legal as well and not classified as child pornography.

Thursday, August 9, 2012

New nation-state malware named Gauss discovered

Kaspersky has put out a report on what I would refer to as a "child analogue" of the Stuxnet, Duqu, and Flame malware, dubbed "Gauss." For a condensed synopsis of the report, head here: Gauss: Nation-state cyber-surveillance meets banking Trojan. The trojan attempts to gather as much information from the computer as possible, and also attempts to steal banking credentials (which is a relatively unique feature of the malware). Gauss is most prevalent, so far, in Lebanon, and its financial credential thievery appears to be targeted at specific Lebanese banks. It has also been found in Israel and Palestine, but is surprisingly absent from Iran. Per the Kaspersky report:
Gauss is designed to collect information and send the data collected to its command-and-control servers. Information is collected using various modules, each of which has its own unique functionality:
► Injecting its own modules into different browsers in order to intercept user sessions and steal passwords, cookies and browser history.
► Collecting information about the computer’s network connections.
► Collecting information about processes and folders.
► Collecting information about BIOS, CMOS RAM.
► Collecting information about local, network and removable drives.
► Infecting USB drives with a spy module in order to steal information from other computers.
► Installing the custom Palida Narrow font (purpose unknown).
► Ensuring the entire toolkit’s loading and operation.
► Interacting with the command and control server, sending the information collected to it, downloading additional modules.
I find it very interesting that a nation-state sponsored piece of malware would exfiltrate financial data, simply for the reason that it would be impossible to limit the scope of the malware to only target malicious actors (or whomever the malware was actually intended for). Then again, everything else the trojan does is criminal under US (and most international) law (data exfiltration, unauthorized access, etc.), so tacking on international banking fraud probably doesn't matter at this point.

Georgia court applies good faith to warrantless GPS use based on 1981 beeper case

A few months ago, I mentioned that an Alabama federal district court denied the suppression of GPS evidence because a 1981 circuit ruling allowed "the warrantless installation of an electronic tracking device ... to the exterior of a vehicle parked in a public place ... where the agents possess reasonable suspicion." United States v. Michael, 645 F.2d 252, 256-59 (5th Cir. 1981) (en banc). A Mississippi court refused to uphold the use of GPS under the same case.

In United States v. Nelson, 2012 U.S. Dist. LEXIS 103944 (S.D. Ga. 2012), a Georgia magistrate denied a motion to suppress after applying Michael and the Davis good faith rule. The GPS device had been placed on the defendant's vehicle on January 14, 2012 - just weeks before the Supreme Court's decision in United States v. Jones. The court held:
The record in this case establishes that when Agent Klarer installed the GPS device on Nelson’s vehicle he relied upon established FBI policy that conformed with binding Eleventh Circuit precedent. Even assuming that reasonable suspicion was a necessary predicate for the warrantless installation of the device, (and it is not clear that even reasonable suspicion was required under then-existing Eleventh Circuit precedent), Nelson did not dispute the government’s assertion at the hearing that the agents reasonably believed that Nelson was involved in the kidnappings at the time they placed the tracker on his vehicle. In any event, the Court finds that the agents had developed sufficient information to furnish reasonable suspicion that Nelson was involved in the kidnappings: he had ties to Marshlick (having dated Marshlick’s wife’s niece), he was the first person Downs encountered after his release by the kidnappers, he knew details about the Downs kidnapping that Downs had not revealed to him during their brief encounter, and he was a suspect in numerous other crimes (including the assault of his former girlfriend and the torching of her mother’s home). Because Agent Klarer acted in compliance with binding appellate precedent when he attached the GPS locator to Nelson’s vehicle, the exclusionary rule has no application in this case.
Michael was decided prior to the modern day Eleventh Circuit's creation, making it binding authority on today's Fifth and Eleventh Circuits.

Wednesday, August 8, 2012

Cybercrime Review to conduct webinar on encryption technology and legal issues

Two weeks from today, Justin and I will conduct the first of what we hope to be many webinars on cybercrime related topics. In our initial presentation, Justin will cover encryption technology and software as well as forensics issues, and I will address the relevant case law on forced disclosure of passwords for encrypted files.

Date: Wednesday, August 22
Time: 1:00-1:30 Eastern

Click here to register. The webinar will be approximately thirty minutes in length, and we will stick around afterward for any questions you may have. Feel free to share this information as this webinar is open to anyone with an interest in the subject. CLE credit is not available for this webinar.

Tuesday, August 7, 2012

Carnegie Mellon study on Silk Road

You may recall that in May I wrote a post about what Bitcoins could buy you in the criminal underground, appropriately titled "What Bitcoins can buy you in the criminal underground."

In that post I mention Silk Road - a site that is pretty much an illicit drug bazaar. To follow up on that, I'd like to draw attention to a new study that has come out, authored by Nicolas Christin, which details the revenue made by the site, and other usage statistics - including a very high satisfaction rate with the transactions.

The study can be found here:

Traveling the Silk Road: A measurement analysis of a large anonymous online marketplace

H/T to Forbes: Black Market Drug Site 'Silk Road' Booming: $22 Million In Annual Sales

Hacking victim details how he lost his email account and everything on his computer

Be sure to read "How Apple and Amazon Security Flaws Led to My Epic Hacking" from Wired writer Mat Honan detailing how hackers were able to delete his entire Google Account, take over his Twitter account, and remotely erase his iPhone, iPad, and MacBook. It's important to read the whole thing - on the last page, he explains why you should not enable the Find my Mac feature in iCloud.

It's enough to scare any sensible person into seeking ways to better protect themselves online. Several websites have made suggestions for doing so including this one from Lifehacker.

One important step is to enable two-factor authentication in both your Google Account and Facebook. Enabling this will require you to enter a code sent to your phone via text message before you can access these accounts on an unfamiliar computer. Thus, even if a hacker is able to change your Gmail account's password, they still won't be able to access it without obtaining the code sent to your phone. There is a special procedure for authenticating on certain types of devices so be sure to follow the directions carefully.

Apple responded, "Apple takes customer privacy seriously and requires multiple forms of verification before resetting an Apple ID password, in this particular case, the customer’s data was compromised by a person who had acquired personal information about the customer. In addition, we found that our own internal policies were not followed completely. We are reviewing all of our processes for resetting account passwords to ensure our customers’ data is protected."

Fifth Circuit affirms illegal gambling convictions for use of sweepstakes software

In United States v. Davis, 2012 U.S. App. LEXIS 15875 (5th Cir. 2012), the Fifth Circuit affirmed the defendants' convictions for illegal gambling after they used computer software to allow users to participate in a sweepstakes in violation of federal and Texas law.

The defendants were charged with conducting an illegal gambling business under 18 U.S.C. § 1955 for their actions in a sweepstakes promotion at three Texas Internet cafés. Under the statute, the act must "violate[] the law of the state in which it is conducted." The relevant issue was whether the defendants operated an "electronic gambling device" in violation of Texas law. If participants paid consideration for the privilege of playing, it would be considered such a device.

Software running on computers at the Internet cafés allowed users to participate in the sweepstakes in three ways: (1) purchasing Internet time - $1 = 100 entries, (2) requesting entries in person, up to 100 per day, or (3) requesting entries by mail, up to 100 per day. Winning entries were predetermined, and participants could discover whether they won by asking an employee, swiping their card, or playing games on the computers.

Thus, the defendants argued that since entries were received without purchase or free with the purchase of Internet time, there was no consideration. The Fifth Circuit, however, held:
[T]he consideration element in the Texas gambling statutes can be fulfilled without an explicit exchange of money for the opportunity to participate in a sweepstakes.... Here, as in Jester, there is legally sufficient evidence from which a reasonable fact-finder could infer that the sale of Internet time at the defendants’ cafés was an attempt to legitimize an illegal lottery.
The court also struck down an argument that the defendants were entitled to a mistake of law defense. The defendants argued they had read opinions from the Texas Attorney General prior to the sweepstakes which supported their plan. Because the federal statute criminalizes what is illegal under state law, a defense should be available based on mistake of state law. The Fifth Circuit, however, found that the defendants did not "reasonably rely on any 'official statements'" because more recent opinions would have shown the act was illegal.

Therefore, the convictions for illegal gambling and conspiracy to commit illegal gambling were affirmed (though a money laundering conviction was reversed).

Monday, August 6, 2012

Cybercrime Review launches site redesign

For those of you not reading via RSS feed, you probably noticed that we launched a new layout over the weekend. We'd love to hear your thoughts - either in the comments or by e-mail.

It's hard to believe that Cybercrime Review began ten months ago. Over 300 posts later, we're still going strong. Thank you for your readership, tips, and arguments along the way!

District Court denies motion to suppress cell site data

In United States v. Madison, 2012 U.S. Dist. LEXIS 105527 (S.D. Fla. 2012), the district court denied a motion to suppress cell site location information as the application contained facts asserting that the defendant was an associate of - and lived near - a known participant.

A 2703(d) order was obtained to get historical cell site records for the defendant after a shooting and other related crimes. To prove specific and articulable facts, law enforcement presented facts concerning the gunman they caught near the scene. They connected the defendant to the gunman with the following facts:
m. Sources have identified Bobby Ricky Madison as a person possibly involved in the armored car robbery that occurred on October 1, 2010. Madison is also a known associate of Moss and Moss's other associates. From document[s] regarding a prior arrest of Madison, the FBI has learned that Madison uses a cellular telephone assigned the number 754-234-7001. 
n. Madison lives in the Opa Locka area near where Moss resides. In May 2010, officers in the same Coconut Creek area from which the two stolen vehicles used in the October 1, 2010, robbery were stolen attempted to perform a traffic stop of a vehicle Madison was driving. He lead the officers on a high-speed car chase before eventually being apprehended. The car he was driving was reported stolen from that same Coconut Creek area at approximately the same time of day as the two vehicles used in the October 1, 2010, robbery.
Thus, the "specific and articulable facts" were that the defendant was a known associate and lived in the area (approximately eight miles away).

The court agreed that the application was sufficient. It presented facts surrounding the armed robbery, the defendant's ties to another participant, and his "skill set and modus operandi for stealing cars." Further, it alleged that at least three others were involved in the act, though only one had been found. As it was reasonable to believe the defendant's cell site data would be relevant and material to the investigation, the 2703(d) order was proper.

Sunday, August 5, 2012

Craigslist wins $233K in case against optimization site

In Craigslist, Inc. v. Kerbel, 2012 U.S. Dist. LEXIS 108573 (N.D. Cal. Aug. 2, 2012), the Northern District of California granted default judgment for Craigslist against www.craigslist-poster.com for violations of the CFAA, Lanham Act, California hacking statute, California fraud statute, and DMCA. Kerbel and his website exploited the CAPTCHA function of craigslist, and sold credits for "campaigns" that would blast out posting all over the country ("24/7"), circumventing the Terms of Use specified by Craigslist. As the court described it, the "[d]efendant's activities burden craigslist's systems and cause it to incur expenses to increase server capacity, provide additional customer service and support for its legitimate customers, and investigate and enforce its policies." The defendant also used trademarks of Craigslist without authorization.

With regard to the CFAA claims, the court stated:
Plaintiff alleges that Kerbel's conduct was both knowing and intentional because it was designed to circumvent craigslist's security features and Defendant had to agree to the TOU with no intention of complying with it. Kerbel also continued said conduct despite receiving cease and desist letters. His conduct caused harm to craigslist of over $5,000 per year, including increased costs associated with the burden on Plaintiff's servers, investigation and enforcement costs to maintain the legitimacy of posts to the site, loss of goodwill, and the need for increased customer service and support. Thus, the Court finds Plaintiff is entitled to default judgment on its CFAA claims.
Kerbel was also dinged for violations of California's hacking statute - California Penal Code §§ 502(c)(1)-(7).  Additionally, he was hit for statutory damages under the DMCA equaling 200K, which was at the low end of the spectrum. The high end, according to the court, would have been 1.7 million dollars. Keep in mind that the owner of the site made only 33 thousand dollars. That amount was tacked on to the judgment for trademark infringement, making the total judgment ~$233,000.

If nothing else, this reinforces the binding force of TOU on websites.

Thursday, August 2, 2012

Analysis of cybercrime cost estimates

ProPublica recently analyzed the often cited estimate of the cost of cybercrime to be around $1 trillion. The director of the National Security Agency recently referred to this amount as "our future disappearing in front of us."

Click here for the story.