Friday, June 29, 2012

Study details teenager habits on the Internet

McAfee recently released a study concerning the activities of teenagers online, entitled "The Digital Divide: How the Online Behavior of Teens is Getting Past Parents." The study details what teenagers do online including the illegal activities they participate in, what parents know, and how teenagers work to prevent their parents from learning of their bad deeds.


Here are a few interesting results:
  • 70% of teens admit to hiding their online activities from their parents
  • Over 50% of teens have hacked someone's social networking account
  • 32% have accessed pornography online
    • 43% of those access pornography on a weekly basis

Wednesday, June 27, 2012

FBI arrests 24 in international carding scheme

Graphic courtesy of FBI
The FBI announced yesterday 24 arrests in 8 countries for involvement in a carding scheme. They estimate that 400,000 potential victims and potential loss of $205 million were involved. Read more here.


Quick update: TCNiSO cable modem hacker DerEngel's vagueness motion dismissed

DerEngel (Ryan Harris) of TCNiSO, who became famous for hacking cable modems and writing a book on the subject,  has lost a motion to dismiss his case on the grounds that the federal wire fraud statute is unconstitutionally vague. His motion was originally filed prior to his jury trial, but was ruled premature, so subsequent to his conviction on seven of eight counts of wire fraud, he renewed the motion. For reference, the original indictment can be seen, here. He also has a motion for judgment not withstanding the verdict currently before the court, but I find it highly unlikely that a judge will nullify a jury verdict based on the clear cut explanation handed down yesterday in the order denying his vagueness motion.

Harris put forth an interesting argument for vagueness, but a quick reading shows its shakiness:
he asserts that if the wire fraud statute can be applied to punish his sale of cable modem hacking products, then it can also be applied to make criminal the conduct of other companies that create products which are readily susceptible to illegal use and known to be used unlawfully by many of their users. . . . Citing tort cases, the defendant asserts, in effect, that because the manufacturer of a product that is put to a harmful or illegal use is not ordinarily civilly liable for the consequences of that use, sellers of products are not on notice of any potential for criminal liability arising from a third party's use of a product. 
In essence, the argument is irrelevant. The wire fraud statute is intentionally vague, to cover a multitude of such schemes - the focus being on the intent to defraud. It is hard to argue that he did not know that selling his products would result in a loss to ISPs, and I find it even harder to believe that he could remotely argue other legitimate uses.

The court ruled along the same lines, stating that the statute has a broad scope for a reason, and that it has been previously held to cover many different situations, including stealing telephone and satellite service - and this factual scenario is not an analogical leap - it's less than a baby step. Therefore, the court concluded that "in convicting the defendant, the jury had to find that the defendant acted deliberately, with intent to defraud the internet service providers, and knew that his scheme was unlawful - findings that were amply supported by the evidence. These requirements provide further support for the conclusion that the wire fraud statute is not unconstitutionally vague as applied in this case."

An attempt to make the case for "hacking back"

Justin's recent post, "The illegality of striking back against hackers," presents a number of interesting issues with regard to organizations hacking in retaliation against those who hack them first. It is only fair that such an act should be allowed in light of the current state of our legal system. But as Justin correctly states, allowing retaliation is not a clear-cut issue and should not be considered lightly.

Hacking cases are complex. Beyond the cases where hackers go to the Internet to boast about their actions, it can be very difficult for law enforcement and prosecutors to track down the perpetrators. Facing a lack of resources, cybercrime investigators tend to focus their attention on issues such as child pornography. Hacking cases and the identity (or other) thefts that follow present great hurdles for millions of Americans each year.

Of course, there is a remedy for consumers - file a lawsuit. After LinkedIn's recent security breach, many quickly jumped at the chance to file. LinkedIn committed a grave error, and attention needed to be brought to the issue so they'll fix the problem and other companies will be warned as well. No amount of investment in security, however, will make a system perfect and neither will it make a company immune from lawsuits and damage to their reputation when breaches occur.

Likewise, there is also a solution for the hacking victim - file a lawsuit. The CFAA allows a civil suit to be brought for certain damages, but it carries with it a multitude of problems. Often, the hacker could only be found by an investigation that would, in turn, violate the CFAA (see Justin's point number 2). They may be located in another country. They may not have any money, and even if they do, there may be no legal process for getting to it. For these reasons (and many others), companies like LinkedIn are often required to take the beating from the press and users, spend a lot of money beefing up security, and keep their fingers crossed.

Until law enforcement and prosecutors make these cases more of a priority, American organizations (and therefore, consumers) will be left without a true means of protecting themselves. But suppose we modified the CFAA to allow a self defense-type approach. In some ways, being hacked is like being punched in the face. If you retaliate in either situation, it's possible that others will come in defense of the attacker (imagine a bar fight where all of your friends are already outside, and you're now facing five guys twice your size). Similarly, if you were in a crowd and weren't sure who the punch came from, you can't just start hitting everyone to get back at the true puncher. However, if you can find them and timely respond, you may be able to defend yourself from further harm.

There are a few ways in which such a modification would be helpful:
  1. Investigation - Allowing victims to hack back would allow them to collect the information that would be essential to any civil or criminal case - information like the IP address of the hacker.
  2. Security Improvement - Patching security issues is much easier if you know how the infiltration happened. Further, knowing what resources hackers are using would allow technology security teams to better plug the holes in their networks. Perhaps the statute could require mandatory reporting so that the government could collect data in an effort to study developing patterns in the hacking world.
  3. "Cathartic Chest Pounding" (Justin's words) - Billion dollar corporations have at least one thing that common hackers don't - a billion dollars. Not every business has the ability to dedicate essentially unlimited resources to protecting themselves, but these do. Hacking back may result in more attacks at first, but the right successes might turn hackers away. (The problem here, of course, is that if large companies make themselves essentially hack-proof, the market for unauthorized data will result in attacks on small business that have no such resources.)
Obviously, there's no easy solution to this problem, but rest assured - the CFAA is not likely to hinder everyone. Now we have the waiting game to see how prosecutors, Congress, and corporations will respond.

Tuesday, June 26, 2012

The illegality of striking back against hackers

It has been an emerging trend in recent security publications to highlight the interesting trend of companies "hacking back" against infiltrators and potential data exfiltrators. The concept sounds intriguing - if the internet is the wild wild west, then what better way to participate in it than to allow the tumbleweeds to shift in the wind as you and your foe see who can draw first, or, more accurately, get the last shot. However, the Computer Fraud and Abuse Act provides no escape hatch for such actions; there is no Castle Doctrine in federal statutes relating to hacking, and no such doctrine in state cybercrime laws, either. Any such activities are ill-advised, likely illegal, and do nothing but encourage the escalation of cybercrime.

It's certainly clear that this is a response to the plethora of attacks that have happened recently, but I think more tellingly, resonates from the clear embarrassment that permeates any large company's mea culpa when they admit a breach has occurred. In the article above, it notes that firms have popped up that are for-hire counter-strikers. While the notion fulfills the age-old revenge story meme, and could even make hackers think twice about striking your company (if they knew you would take such measures), the legal niceties are nothing even remotely so poetic. Here is a non-exclusive list of the problems I see with such a strategy:

1.  Such actions tread into legal no-mans-land - namely, that as far as I can tell, there is no legal precedent in support of such actions. Conversely, there's a ton of case law that is not on your side which states bluntly that unauthorized access is just that, unauthorized - no matter who the party "hacking" is.

2.  Any sophisticated hacker that would attack a semi-large or multi-national corporation isn't going to be hacking from their Dell PC at home, sitting behind a poorly secured Linksys router. They will be hitting through proxies, utilizing Tor, or more likely executing strikes through already compromised machines. The implication of this is three-fold - (a) in striking back, you may end up attacking an unwitting third-party who is likely also a victim of a computer crime - therefore, you will have even less sympathy if litigation arises; (b) if the originating host is an already compromised third-party, you could accidentally cause greater damage to hosts that are specifically enumerated in the CFAA, such as government computers, those containing national security information, or systems involved in medical care or public health/safety (See the DOJ's Prosecuting Computer Crimes manual) - and end up with a significant felony; or (c) (assuming a world where hacking-back becomes common), end up irritating a non-interested party, motivating them to also attack you.

3. While such actions may embolden or vindicate a hacked entity, they also put a larger target on your forehead. More specifically, if I were a hacker and my goal was simply to exfiltrate data, and you then attack me back, I am highly likely to escalate my attacks quid pro quo. Accordingly, what might have been simply a small case of data loss may turn into full scale damage to your systems; instead of sneaking in and out, you are now susceptible to much more malicious attacks - Denial of Service attempts, deletion of sensitive or irreplaceable data, actual hardware damage, or "doxing" of company executives. This undoubtedly will raise the price of the incident exponentially.

4.  It is unclear to me what an entity stands to gain by hacking back, other than the cathartic chest pounding that may occur when one can say that they "lost the battle, but won the war." Is that really worth a potential prison sentence?  Yes, your efforts could assist law enforcement in tracking down who hacked you, but it won't be so cathartic when the tables are turned, post investigation, to then investigate you for your actions.

5. Lastly, in 2008 the CFAA was amended to include a conspiracy offense, so you may not even need to actually breach an attacker to run afoul of the law. Could a corporate agreement with a strike-back contractor be sufficient to violate 18 U.S.C. 1030(b)?  That is not clear - but I'm betting we are going to find out if this trend evolves into the norm.

Monday, June 25, 2012

Indiana law banning sex offenders from social networking sites upheld

In 2008, Indiana enacted a law that banned certain sex offenders from using social networking if the platform was also used by minors (statute available here). An Indiana resident challenged the statute as violating the First Amendment and suggested the prohibition would forbid him from checking his child's accounts, make political speech online, advertise his business, and connect with family and friends. The district court, however, held that no First Amendment violation exists. Doe v. Prosecutor, 2012 U.S. Dist. LEXIS 86862 (S.D. Ind. 2012).

The court reasoned that the statute is narrowly tailored because it "only precluded [the plaintiff] from using web sites where online predators have easy access to a nearly limitless pool of potential victims.... [and] the vast majority of the internet is still at Mr. Doe's fingertips." For example, the court noted, he may still use LinkedIn because users must be 18 or over.

Additionally, the court suggested that many alternative channels of communication exist such as civic meetings, radio shows, letters to the editor, e-mail, and blogging.

Thursday, June 21, 2012

Facebooking juror fails in asserting SCA claim after forced disclosure of trial-related posts

A California juror recently posted to Facebook about the trial while it was in progress. Upon learning of the act, the juror was required to consent to the court's review in camera of his Facebook postings. He argued that the order violated the Stored Communications Act, but the Court of Appeals of California disagreed (Juror No. One v. The Sup. Court of Sacramento Cnty., No. C067309, (Cal. Ct. App. 2012)).

After trial, one of the jurors told the court that another had posted comments to Facebook about the evidence in the case. That juror had not seen the comments during the trial, but another juror had "liked" one of the posts. The juror-author admitted he posted during the trial, but said the content had nothing to do with evidence. One of the parties in the case attempted to subpoena the juror's Facebook records, but Facebook refused to disclose, citing the SCA. The court later ordered the juror to provide the postings himself.

On appeal, the court held:
Juror Number One has provided this court with nothing, either by way of the petition or the supporting documentation, as to the general nature or specific operations of Facebook. Without such facts, we are unable to determine whether or to what extent the SCA is applicable to the information at issue in this case. For example, we have no information as to the terms of any agreement between Facebook and Juror Number One that might provide for a waiver of privacy rights in exchange for free social networking services. Nor do we have any information about how widely Juror Number One's posts are available to the public. 
But even assuming Juror Number One's Facebook postings are protected by the SCA, that protection applies only as to attempts by the court or real parties in interest to compel Facebook to disclose the requested information. Here, the compulsion is on Juror Number One, not Facebook.
The defendant also suggested that the order violated the Fourth and Fifth Amendments but did not actually present an argument or citation to support the theories.

Tuesday, June 19, 2012

Congratulations to Justin for being cited in a brief to the Wisconsin Supreme Court

Congratulations to my co-blogger, Justin Webb, whose published case note was recently cited in a brief to the Wisconsin Supreme Court. In the brief, the state is, among other issues, responding to an argument that the use of real-time tracking via GPS was unconstitutional when the search warrant specified the use of a passive GPS device (one that records data and is retrieved at a later time to obtain the location information). The device was used for four days, as opposed to multiple weeks in Jones. The case is State v. Brereton, and the AG's brief is available here (2012 WL 2160408).

Justin's note, "Car-ving out the Notions of Privacy: The Impact of GPS Tracking and Why Maynard is a Move in the Right Direction" (95 Marq. L. Rev. 751), presents the different ways courts analyzed GPS-related decisions, and suggests that the DC Circuit's use of the mosaic theory in Maynard (later styled as Jones in the SCOTUS case) is the proper approach. Here's the abstract:
In a controversial decision in 2010, the D.C. Circuit held that warrantless GPS tracking of an automobile for an extended period of time violates the Fourth Amendment. The D.C. Circuit approached the issue in a novel way, using “mosaic theory” to assert that the aggregation of information about an individual's movements, over an extended period of time, violated an individual's reasonable expectation of privacy. This Note discusses how state and federal courts have dealt with warrantless GPS tracking, and ultimately asserts that the Maynard court's decision was correct, insofar as it takes account of the interaction of changing technology and shifting societal notions of privacy. This Note urges the Supreme Court to incorporate an approach similar to Maynard within its Fourth Amendment jurisprudence. This Note concludes that failure to do so will contract already-cramped notions of privacy in the digital age, and facilitate a normative shift in conceptions of privacy that may be detrimental and irreversible.

Massachusetts appellate court to rule on compelled password disclosure of encrypted drive

A Massachusetts trial court, dealing with an encrypted drive in a criminal case, has asked the Massachusetts Appeals Court how to act. The question presented to the appellate court is:
Can the defendant be compelled pursuant to the Commonwealth’s proposed protocol to provide his key to seized encrypted digital evidence, despite the rights and protections provided by the Fifth Amendment to the United States Constitution and Article Twelve of the Massachusetts Declaration of Rights?
The case is Commonwealth v. Gelfgatt, Suffolk Superior Court No. SUCR2010-10491. Read more here in an article by Tom Ralph, Chief of the Cybercrime Division of the Massachusetts Attorney General's Office, published in the Cybercrime Newsletter, a publication of the National Association of Attorneys General and the National Center for Justice and the Rule of Law.

Cybercrime Review has extensively covered encryption issues. Click here for our archive on the topic.

Saturday, June 16, 2012

House Financial Services Committee holds hearing on cyber threats to financial institutions

Image courtesy of stock.xchng
The House Committee on Financial Services recently held a hearing entitled "Cyber Threats to Capital Markets and Corporate Accounts" with witnesses from from all major areas of the financial industry. The testimonies presented great information about cyber attacks on the industry, particularly those of:

The webcast and other testimonies are available here.

Friday, June 15, 2012

Tech Check: 1st Circuit errs in description of file hashing

In United States v. Farlow, 2012 U.S. App. LEXIS 11121 (1st. Cir. Jun. 1, 2012) the 1st Circuit erred in its description of how changing a file affects its hash value.  Judge Thompson stated:
The problem for Farlow is that we have rejected the idea that government agents should so narrowly restrict their searches of digital devices. "When searching digital media for 'chats' and other evidence of enticement" -- like the bodybuilder image -- "government agents cannot simply search certain folders or types of files for keywords." Crespo-Rios, 645 F.3d at 43 (emphasis added). The same goes for other specific identifying information -- like hash values. This is because computer files are highly manipulable. Id. at 43-44. A file can be mislabeled; its extension (a sort of suffix indicating the type of file) can be changed; it can actually be converted to a different filetype (just as a chat transcript can be captured as an image file, so can an image be inserted into a word-processing file and saved as such). See id. Any of these manipulations could change a document's hash value. And in any event a limited hash-value search would not have turned up any chat transcripts (which, again, can be saved as image files) or other evidence of Farlow's New York crimes. The government therefore reasonably executed a broad search that fell within the scope authorized by the valid warrant it obtained.
The highlighted/bolded portion is not in fact, completely true. It is true that capturing a chat transcript as an image, or placing it in a different document does change the hash value. But, merely changing the name of a file, or changing its extension using regular file operations does not change that file's hash value. A friendly example of that on OS X:


















And for clarity's sake, a duplicate test on Windows, using "hashtest2.txt" from the OS X machine as a starting point. I have copied the file and renamed it, as well as copied it and changed the extension:


Notice that the hash never changes, from OS X to Windows. It remains eb1a3227cdc3fedbaec2fe38bf6c044a.

I point this out merely to prevent this erroneous statement from being perpetuated. I do not think, on the whole, that it really makes too much difference in the case itself. I'm open to opinions otherwise.

As a caveat, let me also note that changing a file extension can also occur through a program (i.e. MS Paint) whereby one file format is converted to another (png to jpg, for example), and that would change the hash value. I think the words in this decision are just a little unclear and ambiguous.

Thursday, June 14, 2012

8th Circuit affirms conviction despite defendant's entrapment defense

In United States v. Shinn, 2012 U.S. App. LEXIS 11863 (8th Cir. 2012), the Eighth Circuit affirmed a conviction for attempting to induce a child to engage in criminal sexual activities over an argument of entrapment.

The defendant had engaged in an adult romance chat room conversation with what he believed to be a 14-year-old girl, though really a law enforcement officer. The defendant told her that if she was older, he would want to take her out to dinner but said "you're just too young. . . . you want to stay a virgin for as long as possible." The "girl" then indicated she was not a virgin. The two later discussed getting together once she turned 18. As they continued to chat over several months, the conversation progressed to sexual experiences, and the defendant sent her pictures of himself wearing only underwear.

Nearly three months later, the two finalized plans to meet at a hotel. After arriving, the defendant was arrested, and in his car were condoms and cameras, along with the girl's name and contact information. A search of his computer revealed no chats with minors nor evidence related to child pornography. He was convicted and sentenced to sixty-three months in prison.

At trial, the defendant argued inducement as the chat was in an adult romance chat room, the officer initiated some of the chats, and the alleged girl was portrayed "as a sexually precocious teenager." He also argued there was no evidence of predisposition. However, as the Eighth Circuit acknowledged, the defendant initiated the first five conversations and first mentioned sex (referencing her virginity), and he continued to bring sex up over other conversations. Further, predisposition was shown because he "readily availed himself of the opportunity to perpetrate the crime."