Show
Destroy
An entry
Get it down. Make it good. Share it.
Title
Text
https://techcrunch.com/2024/11/08/fbi-says-hackers-are-sending-fraudulent-police-data-requests-to-tech-giants-to-steal-peoples-private-information/ * specific issues fraudulent subpoenas. How to enhance the veracity of subpoenas to prevent fraudulent creation and submission of subpoenas ### Scope Apple, Google, Meta, and Snap, which store huge amounts of customers’ personal and private data, collectively receive tens of thousands of emergency data requests every year. To make matters more complicated, there are tens of thousands of police jurisdictions around the world — including roughly 18,000 in the United States alone (krebs) it is becoming more common for hackers to use EDRs for stalking, hacking, harassing and publicly humiliating others. (KREBS) Nicholas Weaver, a security specialist and lecturer at the University of California, Berkeley, said one big challenge to combating fraudulent EDRs is that there is fundamentally no notion of global online identity. (KREBS) “The only way to clean it up would be to have the FBI act as the sole identity provider for all state and local law enforcement,” Weaver said. “But even that won’t necessarily work because how does the FBI vet in real time that some request is really from some podunk police department?” (KREBS) Rasch said while service providers need more rigorous vetting mechanisms for all types of legal requests, getting better at spotting unauthorized EDRs would require these companies to somehow know and validate the names of every police officer in the United States. (KREBS) NICHOLAS WEAVER AT BERKELEY ## Tactics n March 2024, a known cyber-criminal posted photos on an online forum of a fraudulent emergency data request submitted to Paypal. According to PayPal, the threat actor submitted a fraudulent Mutual Legal Assistance Treaty (MLAT) regarding a local ongoing investigation into child trafficking, which included a case number and legal code for verification, but the request was ultimately denied by PayPal. - https://www.documentcloud.org/documents/25281365-fbi-ic3-notice-241104 It is now clear that some hackers have figured out there is no quick and easy way for a company that receives one of these EDRs to know whether it is legitimate. (KREBS) But there’s no real mechanism defined by most Internet service providers or tech companies to test the validity of a search warrant or subpoena. And so as long as it looks right, they’ll comply.” (krebs) Asked about the validity of the unauthorized EDR shared by KT, Discord said the request came from a legitimate law enforcement account that was later determined to have been compromised. “We can confirm that Discord received requests from a legitimate law enforcement domain and complied with the requests in accordance with our policies,” Discord said in a written statement. “We verify these requests by checking that they come from a genuine source, and did so in this instance. While our verification process confirmed that the law enforcement account itself was legitimate, we later learned that it had been compromised by a malicious actor. We have since conducted an investigation into this illegal activity and notified law enforcement about the compromised email account.” (KREBS) “It’s highly risky if you get caught,” Weaver said. “But doing this is not a matter of skill. It’s one of will. It’s a fundamentally unfixable problem without completely redoing how we think about identity on the Internet on a national scale.” (KREBS - WEAVER) ## Mitgations * Organizations should document approved solutions for remote management and maintenance, and immediately investigate if an unapproved solution is installed on a workstation. - https://www.documentcloud.org/documents/25281365-fbi-ic3-notice-241104 “We have a legal process to compel production of documents, and we have a streamlined legal process for police to get information from ISPs and other providers,” said Mark Rasch, a former prosecutor with the U.S. Department of Justice. (KREBS) n July 2021, a bipartisan group of U.S. senators introduced new legislation to combat the growing use of counterfeit court orders by scammers and criminals. The bill calls for funding for state and tribal courts to adopt widely available digital signature technology that meets standards developed by the National Institute of Standards and Technology. “Forged court orders, usually involving copy-and-pasted signatures of judges, have been used to authorize illegal wiretaps and fraudulently take down legitimate reviews and websites by those seeking to conceal negative information and past crimes,” the lawmakers said in a statement introducing their bill. The Digital Authenticity for Court Orders Act would require federal, state and tribal courts to use a digital signature for orders authorizing surveillance, domain seizures and removal of online content. (KREBS) https://www.wyden.senate.gov/download/the-digital-authenticity-for-court-orders-act-of-2021-one-pager https://www.congress.gov/bill/117th-congress/senate-bill/2547/all-info https://www.congress.gov/bill/117th-congress/senate-bill/2547/text (3) Secure digital signature technology has existed for decades that solves this problem. Digital signatures enable recipients of a digital document to verify that it was issued by an authorized entity and that it has not been tampered with or modified since it was digitally signed. * Since 1994, the National Institute of Standards and Technology has published Federal Information Processing Standard 186–4, which is the official standard for digital signatures for the Federal Government. https://www.congress.gov/bill/117th-congress/senate-bill/2547/text * (7) The legislative branch has also embraced digital signatures. Every bill posted to congress.gov is digitally signed by the Government Publishing Office. * (8) Federal, State, and Tribal courts have not kept pace with the adoption of digital signature technology by other branches of government. ## References * https://techcrunch.com/2024/11/08/fbi-says-hackers-are-sending-fraudulent-police-data-requests-to-tech-giants-to-steal-peoples-private-information/ * https://www.documentcloud.org/documents/25281365-fbi-ic3-notice-241104 * https://www.bloomberg.com/news/articles/2022-03-30/apple-meta-gave-user-data-to-hackers-who-forged-legal-requests * https://krebsonsecurity.com/2022/03/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests/ * https://www.congress.gov/bill/117th-congress/senate-bill/2547/text * https://techcrunch.com/2024/10/07/the-30-year-old-internet-backdoor-law-that-came-back-to-bite/ ### ChatGPT 2024-11-08 https://chatgpt.com/c/672e8c9e-f3d4-800c-8574-2f0c92370591 Emergency data requests (EDRs) are requests for access to data—often personal data—by law enforcement or government agencies when there’s an urgent situation that could threaten someone’s life, health, or safety. Unlike standard data requests, which may go through a longer approval process, EDRs allow authorities to bypass typical requirements to access necessary information quickly. Here’s how they typically work: 1. **Urgency**: EDRs are issued only in cases where there is an immediate threat, such as preventing a crime in progress, finding a missing person, or responding to a serious accident or natural disaster. 2. **Limited Scope**: These requests are supposed to be narrowly focused—meaning they should only ask for data that’s directly relevant to resolving the emergency. 3. **Authorization**: Typically, an authorized officer from a law enforcement agency can issue an EDR. These requests usually do not require a warrant due to the urgency but might require some form of internal review within the agency. ### Legal and Policy Foundations In the United States, EDRs are guided by both federal and state laws, and policies vary across jurisdictions: - **Federal Law**: The primary federal law governing emergency data requests is the Electronic Communications Privacy Act (ECPA) of 1986, specifically the Stored Communications Act. The ECPA allows service providers to disclose information voluntarily to government agencies if the provider believes there’s an emergency involving the risk of death or serious injury. - **State Law**: Some states have additional laws and policies around EDRs. States may outline specific circumstances, requirements, or limitations on the types of data accessible through emergency requests. - **Local Policy**: Local government agencies may have their own procedures for handling emergency data requests, often to align with federal and state regulations. Some cities may set additional oversight measures, such as requiring internal review before data is disclosed. - **Company Policies**: Many tech companies and service providers have policies in place to respond to EDRs from law enforcement. These policies typically outline what types of data can be shared, how to verify that a request is legitimate, and what information to provide only in emergency circumstances. Overall, EDRs are a tool to balance the need for public safety with respect for privacy, but they must be used carefully to avoid potential misuse.
Status
idea
draft
release
personal
Series
Part of a Series?
Bitcoin
On Work
Phoenix Trello Tutorial
Civics
Re Email Address
Tags
data requests
×
security
×
transparency
×
+
Slug
Url
Image 1
Image 2
Image 3
Visible
Date