9 ms·
Judge Rules FBI Must Reveal Malware It Used to Hack Over 1,000 Computers
- spdustin 11y agoImagine a later hardline: "FBI Ordered to Reveal the Code Used to Backdoor San Bernadino Suspect's Phone"
- Zigurd 11y agoThe accused is conveniently dead in this case. In the next case, a defendant's lawyer would surely want to inspect the instruments used to gather evidence.
- kiba 11y agoMaybe we should appoint public defenders for the conveniently dead.
- ikeboy 11y agoThe code being released wouldn't matter, because it can't be installed anywhere without Apple signing it. Presumably the keys wouldn't need to be released in any such order.
- geofft 11y agoThe code is only useful on the specific iPhone in question if it is in fact signed, and Apple does not have the technical capability to sign an update for a specific phone but not others; they all trust the same keys. And Apple would deliver it to the FBI with a signature, so there's a high risk that the signature wouldn't be redacted before being available to the public.
- ikeboy 11y agoBut the version signed could check the id of the phone and shut down if not a hard coded id. Yes, it could be installed on any phone, but it would be useless on any other phone. And in order to modify it to work on other phones (even with source code) you'd need Apple's keys.
- nacs 11y agoIt'd be easy for anyone to patch memory at runtime to skip over that `if` check on the phone's ID (or at least easier than hacking the phone without the backdoor code). Once the backdoor/exploit is created and released, there's no securing it to where it will only be used on a single phone.
- daeken 11y agoIf you could trivially patch memory at runtime, they wouldn't need this firmware in the first place -- they'd just patch out the lock-on-fail code. If you assume that the chain of trust is compromised such that memory changes can be made, you own the device.
- moyix 11y agoPatching memory at runtime on an iPhone is not in any sense "easy". If it were the FBI wouldn't need Apple's help right now at all; they could just NOP out the code that implements the increasing timeout and erase-on-too-many-failures code. To put it another way – if it were in fact easy to patch memory at runtime, there would be no need for the jailbreak community to spend huge amounts of time and effort every new OS release.
- geofft 11y agoYou're right, that's a good point.
- ikeboy 11y agoAlso, Apple does have the ability to prevent signed updates from being installed on phones they don't want it to be. Every update must be signed by Apple specifically to the phone that's being updated, and this includes a nonce to prevent replay attacks. (I forgot about this in my reply above). See https://en.wikipedia.org/wiki/SHSH_blob https://en.wikipedia.org/wiki/SHSH_blob, https://www.theiphonewiki.com/wiki/SHSH https://www.theiphonewiki.com/wiki/SHSH, http://www.saurik.com/id/12 http://www.saurik.com/id/12
- ericcumbee 11y agoAre you sure that is the case? Or is that the Case for Iphone 5C and earlier? I remember listening to the Security now episode where they discuss the IOS Security model and it worked something like. 1)Apple Sends A notification that an update is available. 2) the Phone sends a request with certain identifiers for the update. 3) Witchcraft happens 4) Apple sends a update signed specifically for that device and it will work on no other device. Like I said that might be for 5c and older or I might have completely invented that.
- ikeboy 11y ago3GS and later introduced SHSH blobs. See sources I linked to in https://news.ycombinator.com/item?id=11141965 https://news.ycombinator.com/item?id=11141965 Every update is signed specifically to the device being updated.
- jsprogrammer 11y agoIf you are referring to the software Apple is building to circumvent their kill switch, I don't believe Apple is required to give the FBI access to the software.
- mpitt 11y agoRelated: http://www.zdziarski.com/blog/?p=5645 http://www.zdziarski.com/blog/?p=5645
- singletonaccnt 11y agoSo the headline uses the word "pedophiles", but in the article the word is nowhere to be found. Maybe that's because this sting isn't necessarily about pedophiles, but about people watching and trading child pornography. Using "pedophiles" only serves to reinforce the stigma of a already heavily stigmatized minority. The word "pedophile" should be defined as someone with a sexual attraction towards children. It doesn't describe behavior: people can choose to not act on the attraction, and many, invisible as they are, in fact do not. Also, the people operating and visiting that hidden service could have had other reasons for visiting. They are not necessarily all pedophiles.
- paulddraper 11y agoWhat's the better word?
- idbehold 11y agoI don't believe there is a specific term for someone who watches child pornography. Is there even a term for someone who watches legal consensual adult pornography?
- ikeboy 11y agoVoyeur?
- idbehold 11y agoThat's not specific to being legal, consensual, or adult.
- deleted 11y ago[deleted]
- nickpsecurity 11y agoFan, consumer, or audience of U.S.-based porn. ;)
- 11y ago
- Shivetya 11y agoI am more concerned that there is no limits to what they can do in regards to a honeypot (trap/etc). You would think child porn would be one thing they would not go this far with. Regardless, I think someone with expertise should be allowed to review any code developed by the government in such operations only to ensure it does not somehow violate the rights of innocents
- ikeboy 11y agoThe judge is not concerned http://motherboard.vice.com/read/judge-rules-fbi-running-child-porn-site-for-13-days-was-not-outrageous-conduct-playpen http://motherboard.vice.com/read/judge-rules-fbi-running-chi...
- tomjen3 11y agoWell he is wrong then.
- Lawtonfogle 11y agoCan't wait til they run an actual brothel this way. I mean, it is only a couple of throw away society doesn't care about and just imagine all the monsters we could catch doing so... :(
- ikeboy 11y agoURL should be changed to the source http://motherboard.vice.com/read/judge-rules-fbi-must-reveal-malware-used-to-hack-over-1000-computers-playpen-jay-michaud http://motherboard.vice.com/read/judge-rules-fbi-must-reveal...
- dang 11y agoYes. Changed from http://www.engadget.com/2016/02/19/fbi-reveal-code-lawsuit-dark-web-pedophiles/ http://www.engadget.com/2016/02/19/fbi-reveal-code-lawsuit-d..., which points to this.
- bpicolo 11y ago"Sure, here it is compiled to assembly and stripped of all comments." is sort of what I'd expect
- ebf6 11y agoIf you analyze malware for a living, then the assembly is the source code. :) It's really not that much of an issue. It makes things more fun. I am curious about whether they developed the malware in-house or if they hired a contractor. Is there any information out there on this? I wouldn't be surprised if they cut out parts, which may hint at a particular contractor having developed the malware. Also, I still do not understand why TOR Browser Bundle allows scripts by default.
- sirsar 11y ago> Also, I still do not understand why TOR Browser Bundle allows scripts by default. The best diet is the one you can actually stick to. The best birth control is the one comfortable enough to use. The best anonymity software must be usable enough for Joe Average. If the situation is high-stakes, TBB comes with NoScript installed. And you should probably get a burner laptop, do all your web browsing off TAILS, and randomly change your physical location.
- ebf6 11y ago> If the situation is high-stakes, TBB comes with NoScript installed. And you should probably get a burner laptop, do all your web browsing off TAILS, and randomly change your physical location. You are absolutely correct about practicing good opsec, however I have to challenge the usability argument. TOR is already less usable due to many sites blacklisting TOR exits nodes and latency (although connecting to a hidden service is a better idea, and avoids the blacklisting issue. And yet hidden services tend to avoid the JS requirement as well). If Joe Average is willing to put up with that in order to stay anonymous, I'm sure Joe would be willing to disable scripts. On the other hand, if Joe doesn't understand why having scripts enabled is a security risk, then this might be a better reason to have scripts off by default, anyway.
- boosting6889 11y agoThe Justice Department contends that the act of viewing a child porn image revictimizes the child each time the view occurs and is the basis for arguing that viewing child porn is not a victimless crime. Yet the FBI seized a server and allows such images to be downloaded and viewed thousands of times over a 2 week period. This would be like seizing the operators of an underground rape dungeon where patrons pay to rape children - and allowing such an establishment to run for 2 extra weeks to catch the patrons, regardless of any collateral damage that occurs to innocent children as a result. People would be up in arms over this. So, does viewing an image of child porn cause additional harm to the child in the image or not? Which is it? (This of course excludes instances where the viewer is paying/supporting production of the material)
- presidentender 11y agoThe dissonance is accepted in this case because of the repulsive nature of the crimes, as determined by our current social consensus. Philosophical purity is very appealing, but ultimately the justifications we use for why the law is the way it is only have to stand up long enough to convince most interested parties that we're doing the right thing.
- x5n1 11y agoWell biologically the person has inherited some genes that function in such a way as to lead to their obsession with young people. At the end of the day this is very much a mental problem that can be remedied with bioengineering. Not much else you can do for these people. To criminalize it in all of its forms, is the same thing as criminalizing any sexuality. Perhaps one day we'll create an algorithm that can generate these images without anyone being involved -- does that sound distasteful as well. At this point even artful depictions of a sexual nature are illegal, criminal offense.
- nso 11y agoHas it been proven that Pedophilia is genetic, tho?
- deleted 11y ago[deleted]
- moyix 11y agoUnless this is different from the shellcode they used when taking down Freedom Hosting, I'm not sure what releasing it would do. There are already numerous analyses of the code: - Vlad Tsyrklevich: http://tsyrklevich.net/tbb_payload.txt http://tsyrklevich.net/tbb_payload.txt - Gareth Owenson: http://owenson.me/fbi-tor-malware-analysis/ http://owenson.me/fbi-tor-malware-analysis/ - My own analysis based on running it in PANDA: https://www.reddit.com/r/ReverseEngineering/comments/1jpln2/has_anyone_else_taken_a_look_at_the_shellcode/cbh1qpe https://www.reddit.com/r/ReverseEngineering/comments/1jpln2/... (you can also get the recording of the shellcode executing and step through it here: http://www.rrshare.org/detail/26/ http://www.rrshare.org/detail/26/ ) It's not big, and we have a pretty good idea what every piece of it does. Of course, I suppose we don't know that the malware it used in this case is the same as the one in the Freedom Hosting case, so I guess it would be nice to compare and contrast them.
- belorn 11y agoOne benefit is to have documented evidence that FBI did release malware to the public. There has been little to no discussion on safeguards or liability when it comes to government published malware, and I wonder if a concrete example can enable such discussion.