15 ms·
A Digital Rumor Should Never Lead to a Police Raid
- vorotato 10y agoOtherwise the police become the weapons of criminals which is, of course backwards.
- PaulHoule 10y agoIt's as much a "law and order" issue as it is a civil rights issue. Cops have limited resources to deal with a number of problems and if they don't have the training and procedures to use internet evidence they are going to waste those resources tracking down stolen cars, child porn and whatever in the wrong places.
- coldcode 10y ago(1) It's unreliable (2) It's unconstitutional assuming judges agree (3) It's expensive if you screw it up, such as people die, lawsuits, or embarrassment. All of which is unlikely change behavior unless everyone agrees.
- dtnewman 10y agoIt starts off saying: > If police raided a home based only on an anonymous phone call claiming residents broke the law, it would be clearly unconstitutional... Yet EFF has found that police and courts are regularly conducting and approving raids based on the similar type of unreliable digital evidence: Internet Protocol (IP) address information. I'm not sure that these two are equivalent. A better example would be the police raiding my home based on an illegal phone call that came from my phone number. Sure, the fact that it comes from my phone number doesn't mean I did it, but it's certainly evidence that points to me, just as an IP address can be. In general, the summary linked to above makes it sound like police should never use IP addresses. To be fair, if you read the whitepaper itself, it doesn't say this, but rather that police should be _careful_ in how they use IP addresses. Specifically, it recommends that police "conduct additional investigation to verify and corroborate the physical location of a particular decive connect to the Internet whenever police have information about an IP address’ physical location, and providing that information to the court with the warrant application".
- crooked-v 10y ago> A better example would be the police raiding my home based on an illegal phone call that came from my phone number. That's broadly overestimating the reliability of IP addresses, though. Consumer IP addresses change on a random basis, based on whatever obscure policies an ISP has set up at the time.
- jlarocco 10y agoThat doesn't matter. Police get the physical address from the ISP. The ISP knows which IP was assigned to each customer at any particular time because they log it. Yeah, it's theoretically possible they don't keep the logs, but IRL they always do.
- taormina 10y agoYou have to remember that the ISP might have a physical location if this is a paying customer on a landline, but that's not usually the case. Reverse IP address location lookups are unreliable as worst and inaccurate at best. That house in Kansas that they mentioned? It's the default "middle of the US" location that is returned when they don't actually know where you are.
- tedunangst 10y agoAny ISP is going to have a more accurate idea of which customer has an IP than a generic geolocation service. An ISP in Ohio is not going to return a latitude and longitude that happens to be in Kansas.
- deleted 10y ago[deleted]
- AnthonyMouse 10y ago> Police get the physical address from the ISP. The ISP knows which IP was assigned to each customer at any particular time because they log it. Yeah, it's theoretically possible they don't keep the logs, but IRL they always do. That isn't the source of the uncertainty though. It's part of it in the sense that cost-cutting ISPs may have inaccurate records, but the fundamental issue is that IP addresses are completely unauthenticated. Some people turn off their modems when they're not using them. One way to steal internet service on some ISPs is to clone the MAC of your neighbor's cable modem (and then the ISP thinks you're them). People have guests who use their WiFi. Some people use WEP, or weak passwords, or are just nice people who intentionally leave their WiFi open for public use. Anyone who controls (or compromises) a router can spoof any IP address that routes through it. Same with compromised client devices that can be turned into proxy servers. Even so, the probability that any given traffic is actually from the person whose name is on the bill is still pretty good, unless that traffic is illegal. Because people engaged in illegal activity have the incentive to do one of those things or any of a hundred other ways to get an IP address not tied to your name. And it isn't that hard to do those things. Which means there is a high probability that an IP address associated with illegal activity belongs to an innocent party rather than the perpetrator.
- danso 10y agoFWIW, the prospect of being suspected and questioned (but not necessarily raided) because of your IP location is one of the best metaphors to relate what it's like as a minority to be searched just because you are of the same race as a suspect in an nearby active case. It is perfectly logical to say that if there was an assault on a college campus and that the victim said the perp is an "Asian male", for the police to not prioritize the questioning of all non-Asians in the area. And if the report was made within minutes of the incident and the suspect is on foot, it may be justifiable to target the 5 Asian males loitering around rather than the 95 people of other demographics. What logical person would argue otherwise? But the problem creep comes in the many, many cases when police don't have a threshold for how long and wide that demographic descriptor should be used. Within 1000 feet of the reported attack? A mile? Why not 2 miles? And why not 2 days or even 2 weeks after the incident, just to be safe? The main difference in the ISP/IP metaphor is that in the digital world, it's possible to imagine search-and-question tactics that aren't time-consuming for the police or for the suspect. Hell, the suspect might not even know their internet-records were under any suspicion. OTOH, there are definitely real-world places in which for the police (and their community and most specifically the politicians), hand-cuffing and patting someone down has been so streamlined and accepted by the powers-that-be that it isn't a bother for them (the police) either. edit: To clarify, I don't mean to get in the very wide debate on racial profiling, etc. But when I worked at a newspaper, we had a policy to not mention race unless the police could provide 4 or 5 other identifiers. That led to readers cussing us out because, they'd argue, knowing that the suspect was black is better than nothing. My point here is that sometimes, nothing is not always better than something, and that is most explicitly clear when it comes to broad IP range searches.
- Bartweiss 10y agoI really appreciate this analogy, actually. It's hard to construct a principled, narrow argument against profiling. If you have a single piece of exclusionary information, it's ludicrous to conduct a bunch of searches which are guaranteed to be worthless in the name of equality. (Leaving aside the accuracy of the tip for now.) And yet on a broader level, it's apparent that profiling can have all kinds of awful side effects. An obvious example (and the metaphor carries) is secondary crimes discovered in the course of an investigation. There's another narrowly sensible rule: if a cop stops you for a broken taillight, they shouldn't have to ignore a corpse sitting in your passenger's seat. But combined with profiling, it produces a system where often-profiled people get the law enforced against them far more harshly than other groups. Add to that the cost and stigma of being investigated (a day in jail while innocent is a great way to lose a job), and you have a system where utterly sensible enforcement produces consistently biased harms. The metaphor here carries really well. Imagine if those Kansas farmers torrented a bunch of movies, or that Seattle privacy advocate had a bit of marijuana. Well, those things are illegal, but it's still not fair that shoddy profiling amounts to selective enforcement against the profiled. Even if you never, ever get incorrect data or wrongfully convict someone, profiling with limited data causes all kinds of secondary harms. This is a great non-racial example of why we should worry about it regardless of accuracy.
- rayiner 10y agoNot great to start an article off with sloppy reasoning: > If police raided a home based only on an anonymous phone call claiming residents broke the law, it would be clearly unconstitutional. > Yet EFF has found that police and courts are regularly conducting and approving raids based on the similar type of unreliable digital evidence: Internet Protocol (IP) address information. When police go after an IP address, it happens after there is evidence linking it to some crime. That makes the situation wholly unlike an anonymous phone call, where there is no evidence a crime has even been committed, and where the identifying information itself is trivial to falsify. Also, IP addresses give a lot more information than the article implies. Especially these days now that everyone has a home router that probably keeps the same IP address for weeks at a time if not months. Not enough to trigger a police raid, of course (if we want to argue that the police have too low a standard of evidence for initiating a raid, I agree) but it's probably a good lead to go on in the common case. EDIT: I don't disagree with the rest of the article.
- mordocai 10y agoI would argue that ip address is trivial to falsify (though certainly not as trivial as an anonymous phone call).
- marcoperaza 10y agoYou can send packets with a fake source IP, but you won't get any response back, so it's of extremely limited utility. If there's traffic back and forth between two IPs going through ISP infrastructure, then it's a safe bet that it's the real deal.
- cmdrfred 10y agoOr I send you a word document with a macro that installs a reverse tunnel allowing me to push my traffic through your machine.
- marcoperaza 10y ago
- throwaway92314 10y agoI'll just point this out here. Reena Virk started as a rumour going around in schools. Until eight days later her body was found. A little bit of prudence is necessary, but don't discount rumours out of hand. https://en.wikipedia.org/wiki/Murder_of_Reena_Virk https://en.wikipedia.org/wiki/Murder_of_Reena_Virk
- marcoperaza 10y ago>Law enforcement’s over-reliance on the technology is a product of police and courts not understanding the limitations of both IP addresses and the tools used to link the IP address with a person or a physical location. You can most certainly narrow down an IP address to a particular ISP customer. Is it possible that they have an open wifi? Yes. Is it possible to narrow it down to a single member of the household? Depends! Is it possible that a computer at the destination is being used a proxy by the real attacker? Yes! But it's certainly not the blackbox that the EFF is trying to portray it as. It's totally appropriate to execute a search warrant based on IP logs. A search warrant doesn't mean that any particular person is guilty, just that there is probable cause that there is information about a crime at a certain location.
- snuxoll 10y agoI mean, it's reasonable to link it with a physical location, but only to the extent that there's obviously A computer at the location that is being used for some purpose. The problem is when they use it to try to identify an individual, which is completely unreasonable.
- guitarbill 10y ago> obviously A computer at the location that is being used for some purpose Well "A computer" could be any TCP/IP enabled device nowadays, including a router. So no, it's not reasonable to look at traffic coming from an IP, and say that traffic originated from the physical location of that IP, just because the LAN beyond that router is opaque. I mean, several ISP IP addresses are involved with routing, but "everybody knows" they're shared machines. But again, simply because a trace route stops at a certain machine doesn't mean the routing actually terminates there - for most cases this is not true. It's just that the person behind the router with NAT often owns all devices on the LAN/opaque side. Using this correlation alone is dangerously inaccurate.
- snuxoll 10y agoI never implied that a system in that network was the origin of the traffic, but if a traceroute ends there then obviously SOMETHING at that location is involved, knowingly or not. A search warrant leading to a malware infected machine is acceptable in my eyes. Again, tying traffic to a location is fine, as long as the correlation ends at the computer that originally appears to be the source of the traffic (even if it ultimately isn't) is all that is targeted until evidence can determine the individual behind it.
- xienze 10y ago> Put simply: there is no uniform way to systematically map physical locations based on IP addresses or create a phone book to lookup users of particular IP addresses. Maybe today, but when we have wide deployment of IPv6 (heh), won't ISPs do away with NATing and give everyone their own block of IPs? Then I would think you could reliably tie a person to an IP address as long as the ISP cooperates.
- mikeash 10y agoNAT isn't the only or even the most important source of errors here. The article cites two examples, one where imprecise IP location information was being represented as precise, and one where a Tor exit node was mistaken as the actual originator. Neither one would have been fixed by using IPv6.
- snuxoll 10y agoWell, location will be fixed to an extent with IPv6. All you need to do is contact the ISP that owns the appropriate /48 or whatever they were given, ask them the address of the customer with said /64 and there you go. Of course, this is the same thing they should already be doing with v4, carrier-grade NAT is fairly uncommon for anything but mobile use except in Asian countries. Still, you can't tie an IP address to a specific person or computer, v4 has NAT to contend with and privacy extensions with v6 (which Microsoft and Apple use by default, most Linux distributions do as well) - so regardless if you can get the physical location where that IPv4 address or IPv6 prefix is assigned it does you no good on determining who was actually behind that address (unsecured wifi or easy to crack passwords, malware, the list goes on).
- mikeash 10y agoThe first example isn't due to an inability to get the location, but using a source of data that didn't have it, and didn't adequately explain that fact. It'll happen just as easily with IPv6.
- arca_vorago 10y ago
- eth0up 10y agoA few examples suggesting that SWAT protocol may altogether need reform: 1. http://arstechnica.com/tech-policy/2012/06/swat-team-throws-flashbangs-raids-wrong-home-due-to-open-wifi-network/ http://arstechnica.com/tech-policy/2012/06/swat-team-throws-... 2. https://www.salon.com/2013/08/29/11_over_the_top_u_s_police_raids_that_victimized_innocents/ https://www.salon.com/2013/08/29/11_over_the_top_u_s_police_... 3. https://en.wikipedia.org/wiki/Swatting https://en.wikipedia.org/wiki/Swatting 4. https://www.techdirt.com/articles/20150805/19343431865/no-immunity-cops-who-sent-swat-team-to-68-year-old-womans-house-threats-delivered-over-open-wifi-connection.shtml https://www.techdirt.com/articles/20150805/19343431865/no-im... I'll refrain from posting dozens more supporting links.
- Pxtl 10y agoHere's the problem: what do you do when somebody has managed to describe, over the phone, a convincing scenario that demands an immediate and severe response. Like "people are dying in that room right now and will continue to die if nobody stops them". Fundamentally, there is no good answer to that. Both options can result in lives lost. One is an active shooter being allowed to continue killing freely, the other is sending police officers ready to deal and face lethal force. Obviously no-knock raids on suspected drug-dealers are a different matter - those are unacceptable by any sane metric. But you include swatting in your list. Swatting generally involves a violent emergency where delaying for verification would cost lives. For that case, all I think we can do is treat the swatters as people committing aggravated kidnapping or even attempted murder. They're attempting to send men to detain somebody at gunpoint.
- maxerickson 10y agoThe rational thing might be to let the people in the room die. It depends on how many outwardly hidden death rooms there really are and how often the existence of these rooms is revealed by anonymous phone calls. You don't need much of a ratio there for urgent action against false calls to create more harm than the hidden death rooms. And it doesn't have to be a binary choice; upon receiving notification of a hidden death room, the police could choose to investigate cautiously rather than escalating to extreme force. This will likely still have the effect of reducing the number of hidden death rooms without much risk of shooting innocent people in a raid.
- s_q_b 10y agoIf the use of IP addresses in this manner disturbs you, you should look into the the proposed changes to Federal Rule Of Criminal Procedure 41. This is the EFF's article, which is either a highly overzealous or highly prescient: https://www.eff.org/deeplinks/2016/04/rule-41-little-known-committee-proposes-grant-new-hacking-powers-government https://www.eff.org/deeplinks/2016/04/rule-41-little-known-c...
- soylentcola 10y agoA similar example, while not a raid, hit me closer to home a bit over a year ago. I'm sure that if you follow US news at all, you heard about the looting and arson in Baltimore in the Spring of 2015. While the city was on edge in the wake of a citizen's death in police custody, there had already been some minor demonstrations and a brawl between protesters, baseball fans, and provocateurs downtown earlier in the month. Then, on the day of the funeral held for the man killed in custody, word started to spread of plans for some sort of riot or mass havoc being planned later in the day. Later, authorities pointed to a digital "flyer" being passed around yet nobody investigating this outside of the police has found any source or initial copy of this flyer that dates before this was published in the media. Trust me, we looked. In response to this alleged threat to public order, cops with riot gear and a freaking mini-tank showed up at a major public transit hub right as school let out. Transit was shut down and everyone was corralled into a small area next to a busy street and without a way home for hours. Eventually, tensions got high enough that when the first pissed off teenager or whoever chucked a bottle or a rock, it didn't take long for others to join in. In the ensuing vandalism and arson, hundreds of thousands in damage was caused, people got hurt, the city was put under curfew for a week, and to this day, businesses and residents have suffered from the reputation gained (worsened?) that day. Looking back, the part that really sticks out to me is how the whole thing was triggered (assuming you don't think it was a deliberate provocation) by some "social media flyer" that claimed some teens were planning to run around starting shit after school. This rumor summoned riot police, shut down transit, stranded loads of adults and teens alongside the road, and facing down a phalanx of police plus one armored tactical vehicle. Would those shops and homes still been damaged or those stores been looted and burned in a wave of unrest without this rumor-inspired flashpoint? No idea. But it sure didn't help.
- okwhatthe2 10y agoA spoiler is contained in the following reference. This reminds me of Ghost in the Shell: Standalone Complex: 2nd Gig, wherein a single actor causes an AI to rotate military forces within a refugee area, with the explicit intention of increasing anti-police sentiment among refugees. The world is a stage and, without proper leadership, crowds will behave in ways they believe are allowed within the hard constraints of the social order. This is at the core of the BLM movement, and a pillar of the Occupy movement: police must not view themselves as separate from the policed. For cybernetic reasons as well as pathos ones. Otherwise, from the perspective of the social order, the distinction between the two is error.
- pjc50 10y ago"If police raided a home based only on an anonymous phone call claiming residents broke the law, it would be clearly unconstitutional" I thought that was how SWATting worked - anonymous denunciation by untraceable phone call?
- astazangasta 10y agoYeah, is this just an urban legend? Fake videos, etc.? It's always seemed absurd to me that you can send men with guns to raid someone's house just with an anonymous phone call.
- dottrap 10y agoNope, not an urban legend. This is really happening. Just last week a home with 5 children was wrongly raided: http://www.denverpost.com/2016/09/14/swat-officers-raid-home-in-mesa-county-only-to-find-innocent-family/ http://www.denverpost.com/2016/09/14/swat-officers-raid-home... Wrong house with Grandmother and Teen girl raided with flash-bang: http://reason.com/blog/2015/08/03/swat-team-liable-for-wrong-house-flash-b http://reason.com/blog/2015/08/03/swat-team-liable-for-wrong... This gamer was "Swatted" and the web cam caught it: http://reason.com/blog/2014/08/28/militarization-of-police-helps-feed-swat http://reason.com/blog/2014/08/28/militarization-of-police-h... This 1-year old baby was critically burned by a flash-bang grenade thrown into the playpen: http://www.cnn.com/2014/10/07/us/georgia-toddler-stun-grenade-no-indictment/ http://www.cnn.com/2014/10/07/us/georgia-toddler-stun-grenad...
- stronglikedan 10y ago> If police raided a home based only on an anonymous phone call claiming residents broke the law, it would be clearly unconstitutional. But they do this all the time, especially in low income areas. They just don't call it a raid. They call it a "welfare check".
- xor1 10y agoIt's honestly terrifying.
- pmoriarty 10y agoIn the 1980's, some powerful senator's cell phone was snooped on, resulting in a major scandal when the contents of his phone calls was revealed in the press. This resulted in Congress passing laws that made it illegal for radios to be capable of listening in on cell phone frequencies or being easily modified to allow them to do so. It is likely that only similar widely publicized embarrassments and privacy violations of the rich and powerful will result in any meaningful legislative attempts to curtail the growth of the police state in the United State. They clearly don't intend to do much about it unless they themselves are the victims of such abuses of power. As long as it's just "nobodies" or social or political outcasts who are the victims the police and surveillance aparatus, it's doubtful that much will change.
- AnthonyMouse 10y agoYour example shows why that doesn't work. The correct solution to people eavesdropping on calls is end-to-end encryption, which we still don't have for phone calls. Which means that bad people can still eavesdrop. But meanwhile we now have a stupid law that prevents honest people from buying interesting radio hardware and makes it even less likely that we will ever have open cellphone baseband processors etc.
- eth0up 10y agoA few more examples of botched attempts at IP-based raids: http://arstechnica.com/tech-policy/2011/04/fbi-child-porn-raid-a-strong-argument-for-locking-down-wifi-networks/ http://arstechnica.com/tech-policy/2011/04/fbi-child-porn-ra... The one I'm familiar with is the Sarasota, FL incident, where a married couple was raided in the middle of the night in response to alleged child pornography. Their unit was in a condominium, practically on the edge of Sarasota bay, where various boats moor and dock. After further investigation, it was discovered that the traffic had originated from some guy in a boat using a high gain antenna. If I remember correctly, he had cracked their WEP key and illegally accessed their network to obtain nasty images, lots of them. The insecurity of WEP has been known about for a long time, presumably by LE too. It is conjecture on my part, but a few things come to mind regarding alternative methods of investigation that may have avoided this. 1. Contact the ISP first (in this case I think it may have been Verizon). I remember Verizon having the ability to remotely reset router passwords, which possibly suggests the ability to remotely view associated client data, e.g. MAC addresses and hostnames and maybe even OS. This may have provided valuable clues. 2. Note the protocol used by the wireless router. 3. Wardrive a bit. 4. Maybe check for logs of any accounts the boat guy logged into while on their network. Regardless, the raid was botched and pretty traumatic for the couple, considering they were operating a legal AP probably secured with what they thought was adequate encryption. At the time of this event, WEP was standard default, straight from the ISP. They'd done nothing wrong. More info: http://www.heraldtribune.com/news/20110131/wireless-router-hijacked-for-child-pornography http://www.heraldtribune.com/news/20110131/wireless-router-h...
- braum 10y agomost police, especially in smaller areas, don't have the people on hand or on call to explain all this "techy" stuff to the people who make these decisions OR those people choose to ignore them... it seems like it takes 10+ years for cops to catch up and improve their investigation techniques, at least in the smaller areas with fewer resources.
- eth0up 10y agoNot disputing that necessarily, but take note that SPD has been very very busy[1] with their Stingray IMSI catchers and a host of other fairly sophisticated equipment. Even for an entry-level officer, an Associate degree or several years of military service is required. From my personal observations, the average SPD officer or deputy is pretty bright and even well informed. The chief of Police here has a masters degree and went to an FBI National Academy, although she wasn't chief back then. Also, I believe the FBI was involved in the above mentioned raid. And while I enjoy cynicism, the FBI is anything but stupid. 1 https://www.wired.com/2014/06/feds-seize-stingray-documents/ https://www.wired.com/2014/06/feds-seize-stingray-documents/
- matt_wulfeck 10y ago> IP address information was designed to route traffic on the Internet, not serve as an identifier for other purposes. I think you're going to have a hard time here convincing a jury or judge with this argument. In general LOE isn't concerned with the intentional of what an IP address was meant for. At least with today's ISP an IP address can be a reasonable approximation of a person or persons.
- riskable 10y agoIt is not a reasonable approximation of a person or persons. That's the point. An IP address is merely an end point to some internet traffic. There's a nearly infinite number of reasons why traffic could originate from an IP that was not initiated by the current responsible party. Anything from hacked machines to clever redirects to shared IPs to just plain network trickery. It is so ambiguous at this point that you can't even make an analogy that it is like a home housing a dozen people. Because even in that situation it just means there's n more devices that could've been hacked and they've shared their wifi with n more guests. An IP address by itself should never be used for anything but starting an investigation. For a warrant it had better be surrounded by corroborating evidence.
- matt_wulfeck 10y agoI totally agree with you in principle. However, ultimately the EFF is the one making the argument and I don't personally believe it's going to convince a judge and a jury. And it's important to sometimes be skeptical, because if they use this argument in a trial and lose then it sets a precedent that can be used in future cases. And the prosecuting attorneys have plenty of examples where IPs successfully led directly to the perpetrator of a crime. Think of all of the people who have been arrested and prosecuted for online crimes and took a plea bargain. It's a very uphill battle. I wish the EFF all of the best luck (I myself am a contributor and believer), but I don't think they're going to make much progress with this one.
- nv-vn 10y ago>If police raided a home based only on an anonymous phone call claiming residents broke the law, it would be clearly unconstitutional. Isn't that exactly what happens when you get SWATted?
- rocky1138 10y agoWhy don't we just regulate any Internet-connected device? When you purchase one, you register your name and address and are given the IP address in return. Then, we can simply look up the physical address of the IP address holder.
- hughes 10y agoThis would be the end of any hope of privacy on the internet.
- rocky1138 10y agoI should probably say that I was being extremely sarcastic, because this sort of thing doesn't come off well on the Internet :)
- jedberg 10y agoI'm not sure if you're trying to make a sarcastic analogy to gun registration or not, but if you are, they aren't quite the same, given that a gun is a physical object and an IP can change without the user knowing or being responsible for that change.
- rocky1138 10y agoHaha nah, I didn't put those two together. I guess gun registry is a big topic in the states right now. I was just pretending to be a politician since that's the sort of response I feel they would come up with.
- sean2 10y agoI know you're just sarcastic trolling, but since your post seems to be generating some discussion without anyone pointing out the technical implications on a technical forum... We already do this, but it's called the MAC address. And it can be used to trace back the piece of hardware to the purchaser. Unfortunately it can't solve the problem for innumerable reasons. For one, it turns out to be pointless to route internet packets or police raids to the location of my computer, knowing it has a unique number (currently the MAC) that can identify it as made in China and sold in Virginia...Better to use the dynamically assigned address (currently IP) of my home router which, with a call to Comcast, can give you my physical address in Hawaii. Of course that physical address might serve any of my neighbors, but then again my computer's MAC also serves any guest in my house that asks nicely to use my computer or anyone tech savy enough to clone it.
- bootload 10y ago"A call is an unknown source, talking about unreliable information, about a location. It is NEVER to be trusted NEVER...." -- Michael A. Wood Jr An unverified call can never to be trusted. Read the whole twitter thread by ex BPD, USMC Retd., Michael A. Wood Jr [0] to understand why. [0] https://twitter.com/MichaelAWoodJr/status/778813281376931840 https://twitter.com/MichaelAWoodJr/status/778813281376931840