4 ms·
Can someone familiar with the situation explain how the employers know they used Bylock before the police raid?
by codewithcheese 9y ago
Can someone familiar with the situation explain how the employers know they used Bylock before the police raid?
- shultays 9y agoIt says in the article She knew the arrest was coming. She'd already lost her job, because traces of the app known as Bylock were found on her phone.
- codewithcheese 9y agoYes but whats the process? Were traces of the app found by her employer? Are employers searching employees phones?
- shultays 9y agoI am assuming data is shared by mobile operators to government. And then they fired everyone on that list and works at the government
- laurent123456 9y ago> Were traces of the app found by her employer? Probably that's just the journalist words as I don't think they found or even looked for "traces of the app" on the phone. Most likely the government got a log of the DNS lookups from the ISP and made their arrests based on this.
- gazorpazorpaway 9y agoAs others have commented, it was just a matter of the ISP identifying all clients doing DNS lookups or connecting to the Bylock domain. The government have complete control of all ISPs and mobile network operators in Turkey. They don't own them, but you can't give people Internet access without joining the government censorship/logging program. As she was a teacher she would be employed by the government, and they just fire everyone employed in the government automatically when their names show up on the blacklist. I suspected firing of family members and friends that are connected to falsely accused person is done manually. Also it doesn't really matter if the person is employed by the government or not. No employer would dare to keep anyone that is blacklisted as the employer would probably be accused themselves of helping a terrorist if they kept them. Plus, obviously, most big corps in Turkey are run by Erdoğans friends and family directly and indirectly.
- aaron695 9y ago"According to the daily, MİT has completed most of its works regarding ByLock and determined all the users in the server." "The Department of Anti-Smuggling and Organized Crime transferred the list to its own database, with police in provinces able to check the list with a password given to them. Only one or two officials in the provinces are able to check the names in the list by entering the suspected person’s Turkish identity number or phone number. In the checks done in the provinces, authorities are initially attempting to find who used the phones with ByLock. If the person who bought the phone line and the one who used it is different, then legal proceedings are conducted against the latter." http://www.hurriyetdailynews.com/turkeys-intel-agency-sends-list-of-122000-bylock-users-to-prosecutors-office-110317 http://www.hurriyetdailynews.com/turkeys-intel-agency-sends-... "Beşikçi said it was due to a single line of code, which created a window "one pixel high, one pixel wide" — essentially invisible to the human eye — to Bylock.net. Hypothetically, people could be accused of accessing the site without having knowingly viewed it." Sounds like the app touched base with a unique server. Then it's a simple lookup of users at the ISP level. Then inform government agencies / employers if their employees are on the list. To me both articles imply the trace evidence on the phone is that it accessed something at some point in time rather than forensics on the phone. [edit] I can't find any trace of the "bylock.net" in the Bylock apk source code. Someone else might want to look but something is missing. It'd be nice to know the exact line, if it's obscured that'd make it interesting.