5 ms·
FBI May Not Have Had Access To Instapaper Hard Drive Data After All
- milkshakes 15y agoso they took the blades but not the drives? what would the point be?
- mrkurt 15y agoA rarely promoted benefit of a SAN!
- mrpollo 15y agoFBI Raid ready?
- skeletonjelly 15y agoRaid 0!
- bkudria 15y agoSo... is this just a case of massive incompetence on the FBI's part? Why would they take the server and not the HDDs?
- bigiain 15y agoI wonder if this is a case of "the law" being so far behind technology that it's completely unworkable? My suspicion is that the FBI had a warrant for somebodies "server", without any consideration given to what "a server" means in terms of physically removable equipment compared to what someone like Marco actually gets when he leases "a server". I'll bet no one tried to explain to the judge signing the warrant that the "server" they wanted to seize was actually a blade card sitting in a chassis with a bunch of other blades (that were _other_ people's "servers" (on which they were running their businesses), and that the "disks" for the servers they wanted to seize were actually virtual disks sitting on another piece of shared hardware... And I wonder what we'll be deploying on when the law catches up with today's standard hosting practices?
- Harkins 15y agoIt sounds to me like the FBI grabbed the entire enclosure that included their target and unrelated DigitalOne customers, then sorted out which they wanted to keep as evidence from there.
- bigiain 15y agoOne assumption is that the FBI took the blade chassis that the target's server lived on (with the Instapaper one as collateral damage) _and_ a NAS box with the target's virtual disks (but a different NAS to the one with the Instapaper disks). It's also possible the FBI just took a rackful of diskless blade servers, and have no evidence at all, target related or not...
- brown9-2 15y agoWe don't know that they didn't seize other hard drives, just not ones used by Instapaper.
- tlrobinson 15y ago...unless they had one of these: http://www.wiebetech.com/products/HotPlug.php http://www.wiebetech.com/products/HotPlug.php
- canistr 15y agoI think he should make an open apology to the FBI. People really have to understand that "the government" isn't after you and that Western society has generally had a really good track record of not abusing their power as compared to most places around the world. The FBI simply doesn't walk into data centers or your homes and try to disrupt things. There are real American people who work in the government and police agencies who do good work. You have to realize that when they do something they shouldn't be doing, they have to answer to the court of law just like you and I with presented evidence. I'm sorry if you disagree with me. But I don't think it's fair to assume corruption on part of the police.
- bgentry 15y agoIt's not about an assumption of corruption. It's about the fact that the FBI took something which they had absolutely no right to take. Whether or not they looked at or did anything with the data on his servers is irrelevant to the fact that they violated constitutional provisions against unreasonable search and seizure.
- canistr 15y agoHe did make it a point in his initial post to claim the passwords were salted. Meaning he wanted to assure his users they were protected from even the FBI. Furthermore, assuming the FBI wanted to seize and investigate his servers for their own nefarious purpose. But remember, let's not confuse direct violation of constitutional rights with mistakes.
- kijinbear 15y agoThe FBI still took Instapaper's blade servers, and that was wrong. I don't think it was intentional at all, but it was certainly careless, and therefore I don't think there's any need for Marco Arment to apologize to the FBI. If anything, the FBI should apologize for their careless seizure of hardware not covered by the warrant.
- ktsmith 15y agoYou are making an assumption that his blade server wasn't covered by the warrant. It's much more likely that the warrant was quite broad and allowed for the FBI to take exactly what they did. This has proven to be the case throughout the years under similar circumstances. I'm more surprised they only took one enclosure.
- eli 15y agoWell, yeah. Did anyone honestly think the FBI intentionally (and perhaps even illegally) took data belonging to Instapaper to.. what? Build profiles on upper middle class Americans' reading habits? I'm definitely not an apologist for the post-9/11 police state, but that's a pretty silly conspiracy theory.
- wmf 15y agoNo, people thought the FBI accidentally took data belonging to Instapaper. You're right that the FBI wouldn't have looked at it anyway since their investigation is not about Instapaper. They can't even afford to investigate crimes that are reported, so they definitely don't have the resources for random Web 2.0 fishing expeditions.
- gojomo 15y agoMy concern would be that if the wrong disks get imaged (either by real bumbling, or erring on the side of over-collecting, or calculated-hoovering-that-could-be-portrayed-as-an-honest-mistake-later), the disk data could then wind up in some broader forensic analysis pipeline, or long-term evidence archive, and then be eventually misused. For example, if they think they may have imaged too much, do they promptly and irreversibly wipe the extra? Or keep it, just in case their assessment of its relation to the current investigation changes again? Could current or future automated criminal-activity-analysis engines be run against every old disk image in their possession, ignoring the details of how/why they were collected?
- wmf 15y agoCould current or future automated criminal-activity-analysis engines be run against every old disk image in their possession... As problematic as that is, it's a drop in the bucket compared to things like Echelon. I think people should be realistic about their paranoia.
- nknight 15y agoEchelon can be guarded against with in-transit crypto. Physical access to systems is far more problematic. Even if the data is nominally encrypted on-disk, the key must be in RAM to make use of the data, rendering it vulnerable at the time of seizure. (You can partially mitigate the risk, but you can't make it 100%, and it's very likely you'll have issues with cost, performance, and user-friendliness along the way.)