12 ms·
German Chaos Computer Club analyzes and releases government malware
From the press release: "The largest European hacker club, "Chaos Computer Club" (CCC), has reverse engineered and analyzed a "lawful interception" malware program used by German police forces. It has been found in the wild and submitted to the CCC anonymously. The malware can not only siphon away intimate data but also offers a remote control or backdoor functionality for uploading and executing arbitrary other programs. Significant design and implementation flaws make all of the functionality available to anyone on the internet."
- scrrr 15y agoAnd it's things like that that will make even more people vote the Pirate Party. Luckily the German public is by and large opposed to surveillance. (for historical reasons)
- cf0ed2aa-bdf5 15y agoThe latest surveys show the Pirate Party at about 8% while the FDP (the smaller one of the governing parties which got 14.6% in the state elections in 2011) is at 3% http://www.infratest-dimap.de/umfragen-analysen/bundesweit/sonntagsfrage/ http://www.infratest-dimap.de/umfragen-analysen/bundesweit/s... However I don't really think that the German public is strongly opposed to surveillance, especially since the media tried making a big deal out of the few incidences where some assholes decided to beat up people on the Munich and Berlin subways lately.
- rmoriz 15y agoThe latest survey by Emnid released today shows 9% for Piratenpartei (PIRATEN): http://www.wahlrecht.de/umfragen/index.htm http://www.wahlrecht.de/umfragen/index.htm
- rickmb 15y agoOpposed for historical reasons? The fact is that the citizens of Germany, and most other Western nations formerly known as the "free world" are today under more intense surveillance than the Stasi could have ever dreamed of. The German public in general is just mildly less apathetic about this as the rest of us. The only thing that makes a real difference in Germany is the constitutional court, that appears to suffer less from political influences than the highest courts in most other nations, and actually takes its task of protecting citizens constitutional rights very seriously.
- nolok 15y agoI don't fully agree with you about the political influences, at least not in Europe. Most of the high constitutional courts tends to side with privacy and protection of it and of the citizens most of the time (at least in several cases I've seen in Spain, France, Netherlands and Germany). The big issue is that nowadays our government are much better at hiding how much spying they do; most of the crazy abuses are never ever challenged in court because nobody ever bother or notice. Especially with the relatively good European laws on the matter, most of stuff like this would lose in court but it never gets to that point because 1 - a lot of people don't want to spend the time and effort to push it to that point, 2 - with modern spying being so well hidden, people don't even notice their rights are being abused, so what would they sue for.
- Nitramp 15y ago> [western world citizens] are today under more intense surveillance than the Stasi could have ever dreamed of [...] I keep hearing that, and I'm sorry, but it's pure sensationalist bullshit. At the end, the Stasi employed one secret informer per ~90 citizens (!), and one official employee per ~180 citizens. That was the (proportionally) biggest secret service that ever existed. The Stasi kept tabs on more or less anything happening in the Eastern German society, down to what individual people had for lunch, and had infiltrated every organisation within its reach. I can understand disagreement with things like this Bundestrojaner. But spouting ridiculous, sensationalist comparisons like these only harms a legitimate issue by painting its adherents as raving zealots.
- 0x12 15y agoI think part of this is because nowadays it requires far fewer people to keep track of the population than it did back then. Just mining Facebook and twitter will tell you what lots of people had for lunch...
- fl3tch 15y agoAdvertising companies know everything you do online. They have "behavioral profiles" far more detailed than anything the Stasi had. We are in fact under much more surveillance, but the problem is not the government.
- Uchikoma 15y agoOpposed? You might live in a different Germany than I do. The German public is mostly law and order.
- Udo 15y agoExactly. From where I'm standing it looks like "the public" is nothing short of obsessive when it comes to compliance with rules. Any rules.
- mrich 15y agoQuality analysis by the CCC. I'm glad we have such an organization in Germany.
- xerxes2001 15y agoSo much win. I am really thankful that the CCC has such a strong standing in Germany. I am looking forward to the news tomorrow :)
- FrojoS 15y agoNo reason to wait, its already the FAZ top story [1]. Same with the Die Zeit [2]. Interestingly Der Spiegel has apparently not picked up the story yet. [1] http://www.faz.net/aktuell/chaos-computer-club-der-deutsche-staatstrojaner-wurde-geknackt-11486538.html http://www.faz.net/aktuell/chaos-computer-club-der-deutsche-... [2]
- perlgeek 15y agoDer Spiegel has now picked it up [1], but of course some people driving around in circles are more important, so it's not in the top spot on the front page :-) [1] http://www.spiegel.de/netzwelt/netzpolitik/0,1518,790756,00.html http://www.spiegel.de/netzwelt/netzpolitik/0,1518,790756,00....
- eis 15y agoI wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.
- matthiasjakel 15y agothere was a big public discussion about the government trojaner in germany. they government also has to report how often it is used. so you can be sure thats the work of some government part.
- eis 15y agoI can't follow your logic. I know about the discussion and the statistic reports but how does that proof that this every-day-trojan actually is controlled by the government?
- DasIch 15y agoThe first paragraph: > Dem Chaos Computer Club (CCC) wurde Schadsoftware zugespielt, deren Besitzer begründeten Anlaß zu der Vermutung hatten, daß es sich möglicherweise um einen „Bundestrojaner“ handeln könnte. Einen dieser Trojaner und dessen Funktionen beschreibt dieses Dokument, die anderen Versionen werden teilweise vergleichend hinzugezogen. Translates to: > The Chaos Computer Club (CCC) received malware, whose owners who had reason to believe that it could possibly be the "Federal Trojan". One of these and its function is described by this document, other versions have been used for comparisons. I guess they won't publish any more information to protect their sources.
- eis 15y agoYea. So they got it from people who believe it might be the federal trojan. No proof. I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.
- canistr 15y agoI think it's also possible that some of those safeguard provisions were left out of the software so that in case the malware was detected, it could have been attributed to standard hacker groups as opposed to German government organizations who play within a specific set of rules and regulations. Obviously, this plan failed and it has been identified as government-sponsored malware.
- DasIch 15y agoA standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.
- canistr 15y agoObviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.
- DasIch 15y agoThere is a significant difference between identification of a botnet and listening into communication, controlling it or even taking it down. Especially the latter can be impossible to do legally if you don't manage to shut down however is controlling it. In any case this doesn't matter because the government would have to put these safe guards in place. They cannot not implement them simply because someone might suspect the government behind it if it is detected.
- rhizome 15y agoAfterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities. They rarely are.
- DasIch 15y agoThe press release and the analysis are unfortunately poorly written and make it appear as if a couple of overeager teenagers wrote this, although their conclusion is accurate given the information given in the analysis. Releasing the binaries alone to back up such a statement might be good enough for the hacker community but if you want to persuade the public you need to be more professional in your choice of words. Even though this is a great achievement and I hope that this will have significant impact.
- mikkohypponen 15y agoOur take on this case: http://www.f-secure.com/weblog/archives/00002249.html http://www.f-secure.com/weblog/archives/00002249.html Also, we decided to detect it.
- stfu 15y ago> Also, we decided to detect it. How generous...
- 46Bit 15y agoUnfortunately as time goes on this might be not as free-will a decision. The right of law enforcement to breach our computers for the 'good of the public' will probably only get worse.
- wnight 15y agoIt's already there for many unsuspecting users. You have to root your iPhone to begin to investigate what might be spying, let alone stopping it, and Apple is doing their best to make the phone unrootable. Soon it won't be (practically) possible. And not just Apple, they're just one of the first with effective lock-in, and market-share. Soon having programming/debugging tools could be ample evidence of intent to criminally (the only way) access a computing device.
- mcantelon 15y agoThe ability of commercial anti-virus vendors to decide what end users are protected against is a good argument for open source anti-virus that crowdsources detection patterns.
- stfu 15y agoThis is a very good point. I have always been a bit sceptically on the anti-virus companies. The market looks a bit odd to me - different from many other software markets. A lot of regional market domination. Norton in the US, Kaspersky in the RU or ANTIVIR in GER. Looks almost like certain nations prefer having their "own" anti-virus company structures in place. Are there any serious anti-virus open source alternatives available?
- hukl 15y agoF-Secure will detect the malware according to their blog post: http://www.f-secure.com/weblog/archives/00002249.html http://www.f-secure.com/weblog/archives/00002249.html
- kstenerud 15y agoThe wording of their "backdoor policy" is ambiguous: http://www.f-secure.com/virus-info/bdtp.shtml http://www.f-secure.com/virus-info/bdtp.shtml "F-Secure Corporation would like to make known that we will not leave such backdoors to our F-Secure Anti-Virus products, regardless of the source of such tools. We have to draw a line with every sample we get regarding whether to detect it or not. This decision-making is influenced only by technical factors, and nothing else, but within the applicable laws and regulations, in our case meaning EU laws." So they won't leave explicit backdoors in their software, but their decision on whether or not to detect a particular malware is influenced by EU law.
- wnight 15y agoWhat about, then, when EU law requires them to leave an explicit backdoor? Transparency is a top priority, otherwise we're approaching a high-tech East Germany. The group I least trust snooping on the world is the government (ie, above the law).
- Joeboy 15y agoProbably a stupid question, but does this target Windows?
- venti 15y agoYes, the malware described in the CCC's document is a Windows DLL file.
- Luyt 15y agoYes. And why? Probably because the majority of the personal computers of German citizens use Windows as their operating system.
- sunchild 15y agoSo, if you are in the 10% of Mac users, you are of no interest to the authorities? Quite pragmatic, I suppose.
- DasIch 15y agoIt targets Win32.
- adimitrov 15y agoThis is actually important to note: the software depends on an unsigned 32 bit kernel module. If it were 64 bit, it would have to be signed to function, so this particular piece of malware will only work on Windows 32. That said, there might be Bundestrojaners for 64-bit Windows. Or even entirely different operating systems.
- mrpixel 15y agoThis is all a steaming pile of horseshit. It won't pass proper journalism.
- Uchikoma 15y agoGerman newspaper, clueless as ever, show a MacBook http://www.faz.net/polopoly_fs/1.1486520.1318104289!/image/3251345485.jpg_gen/derivatives/default/3251345485.jpg http://www.faz.net/polopoly_fs/1.1486520.1318104289!/image/3...
- Knack 15y agoUnfortunately, it is, it was and it will always be necessary to spy on people who are suspicious of committing a crime. Proper surveillance has saved uncountable lives. Years ago, police was using cameras and directional microphones. But as technology evolves, the methods to prevent crime have to envolve as well. To not allow the police to use the same technology as the criminals would actually endanger stability of the society. If you don't agree, have a look at what happened and happens in Africa all the time as an extreme example to what happens it mankind lives without proper regulations. The key point that needs to be discussed is not whether this kind of technology should be used, it's how and who is allowed to use it. Countries need a proper separation of powers. And the use of surveillance should only under any circumstances be approved by the independed jurisdiction. Personally, if you can get one pedophile or terrorist I wouldn't care if the whole police of Germany would share my Jena Jameson collection.
- Confusion 15y agoProper surveillance has saved uncountable lives. I hate to do this, but: citation needed. All the camera's in London have done nothing to reduce crime or increase the amount of crimes solved.
- anon1385 15y agoI hate to do this, but I downvoted you because you demand evidence for one sweeping generalisation, and then proceed in the very next sentence to make a broad sweeping generalisation without providing any evidence. I'm not saying I disagree with you, but if you are going to be confrontational then at least try not to be so blatantly hypocritical.
- Confusion 15y agoWell, I thought that fact was well known. It has been extensively covered by the media. [1][2][3] [1] http://www.schneier.com/blog/archives/2008/05/londons_cameras_1.html http://www.schneier.com/blog/archives/2008/05/londons_camera... [2] http://articles.cnn.com/2010-02-25/opinion/schneier.security.cameras_1_cameras-cctv-footage-police-officer?_s=PM:OPINION http://articles.cnn.com/2010-02-25/opinion/schneier.security... [3] http://www.google.nl/search?q=london+cameras+reduce+crime http://www.google.nl/search?q=london+cameras+reduce+crime
- adulau 15y agoThe title is a bit misleading. It seems this is a not a governmental malware to install on each citizen's PC. It's more a software installed on request by a judge for specific criminal cases. Looking a bit in IDA, the software is quite versatile and don't use any obfuscation techniques regularly seen in other malware. I suppose this is more and more used by the police because of the use of encryption on consumer products like Skype and other communication tools.
- kahawe 15y agoThere is one more detail hinting that this could indeed be the "Bundestrojaner". faz[1] cites a leaked offer from a German company to the authorities that, according to faz, contains exactly the characteristics found by the CCC. Even renting an "intermediate" communications server in the USA is mentioned. The especially striking thing about this trojan is the functionality to load additional modules and go far, far beyond simple wiring tapping of (otherwise encrypted) communications (at the source) - which was the only thing that was actually approved (and the reason for this software in the first place) and it was stated clearly that the software must NOT go beyond wire tapping and technical precautions have to be taken to prevent the software from doing anything else. Furthermore CCC's analysis showed that the part of loading additional code was actually hidden, obfuscated and spread out amongst the machine code - whereas the rest of the code was very straight forward, no obfuscations. So clearly whoever developed that thing was very aware of how illegal and unlawful that functionality is. [1] (in German) http://www.faz.net/aktuell/feuilleton/ein-amtlicher-trojaner-anatomie-eines-digitalen-ungeziefers-11486473.html http://www.faz.net/aktuell/feuilleton/ein-amtlicher-trojaner...
- raphman 15y agoThe chancellor's press secretary denies that this malware is the Bundestrojaner, claiming that it has never been used by the BKA, the federal crime investigation department [1]. From the wording of the tweet I assume that instead some LKA (crime investigation departments on the state level) had been using the malware. [1] http://twitter.com/#!/RegSprecher/status/123056930888491008 http://twitter.com/#!/RegSprecher/status/123056930888491008
- biafra 15y agoThis might be considered proof that the found program was indeed used by the LKA Bayern. http://ijure.org/wp/archives/727 http://ijure.org/wp/archives/727 (in german)