6 ms·
> The documents are written on simple copy paper and lack any kind of security features. Wait, sorry, sorry, sorry, hold up, full stop...could you repeat that
by usrbinbash 3y ago
> The documents are written on simple copy paper and lack any kind of security features.
Wait, sorry, sorry, sorry, hold up, full stop...could you repeat that again?
These orders arrive AS GODDAMN PAPER PRINTOUTS?!?
Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key?
- Schiendelman 3y agoYes, and until we pass real consequences for data breaches - protections for individuals - none of this will change.
- bdavbdav 3y agoI think their point is that the fault here is on the system that requires people comply with non verifiable warrants, as opposed to the people handing over the data.
- esaym 3y agoWhat, gmail is better?
- eqvinox 3y ago> Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, Yes. Or a PDF attachment on an e-mail, possibly scanned from something that was printed a few minutes earlier because someone had to sign it with a pen. > trivially verify with the ordering entities public key You're underestimating the complexity of establishing a PKI infrastructure to handle federal, state and local authorities, signalling which keys have what exact authority, revoking compromised keys, … and then doing tech support for some redneck judge that owns more guns than electronic devices.
- hnfong 3y agoHaving a cert from a validated *.gov CA doesn’t seem that complicated, or at least, should be “just as complicated” as setting up properly TLs certs. Getting the tech adopted might be difficult (like you say some judges may not see the point of it) but the PKI doesn’t have to be super complicated… Having different authorities provide signatures for different types of documents may or may not be needed, in theory it is more secure, but just checking the domain name suffix should be a good start. And every tech literate person has a general idea how to tell “valid” domain names from phishing sites, so the scheme translates well
- ben_w 3y ago> Having a cert from a validated *.gov CA doesn’t seem that complicated, or at least, should be “just as complicated” as setting up properly TLs certs. You're not wrong, but you are overestimating the tech skill level of the average non techie. I'm travelling right now, and a surprising fraction of restaurant websites here aren't https.
- hnfong 3y agoYes, but we're talking about the judiciary here, not restaurants... Surely they'd have a minimal IT department...
- ben_w 3y agoYou might hope so, but I have no reason to think they are magically more ept than anyone else. I don't know much about the American ones, but the British ones are complaining about the ceilings falling down due to chronic underfunding of basic maintenance; getting the digital infrastructure right is probably lower down their wish list than ceilings that don't collapse: https://www.standard.co.uk/news/london/courtroom-shut-ceiling-collapse-inner-london-crown-court-repairs-b1109973.html https://www.standard.co.uk/news/london/courtroom-shut-ceilin...
- kotaKat 3y agoI pointed this out in a previous post elsewhere but there are places out there with little to no manpower, period. https://www.wwnytv.com/2023/11/15/st-lawrence-county-struggling-find-judges/ https://www.wwnytv.com/2023/11/15/st-lawrence-county-struggl... A single judge, and likely, a single court clerk, are the only people in many, many rural courthouses. And sometimes, that judge themselves might have been able to get into the job with one vote as a joke. Neither of them could have any IT support, just a couple laptops from the county if that to help them out. These courts out there run a lot more on paper and fax and occasionally normal email (https is 'secure email' right? /s). They'd have zero clue what a CA even is, other than the Golden State.
- hn_throwaway_99 3y ago> Am I to understand that official orders that instruct telco providers to provide the private communication data of people, are transmitted as smushes of pigment on thin pieces of wood-paste, instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key? Was honestly having a difficult time determining (a) if this was sarcasm or (b) you just have no idea of the technical competence of many of these jurisdictions, not to mention the complexity of managing this type of public key verification system for the number of jurisdictions involved.
- autoexec 3y agoAt one place I worked for we used to get them via fax! That said, you could call and verify that the person the document claimed to send it actually did.
- vintermann 3y ago> instead of a digitally signed file that the recipient can trivially verify with the ordering entities public key? They wouldn't want that, because they don't want it to be easy to prove that they demanded surrender either.
- wruza 3y agoIt’s amusing how much HN expects from “the outer world”. Companies can adopt new tech in 1-2 years. Industries have around 5-10 years inertia. Bureaucracies like courts still live in the past millenia. You should be happy that they are using email. The best security measure they will implement after this article going wide is something like “only emails from @<domain> are valid, but we’ll destroy you anyway in case a judge mistakenly sends you an order from his own gmail”.
- mulmen 3y ago> Bureaucracies like courts still live in the past millenia. You should be happy that they are using email. This is a feature. We don't want courts to "move fast" because the consequence of breaking is far more severe than losing a few files on Google Drive.
- fallingknife 3y agoIf you don't move fast with new tech, you are broken. E.g. the article in this post.
- respondo2134 3y agoThe implied assumption here is that everything needs to adopt new tech. Lots of things are essentially "as perfect as we're going to get them" and everything new is a very marginal improvement or a big step backwards.
- mulmen 3y agoThe only thing broken is Verizon’s lawyer’s phone.
- wayfinder 3y agoI mean digital signatures have really only been a thing for like 20 years, and barely because people only started caring about it more in the past 10. While the US has been around for nearly 250 years. And truthfully, despite a highly technical crowd, how many of y’all have actually ever sent or received a digitally signed email? If you’ve tried, you know why no one ever does it.
- csunbird 3y agoOh wow! In my country, legal documents like this arrive with a QR code or confirmation code attached that can be used to verify legitimacy of the document on the official e-government internet site.
- deaddodo 3y agoEvery valid warrant has a verification authority contact. You are allowed to withhold access until verification can be made, and generally it can be done in 5-30mins. I worked in a data center once, and we would have FBI contacts that would come in regularly to access criminal data (CP, terrorist communique, heavy piracy, etc). We would verify the warrant before secure entry+accompany them to the specific requested entity. I know procedures are similar + even more stringent for the medical field. Things get even more complex for small local authorities, but the idea that "just having a slip of paper" is enough is ridiculous; unless the person accepting the request is dumb/lazy/uninformed/undertrained/etc, as in any social engineering feat (in your case, the responsible person decides to not bother with the QR because their phone connection is bad, it takes too long, etc; for example).
- PrimeMcFly 3y ago> You are allowed to withhold access until verification can be made, and generally it can be done in 5-30mins. So it's not like on TV where if they have the paper they can just show it to you and barge past you by force? For arrest warrants that makes sense, but they portray search warrants the same way.
- pixl97 3y agoSearch warrants can be more aggressive if they believe the searched are going to be oppositional and attempt to destroy evidence. Now for a typical business where law enforcement is going after someone else's data it's more laid back as the most law enforcement expects is the company to get on the phone with a lawyer to see if they should comply type thing.
- 3y ago
- multjoy 3y agoThe much-derided SnOOPEr'S CHarteR in the UK (which actually formalised and regulated stuff that was already being done) means that while it's not a judge signing off warrants for comms data, it involves police gatekeepers (and believe me, getting a warrant to blow someone's door off is a piece of piss compared to writing up a comms data application), who then send it to an independent decision making body who then return it to the police who then upload the request to CSP systems using a pre-agreed portal with appropriate authentication. This touchstone of 'judicial oversight' is frequently nonsense. You can't tell me that every judge who has to give a warrant for a DUI blood draw at 3am in smalltown US is giving the matter any kind of scrutiny, nor that that judge has any legal or judicial experience at all.
- yladiz 3y agoThe point of sending a letter, compared to an email, isn’t only about proving who issued the subpoena, but also being able to prove it was received. You can’t really prove an email was received, but you can send a verified letter proving it was delivered.