3 ms·
To play devil's advocate, I think the point is how that "connection to entities on the SDN list" can be arbitrarily determined. Especially when digital channel
by j42 12y ago
To play devil's advocate, I think the point is how that "connection to entities on the SDN list" can be arbitrarily determined. Especially when digital channels are often source-agnostic and you could demonstrate "evidence-backed" relationships between two people who don't even know of each other's existence. In a court of law where technical misinformation abounds, this is not improbable.
Imagine an individual on the SDN list has a fraudulent merchant account, which they use to receive and remit payments while obfuscating origin. These can often be mixed in with legitimate business, especially when the purpose is to avoid suspicious use patterns.
Now, if you've in any way (knowingly or unknowingly) initiated a credit card transaction through such an account, that link is fully documented and "provable."
No DA would press charges on something so baseless, but let's say you were a security researcher of some perceived value in finding the real target... they can, will and have been known to use whatever tactics are available to coerce desired behavior, with no concern to the aftermath; all of the power, with none of the messy aftermath/burden of proof that could affect a 99% conviction rate (ie, a trial).
It's not so much the criminals they are currently seeking to apply this to, but those caught up in the dragnet of a system that doesn't fully understand technology, who are seen as a means to an end.
This is but another tool they can use to exploit these people in the pursuit of that goal.