FBI Bungles Malware Attempt As Courts Begin To Question Its Legality

from the fbi-as-script-kiddies dept

Back during the summer, we wrote about how the FBI was increasingly using malware to spy on people (though they apparently tried to avoid using it with technically savvy people to avoid having its capabilities “discovered”). However, the Washington Post has more details on how the FBI uses malware in trying to track down someone, based on court documents — though it also notes that at least some courts have balked at such techniques, pointing out that they go way too far and probably violate the 4th Amendment.

The FBI has been able to covertly activate a computer’s camera — without triggering the light that lets users know it is recording — for several years, and has used that technique mainly in terrorism cases or the most serious criminal investigations, said Marcus Thomas, former assistant director of the FBI’s Operational Technology Division in Quantico, now on the advisory board of Subsentio, a firm that helps telecommunications carriers comply with federal wiretap statutes.

The FBI’s technology continues to advance as users move away from traditional computers and become more savvy about disguising their locations and identities. “Because of encryption and because targets are increasingly using mobile devices, law enforcement is realizing that more and more they’re going to have to be on the device — or in the cloud,” Thomas said, referring to remote storage services. “There’s the realization out there that they’re going to have to use these types of tools more and more.”

The ability to remotely activate video feeds was among the issues cited in a case in Houston, where federal magistrate Judge Stephen W. Smith rejected a search warrant request from the FBI in April. In that case, first reported by the Wall Street Journal, Smith ruled that the use of such technology in a bank fraud case was “extremely intrusive” and ran the risk of accidentally capturing information of people not under suspicion of any crime.

Smith also said that a magistrate’s court based in Texas lacked jurisdiction to approve a search of a computer whose location was unknown. He wrote that such surveillance software may violate the Fourth Amendment’s limits on unwarranted searches and seizures.

Yet another federal magistrate judge, in Austin, approved the FBI’s request to conduct a “one-time limited search” — not involving the computer’s camera — by sending surveillance software to the e-mail account of a federal fugitive in December 2012.

Still, the report details how the FBI can insert malware in a variety of ways, and that the malware can often do things like turn on your camera without the light turning on. Most reports of malware concerning turning on cameras in the past still had the light go on. It appears that this is all the more reason for people to tape over their cameras. That said, it could be even worse. If they can turn on your camera remotely, they can almost certainly turn on your microphone remotely also. And, of course, with a microphone there is no light in the first place and you can’t just cover it up. Voila, instant wiretaps beyond just phone calls. Seems extreme, but does anyone doubt that the FBI can do this, and likely does do this?

Of course, the Washington Post report also shows that while the FBI may be able to create and install malware like this, it also seems to make an awful lot of mistakes:

Federal magistrate Judge Kathleen M. Tafoya approved the FBI’s search warrant request on Dec. 11, 2012, nearly five months after the first threatening call from Mo. The order gave the FBI two weeks to attempt to activate surveillance software sent to the texan.slayer@yahoo.com e-mail address. All investigators needed, it seemed, was for Mo to sign on to his account and, almost instantaneously, the software would start reporting information back to Quantico.

The logistical hurdles proved to be even more complex than the legal ones. The first search warrant request botched the Yahoo e-mail address for Mo, mixing up a single letter and prompting the submission of a corrected request. A software update to a program the surveillance software was planning to target, meanwhile, raised fears of a malfunction, forcing the FBI to refashion its malicious software before sending it to Mo’s computer.

The warrant authorizes an “Internet web link” that would download the surveillance software to Mo’s computer when he signed on to his Yahoo account. (Yahoo, when questioned by The Washington Post, issued a statement saying it had no knowledge of the case and did not assist in any way.)

The surveillance software was sent across the Internet on Dec. 14, 2012 — three days after the warrant was issued — but the FBI’s program didn’t function properly, according to a court document submitted in February,

“The program hidden in the link sent to texan.slayer@­yahoo.com never actually executed as designed,” a federal agent reported in a handwritten note to the court.

It looks like this is the typical case of once law enforcement has a tool it’s looking to use it more and more, even as it clearly has not yet worked out the kinks — and there’s been no real chance for a comprehensive look at whether or not the use of such tools is legal, beyond what individual judges are deciding on a case by case basis.

Of course, just the fact that the FBI is able to turn on cameras and microphones without letting someone know has some pretty serious consequences. Jon Schwarz pointed out the basic similarities to 1984 about what happens when the government can magically spy on just about anyone without you knowing about it. Making people live in fear is not what “freedom” is about, now is it?

Raise your hands for those who expect that this technology won’t be abused.

Filed Under: , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “FBI Bungles Malware Attempt As Courts Begin To Question Its Legality”

Subscribe: RSS Leave a comment
Anonymous Coward says:

So how long is this going to be before users on the internet start cutting wires to the microphone and camera? Or go luddite and refuse to buy those sets of hardware that contain such features?

Every action has a reaction. While I’m doing nothing that would actually be of interest to these spying agencies, I’m pissed that I have to take steps to prevent it on hardware that is mine, bought and paid for.

At this point I am considering that maybe being on the internet in plain view may not be such a good idea. The darknet is becoming more and more attractive as the Snowden leaks continue.

Anonymous Coward says:

Re: Re:

The Darknet is not much safer, and makes it much harder to find things. Further, the resulting fragmentation of society in small groups serves the governments purposes, as it becomes much harder for people to communicate ideas and opinions widely, or organise on a large scale.
Love or hate Twitter, Facebook etc, they have a tremendous social reach that can result in effective opposition to politicians. The Darknet is closer to the underground magazines of the 60s and 70s, preaching to the converted, but with very limited reach because they were easy to ridicule and write of as being part of a minority culture.

PlagueSD says:

For me, as far as cameras go, I keep my laptop and tablet off and “closed” so the camera is effectivly blocked. As for my phone, it stays in it’s case which blocks the front camera and I set it flat on the desk…blocking the rear camera. For my computer, when I’m not using my microphone, I turn it off with a “hardware” switch. Since it’s USB, it also unmounts the drivers. If the FBI figures out a way into my network and finds a way to override a physical button, then my computer would make that “ding” sound when you plug a USB device in and I’d be notified anyway.

Unfortunatly, there is nothing I can do about the microphone on my cellphone, so if I was going to do anything illegal, my phone would be staying at home anyway.

Anonymous Coward says:

Re: Re:

so if I was going to do anything illegal, my phone would be staying at home anyway

And if you were to go to a political meeting, well, you would go to a Democratic meeting, or a Republican meeting, and there’s really nothing wrong with taking your phone to one of those meetings. You would be absolutely paranoid to worry about taking your phone to a political party meeting. After all, it’s not like either the Rs or the Ds are dirty communists. You wouldn’t go to a dirty communist meeting with or without your phone now, anyways.

Anonymous Coward says:

Unified Solution to this issue

A spot of tape. (British accent)

Manufacturers should place a LED directly in line to power the camera so that it would not be possible to turn it on without that light being on. The only drawback would be that the camera would no longer function if the LED burned out but all things considered it would be worth it.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...