Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A five-year jail term has been handed to a US man found downloading and watching child abuse imagery at work.
Investigators at the Seattle branch of the Social Security Administration where he worked were apparently alerted to his activities when his company computer was hit by a malware attack.
Thomas J. Barrett, 50, of Lynnwood, WA, seems to have been seriously addicted to grotesque photos and videos of underage girls being assaulted, with over 3,700 items found on his system.
In between browsing for fresh material for his collection, he also researched possible penalties for such activities, and alternated between porn and work time to keep his habits from his colleagues, indicating at least some awareness of just how wrong his behaviour was.
On one of his trawls through the seedier side of the web, a malware alert brought administrators' attention to what was going on, and subsequent investigations included setting up a spy camera monitoring his workstation.
The investigators were then exposed to the unedifying sight of Barrett "fondling himself" at his desk. He was arrested in January, but remains free on bail until his sentence comes into force.
Barrett's defense team claimed his time in the US Army sparked his addiction, with a visit to Europe opening an "evil door" in his delicate mind.
This is the second time in as many weeks that we've reported on malware playing a significant part in bringing paedophiles to book.
Before anyone gets the wrong idea, there's nothing noble about being a malware author or purveyor; it's still a nasty and criminal business, just perhaps not quite as nasty as these chaps.
Follow @VirusBtn
Follow @NakedSecurity
Image of man surfing web courtesy of Shutterstock.
Child porn sentence for Wickford hacker (From Echo) Jump to main content News Sport Weather forecast Mobile site E-Newsletters News feed Find us on Twitter@Essex_Echo
Follow us
Find us on FacebookEcho
Like us on Facebook
Site map Register Log in Child porn sentence for Wickford hacker (From Echo)
Get involved: send your pictures, video, news and views by texting ECHONEWS to 80360, or email us »
Search: NewsSportLeisureLocal InfoEventsAnnouncementsPublic NoticesJobs with usAdvertiseClick2findBuy & SellDatingCarsHomesJobsLocal NewsNationalVideoLettersTopicsArchive Echo » News » News RSS Feed Send your news, pictures & videos Child porn sentence for Wickford hacker 8:13am Wednesday 12th June 2013 in News Ryan Cleary
A member of the computer hacking group LulzSec is due to be sentenced today for possessing indecent images relating to extreme child pornography.
Ryan Cleary, 21, of Wickford, known as ViraL, appeared in court last month where he admitted hacking and launching cyber attacks on a range of organisations including the CIA and the Serious Organised Crime Agency as part of his work with the "hacktivist" group.
He was jailed for a total of two years and eight months.
But Cleary, who has Asperger's, also admitted possessing indecent images relating to extreme child pornography, which were found on his hard drive.
He is due to be sentenced for this at London's Southwark Crown Court today.
His barrister, John Cooper QC, told the court in May how Cleary is a ''totally obsessed, compulsive individual'' who became fixated with computers after being sent to boarding school aged 11.
By the time of his arrest he was ''reclusive'', living in his bedroom.
Cleary is not ''a career sexual pervert'', Mr Cooper said, linking the 172 indecent images, downloaded in one session, to his Asperger's and computer obsession.
Fellow LulzSec members Ryan Ackroyd, Jake Davis and Mustafa Al-Bassam were handed various sentences last month for their roles in the hacking.
Email Print this page Email Print this page click2find Block list Jobs
Newsquest (Essex) Ltd, 58 Church Street, Weybridge, Surrey. KT13 8DP|3102787|Registered in England & Wales About cookies
We want you to enjoy your visit to our website. That's why we use cookies to enhance your experience. By staying on our website you agree to our use of cookies. Find out more about the cookies we use.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
In a case that could have far-reaching implications for compelling criminal suspects to decrypt digital storage devices, a judge on Tuesday stayed [PDF, posted courtesy of Wired] - temporarily suspended - a previous order that would have forced him to decrypt hard drives suspected of containing child pornography.
The hard drives were seized from computer scientist Jeffrey Feldman, from the US state of Wisconsin.
The government has previously said in court papers that even without forcing Feldman to decrypt storage devices found in his house, they have managed to glean incriminating data from unencrypted portions of the storage.
The government says it found a large number of user-created links that "strongly suggest, often in graphic terms," the presence of encrypted abuse images on Feldman's hardware.
The investigators also found a peer-to-peer sharing utility that contained logs of 1,009 videos that Feldman had allegedly received, distributed and stored - most of the filenames being "unambiguously indicative" of child porn.
At question is Feldman's right, under the Fifth Amendment, to be shielded from self-incrimination.
Magistrate William Callahan Jr. of Wisconsin wrote in April that this is "a close call," but that if Feldman used a password to decrypt a storage device, it would be, more or less, the same as telling the government "something it does not already know" and would be tantamount to self-incrimination.
Callahan subsequently viewed new evidence that caused him to reconsider.
According to the order [PDF], the Federal Bureau of Investigations (FBI) had managed, given "substantial resources," to decrypt and access one single hard drive.
On that decrypted segment of Feldman's far more extensive storage system, the FBI says it found "an intricate electronic folder structure comprised of approximately 6,712 folders and subfolders," in which agents found 707,307 files, including "numerous files which constitute child pornography."
Writing [PDF] in late May, Callahan ordered Feldman to either enter the passwords without being observed by law enforcement or government counsel, or provide an unencrypted copy of the data.
However, a new federal judge, Rudolph Randa, has stayed that decision. Ars Technica's Cyrus Farivar writes that Callahan was taken off the case, not being an "Article III Judge" and lacking the authority to grant the order in the first place.
The latest wrinkle in Feldman's case doesn't do much but postpone the question of whether compelling somebody to decrypt their electronic storage device is a violation of Fifth Amendment rights.
But if the government already has enough evidence to convict Feldman of possessing child abuse images, is it necessary to compel decryption?
We'll keep watching this space. Regardless of this case or others like it, it's important to fight the erosion of rights such as those granted by the Fifth Amendment.
Follow @LisaVaas Follow @NakedSecurity
Image of child and hard drive courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
A US federal magistrate has refused to order a Wisconsin computer scientist and child abuse image suspect, Jeffrey Feldman, to decrypt the hard drives the government seized from him.
The rationale of Magistrate William Callahan Jr. of Wisconsin: the Fifth Amendment to the US Constitution shields citizens from being compelled to self-incriminate.
Callahan wrote [PDF, posted courtesy of Wired] that, unlike in similar cases, where the government has compelled people to unlock the encrypted portions of their hard drives, in this case, Feldman hasn't admitted that he has access and control of the hardware.
This is in spite of the many storage devices in question having been found in his house, where he's lived alone for 15 years.
Callahan's thinking:
This is a close call, but I conclude that Feldman’s act of production, which would necessarily require his using a password of some type to decrypt the storage device, would be tantamount to telling the government something it does not already know with 'reasonably particularity' - namely, that Feldman has personal access to and control over the encrypted storage devices. Accordingly, in my opinion, Fifth Amendment protection is available to Feldman. Stated another way, ordering Feldman to decrypt the storage devices would be in violation of his Fifth Amendment right against compelled self-incrimination.
The government, trying to convince the courts to force the suspect to comply, had said [PDF, again posted courtesy of Wired] that if Feldman doesn't unlock the drives, the case could suck up even more resources than it has already, and investigators might even damage the hardware.
From the court papers:
The United States, the FBI in particular, has already expended substantial resources in the effort to break the encryption preventing it from accessing the information as ordered by the Search Warrant and more will be required if the encryption must be broken manually. Members of the FBI's Computer Analysis Response Team (CART) have spent more than ten weeks decrypting Mr. Feldman's storage devices.
In fact, the prosecutors warn, encryption is getting both tougher to crack and used more widely, painting "a grim picture of the future for law enforcement officers" as they seek to carry out court-mandated search warrants.
Even if you're a privacy absolutist, even if you believe that the FBI and other law enforcement agencies in the US have gotten a bit too cozy with surveillance of the nation's citizenry and warrantless searches, you've got to have a bit of sympathy for law enforcement here if you believe (and I hope that you all do) that putting child abuse image collectors and creators out of business is a vital job.
The government said in its court papers that what they did manage to glean from unencrypted portions of Feldman's computer storage showed a large number of user-created links that "strongly suggest, often in graphic terms," the presence of encrypted abuse images on Feldman's hardware.
The investigators also found a peer-to-peer sharing utility that contained logs of 1,009 videos that Feldman had allegedly received, distributed and stored - most of the filenames being "unambiguously indicative" of child porn.
If your first inclination is to curse the judge, check that impulse. This is about far more than this one alleged child abuse image collector.
Hanni Fakhoury, a staff attorney with the Electronic Frontier Foundation, told Wired that the decision is important beyond whether it gums up a child abuse prosecution, because it's a core issue in regards to government overreach:
This isn’t just about child porn. It’s about anything on your computer that prosecutors or government officials may want.
It's hard to get enthused about a court decision that hampers law enforcement as they work hard to fight child abuse.
But curbing law enforcement's already substantial power, particularly when it comes to power that would contradict our Constitutionally guaranteed rights, is what a properly functioning judicial system should be doing.
Add this to a recent judicial decision to deny the FBI the right to plant spyware on a bank fraud suspect's computer, and you have to come to the conclusion that US courts certainly are capable of gleaning the subtleties of where electronic information, surveillance and our rights intersect.
Should we keep watching this space? Oh, yes.
Just as encryption gets stronger and technology advances, so is the legal landscape every shifting.
That shifting landscape is a very good reason to encrypt your hard drive, though of course device loss and hacking, as always, are right up there to bolster the encryption argument.
Follow @LisaVaas Follow @NakedSecurity
Images of Person behind glass and locked computer courtesy of Shutterstock.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
SophosLabs has received a number of disturbing reports from German computer users about a ransomware malware attack that is locking computer screens, and demanding payment of a fine.
Like other ransomware attacks, a message appears claiming to come from the police that says that evidence gathered proves that the computer has been used to view pornography involving minors.
Unlike most attacks, however, the warning message also includes images of the purported sexual abuse of children, along with the minors' names, dates of birth and location.
Some of the images claim to be of girls as young as 13 years old. Obviously, we are unable to confirm if the people pictured in the images are as young as the bogus police warning message claims.
However old the people in the pictures really are (and some of them *do* look under-age), it's easy to imagine how people who see what appears to be an official police warning, alleging that child porn websites have been accessed, and finding that their computer has been locked, could easily be scared into paying a fine to the cybercriminals behind this attack.
Naturally we have informed the authorities - including our colleagues at the Internet Watch Foundation - so they can work with their partners worldwide, and we have censored the images used in this article.
SophosLabs hasn't received any reports of sightings of the ransomware from UK computer users, but if the webpage is visited from a UK IP address the message adjusts itself to pretend to come from the Metropolitan Police rather than the Bundeskriminalamt:
Your Personal Computer has been blocked
The work of your computer has been suspended on the grounds of unauthorised cyberactivity
All the illegal actions that you performed on this computer were recorded and classified in the Police Database. This also includes photos and videos that were taken by your web camera for further identification. You've been charged with viewing pornography that involves minors.
The computer's IP address and internet service provider is also displayed, and in the corner of the screen can be seen a live video image from the computer's webcam.
There have been a spate of attacks in the last year, where computer users have discovered their computers frozen by messages purporting to come from the police, and claiming to have gathered webcam evidence of who was using the computer at the time of the alleged offence.
Perhaps the most famous example of ransomware malware is Reveton, described by Paul Ducklin in the following great video:
Spanish police arrested more than a dozen members of a multi-national Reveton gang earlier this year.
Whether the latest ransomware impacting German computer users is related to Reveton is currently unclear, and malware experts at SophosLabs are continuing to investigate the attack. Sophos products have already been updated to block access to the offending website where the messages are displayed.
How to report online child abuse If you have information about online child abuse that you wish to report to the authorities, visit the websites of the Virtual Global Taskforce, CEOP (the Child Exploitation and Online Protection Centre) and the IWF (Internet Watch Foundation) which provide a reporting mechanism.
Follow @gcluley
Thanks to Dirk Kollberg and Paul Baccas of SophosLabs for their assistance with this article.
Tags: BKA, Bundeskriminalamt, child abuse, Germany, Internet Watch Foundation, iwf, Malware, Metropolitan Police, ransomware, reveton, sexual abuse, UK
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Just because a neighbor saw titles for child abuse image files on an unsecured wireless network doesn't justify the law barging in and searching for the images, ruled an Oregon judge in the US.
The decision reversed the judge's previous conviction of John Henry Ahrndt, who, it turns out, was already a convicted sex offender.
In a ruling filed January 17, Senior District Judge Garr M. King said that Ahrndt's Fourth Amendment rights ensuring protection against unreasonable searches had been blown when a deputy got the go-ahead from his supervisor and clicked on one of the titles:
There is no evidence [Ahrndt] intentionally enabled sharing of his files over his wireless network, and there is no evidence he knew or should have known that others could access his files by connecting to his wireless network. [The deputy's] action of clicking on the image in [the neighbor's] iTunes directory to open the image violated Ahrndt’s Fourth Amendment rights.
Here's how the files were discovered in the first place: In February 2007, one of Ahrndt's neighbors - a woman identified as "JH" in court documents - got onto his unsecured wireless network when her own network went down.
Ahrndt's network was coming off a Belkin 54G router with a default setting of "no security".
JH opened up iTunes and noticed another user's library, called "Dad's LimeWire Tunes", available for sharing.
She then opened the folder and saw file names that got her on the phone with her local sheriff's office, pronto.
Some of the titles were very sexually explicit. Some other titles were used in conjunction with acronyms indicating age, such as "5yoa" and "8yoa".
Washington County Deputy John McCullough responded to JH's call a little less than an hour later. He wasn't sure whether he could legally open the files, so he called his supervisor, who gave him the go-ahead.
McCullough later recalled seeing the words "getting raped" and "being raped" in those file names.
Deputy McCullough opened a file and did, in fact, find images of child abuse - a search that Judge King last week deemed unreasonable, finding the evidence unsubmittable.
It's interesting to note the trail of evidence that a group of documents such as these leave on a computer.
According to Judge King's filing, Arnhdt admitted to downloading child abuse images as recently as eight months prior to law enforcement obtaining warrants and searching his home and computers. He'd subsequently deleted the files, though, he said.
Arnhdt told agents that he'd used LimeWire, a peer-to-peer file-sharing application, to download the images. If agents were capable of recovering deleted files, they'd find the images, he told them - specifically, on external hard drives that he'd converted from hard drives of old computers.
Investigators did, in fact, recover traces of the files, including:
Advertising pages located in an "orphan" file - e.g., one whose parent file had been deleted. Images located in a Google Hello "scache" indicating the images had been sent or transmitted. (For a detailed look at how forensics experts find such images, check out this white paper by J. Curl: "Forensic Investigation of Google's "hello" [PDF].)An .mpg movie that had been viewed in Windows Explorer or by using a My Computer thumbnail or filmstrip view. A deleted file recovered from Ahrndt’s computer.Deleted files recovered from his USB flash drive.
Will Judge King's decision be upheld?
A commenter on The Wall Street Journal's coverage of the case thinks not:
joe doaks: … I believe that historically, you are free to look at any ambient electromagnetic radiation you are able to receive and decode. A couple decades back, an over-the-air HBO provider with not-very-sophisticated encryption, found this out the hard way.
I'm no legal expert, but I'd suggest that this argument misses the mark, given that it's not the legality of JH's unauthorized accessing of Arnhdt's network that was in question.
Rather, it was Deputy McCullough's opening of one of the files without a warrant that rendered the evidence unsubmittable.
Regardless of the legal technicalities, it's a good reminder that unsecured wireless networks render files sharable and readable.
This ruling is just one in many that get handed down in child abuse and unreasonable search cases.
I wouldn't count on the courts letting you off the hook if you're up to something reprehensible on an unsecured wireless network.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
Sometimes some good can come from poor computer security.
The Burton Mail reports that a 46-year-old British man was found guilty of downloading indecent images of children after he accidentally shared his USB memory stick with a work colleague.
According to reports, Nicholas Hill, of Belvoir Crescent, Newhall, handed a memory stick to a female colleague in order to get a recording of a TV programme, but as soon as his workmate plugged the USB drive into her computer she was shocked to be presented with an array of indecent photos.
Clearly, Hill had not encrypted the data on his USB flash drive.
When police were called they found "279 images in the mildest category and six which were slightly more serious" contained on the memory stick.
Hill's defence team said that he had been collecting such images for a number of years, and told a hearing at Derby Magistrates' Court that their client deeply regretted committing the offence, and was previously a "man of good character".
Presiding magistrate Jill Steiner put Hill on probation for three years, and ordered him to attend a community sex offenders' group work programme. If Hill buys computer equipment in future, he must allow it to be inspected by police officers - although he has said that he will access the net only from a public library in future.
Aside from serving probation, Hill has also been ordered to pay £85 costs. As he is currently between jobs, it was has been agreed that he can pay the fine in monthly installments.
Being a consumer of child abuse imagery only encourages others to supply more, and ultimately abuse the young innocent victims. Hopefully Hill will rebuild his life, and not engage in child abuse material again.
If that's the case then some small good will have come out of poor security.
Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.
Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.
Already using Google+? Find us on Google+ for the latest security news.
In at least one case, the US police's hunt for online child abuse images has been stymied by Tor, a Freedom of Information Act (FOI) request has revealed.
The FOI request, which was originally for all Justice Department records mentioning the Silk Road marketplace (a site that National Public Radio has referred to as the "Amazon.com of illegal drugs"), was made by MuckRock's Jason Smathers.
According to the FOI documents, a citizen reported stumbling on a cache of child abuse images while browsing anonymous Tor sites, viewable with specialized, hard-to-come-by tools and the .onion domain, while he was searching for the deep-web location of the Silk Road:
He visited the Tor directory at the following site: [expunged]. At this site, he noticed a link to 'adult' websites and clicked on it. He noticed a link on the next page for 'TSCHAN' which he recognized to be a hacking affiliated group. When he clicked on this link, he saw pictures he described as child pornography. He said it looked like child pornography because he could tell the subjects were very young with some in diapers. All were still images, no videos, and he said most showed the children posing for the pictures.
Investigators were unable to determine the origin of the pornography's host, as they described in a Detroit field office 2011 FBI Complaint/Assessment Form that was part of the FOI documents:
Because everyone (all Internet traffic) connected to the TOR network is anonymous, there is not currently a way to trace the origin of the website. As such no other investigative leads exist.
Tor, a free, open-source program, bestows online anonymity via a circuit of multilayered, encrypted connections routed through a worldwide volunteer network of servers in order to conceal a user's location or usage from anyone conducting network surveillance or traffic analysis.
In spite of the investigators' despair, however, it's quite possible to bust Tor communities.
One recent example is "The Farmer's Market," an online narcotics store that hid its operations with Tor. The Farmer's Market was brought down in April.
Granted, Tor was incidental to that bust.
As the indictment laid out, authorities were aware of the Farmer's Market's use of Hushmail - a service based in Canada that offers PGP-encrypted e-mail, file storage, vanity domain service, and instant messaging - before the operation was moved to Tor.
And as Naked Security reader HushFail commented at the time, Hushmail only protects users until law enforcement whips out a badge.
Hushmail has in the past turned over cleartext copies of private email messages associated with multiple accounts at the request of law enforcement agencies under a mutual legal assistance treaty between Canada and the US, such as in the case of US v. Tyler Stumbo.
Another factor in the Farmer's Market bust was payment processing via means that included PayPal - to an agent with the US Drug Enforcement Administration, no less.
Clearly, some law enforcement agencies find ways to track down their prey, even if the suspects are using Tor.
But as Tor Project development director Karen Reilly told Ars Technica on Tuesday, there are non-Tor-specific means of getting through Tor, beyond tracking suspects through Hushmail or PayPal.
Tor Project members regularly meet with law enforcement to explain how Tor works and to direct them to these vulnerabilities, Reilly told Ars in an email exchange:
Saying that you have no leads is ridiculous. … Hidden services are just like a street address. You can't break an address. You can break the doors or windows of the house at that address. An attack on a .onion and a .com are the same. The usual PHP vulnerabilities to SQL injection and the like are applicable.
And as Ars pointed out, such are the vulnerabilities Anonymous used to take down Tor sites in its Operation Darknet anti-child-abuse-websites effort.
That Anonymous operation succeeded in taking down 40 child abuse sites, including Lolita City, in October 2011.
Anonymous managed to crack Tor to not only bring down the abuse sites, but also to publish account details of 1,589 users from the site’s database.
Obviously, Tor anonymity is not foolproof.
Tor itself warns about one vulnerability on its site:
Be aware that, like all anonymizing networks that are fast enough for web browsing, Tor does not provide protection against end-to-end timing attacks: If your attacker can watch the traffic coming out of your computer, and also the traffic arriving at your chosen destination, he can use statistical analysis to discover that they are part of the same circuit.
That means that a potential eavesdropper on an end user’s network may be able to analyze the patterns of data being returned and may be able to make a reasonable hypothesis about the source of the communication.
Such a technique wouldn't help the FBI unless they already knew enough about their suspects to plant an eavesdropper on their network, of course.
But in sum, it seems that there have been multiple unmaskings of Tor users, whether it's by the means employed by the multinational task force that cracked the Farmer's Market or the vulnerabilities exploited by Anonymous.
If they can do it, it's hard to see why the FBI can't.
Follow @LisaVaas
Child alone image, courtesy of Shutterstock.
Tags: anonymous, child porn, Encryption, FBI, FOI, Hushmail, Lolita City, Operation Darknet, pornography, The Farmer's Market, Tor
In a move that we can all get behind, hacker group Anonymous has announced that they have taken down a huge cache of child pornography and released 1,589 usernames of the website’s patrons. The action came as part of Operation Darknet, which targets illicit websites that are part of an unindexed and therefore unsearchable corner of the Internet.
The server in question is owned by Freedom Hosting, and apparently services over 40 child pornography websites. The largest of these, disturbingly called Lolita City, was said to contain over 100gb of child pornography.
Interestingly, the Anonymous hack is extremely well documented. In two separate Pastebin posts, the hackers involved provide a timeline of events, as well as some of the methodologies they used in tracking and taking down the servers.
According to their timeline, the hackers first became aware of Lolita City while leading a related campaign against a portion of the Hidden Wiki which included links to child pornography. While working to suppress the Hidden Wiki for linking to child pornography, the group turned their attentions to the websites linked on the Wiki. Through their investigations, they discovered that many of the sites shared a similar “fingerprint” in that they were supported and hosted by a company called Freedom Hosting.
The group then issued an ultimatum to Freedom Hosting to remove the content, or be shut down through their attacks. Freedom Hosting refused, and has since been the target of the hacker’s ire.
While attacks by the hacker group have often been divisive, going after the supporters of child pornography is something that is hard to criticize. In fact, this might be the best application of the groups’ talents; an intersection of Internet knowledge and the ability to carry out electronic attacks. Of course, preventing child pornography from being moved around the Internet doesn’t stop the predators that created the materials. Hopefully, law enforcement will take up the information gleaned by the group and start making some arrests.