Google Search

Showing posts with label image. Show all posts
Showing posts with label image. Show all posts

Friday, August 9, 2013

US child abuse image suspect shielded from decrypting hard drives

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Person behind glass. Image courtesy of Shutterstock.A US federal magistrate has refused to order a Wisconsin computer scientist and child abuse image suspect, Jeffrey Feldman, to decrypt the hard drives the government seized from him.

The rationale of Magistrate William Callahan Jr. of Wisconsin: the Fifth Amendment to the US Constitution shields citizens from being compelled to self-incriminate.

Callahan wrote [PDF, posted courtesy of Wired] that, unlike in similar cases, where the government has compelled people to unlock the encrypted portions of their hard drives, in this case, Feldman hasn't admitted that he has access and control of the hardware.

This is in spite of the many storage devices in question having been found in his house, where he's lived alone for 15 years.

Callahan's thinking:

This is a close call, but I conclude that Feldman’s act of production, which would necessarily require his using a password of some type to decrypt the storage device, would be tantamount to telling the government something it does not already know with 'reasonably particularity' - namely, that Feldman has personal access to and control over the encrypted storage devices. Accordingly, in my opinion, Fifth Amendment protection is available to Feldman. Stated another way, ordering Feldman to decrypt the storage devices would be in violation of his Fifth Amendment right against compelled self-incrimination.

The government, trying to convince the courts to force the suspect to comply, had said [PDF, again posted courtesy of Wired] that if Feldman doesn't unlock the drives, the case could suck up even more resources than it has already, and investigators might even damage the hardware.

From the court papers:

The United States, the FBI in particular, has already expended substantial resources in the effort to break the encryption preventing it from accessing the information as ordered by the Search Warrant and more will be required if the encryption must be broken manually. Members of the FBI's Computer Analysis Response Team (CART) have spent more than ten weeks decrypting Mr. Feldman's storage devices.

In fact, the prosecutors warn, encryption is getting both tougher to crack and used more widely, painting "a grim picture of the future for law enforcement officers" as they seek to carry out court-mandated search warrants.

Locked computer. Image courtesy of Shutterstock.Even if you're a privacy absolutist, even if you believe that the FBI and other law enforcement agencies in the US have gotten a bit too cozy with surveillance of the nation's citizenry and warrantless searches, you've got to have a bit of sympathy for law enforcement here if you believe (and I hope that you all do) that putting child abuse image collectors and creators out of business is a vital job.

The government said in its court papers that what they did manage to glean from unencrypted portions of Feldman's computer storage showed a large number of user-created links that "strongly suggest, often in graphic terms," the presence of encrypted abuse images on Feldman's hardware.

The investigators also found a peer-to-peer sharing utility that contained logs of 1,009 videos that Feldman had allegedly received, distributed and stored - most of the filenames being "unambiguously indicative" of child porn.

If your first inclination is to curse the judge, check that impulse. This is about far more than this one alleged child abuse image collector.

Hanni Fakhoury, a staff attorney with the Electronic Frontier Foundation, told Wired that the decision is important beyond whether it gums up a child abuse prosecution, because it's a core issue in regards to government overreach:

This isn’t just about child porn. It’s about anything on your computer that prosecutors or government officials may want.

It's hard to get enthused about a court decision that hampers law enforcement as they work hard to fight child abuse.

But curbing law enforcement's already substantial power, particularly when it comes to power that would contradict our Constitutionally guaranteed rights, is what a properly functioning judicial system should be doing.

Add this to a recent judicial decision to deny the FBI the right to plant spyware on a bank fraud suspect's computer, and you have to come to the conclusion that US courts certainly are capable of gleaning the subtleties of where electronic information, surveillance and our rights intersect.

Should we keep watching this space? Oh, yes.

Just as encryption gets stronger and technology advances, so is the legal landscape every shifting.

That shifting landscape is a very good reason to encrypt your hard drive, though of course device loss and hacking, as always, are right up there to bolster the encryption argument.

Follow @LisaVaas
Follow @NakedSecurity

Images of Person behind glass and locked computer courtesy of Shutterstock.


View the original article here

Tuesday, March 19, 2013

Convicted sex offender let off the hook for child abuse image collection

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Fingers on keyboard, courtesy of ShutterstockJust because a neighbor saw titles for child abuse image files on an unsecured wireless network doesn't justify the law barging in and searching for the images, ruled an Oregon judge in the US.

The decision reversed the judge's previous conviction of John Henry Ahrndt, who, it turns out, was already a convicted sex offender.

In a ruling filed January 17, Senior District Judge Garr M. King said that Ahrndt's Fourth Amendment rights ensuring protection against unreasonable searches had been blown when a deputy got the go-ahead from his supervisor and clicked on one of the titles:

There is no evidence [Ahrndt] intentionally enabled sharing of his files over his wireless network, and there is no evidence he knew or should have known that others could access his files by connecting to his wireless network. [The deputy's] action of clicking on the image in [the neighbor's] iTunes directory to open the image violated Ahrndt’s Fourth Amendment rights.

Here's how the files were discovered in the first place: In February 2007, one of Ahrndt's neighbors - a woman identified as "JH" in court documents - got onto his unsecured wireless network when her own network went down.

Ahrndt's network was coming off a Belkin 54G router with a default setting of "no security".

JH opened up iTunes and noticed another user's library, called "Dad's LimeWire Tunes", available for sharing.

She then opened the folder and saw file names that got her on the phone with her local sheriff's office, pronto.

Some of the titles were very sexually explicit. Some other titles were used in conjunction with acronyms indicating age, such as "5yoa" and "8yoa".

Washington County Deputy John McCullough responded to JH's call a little less than an hour later. He wasn't sure whether he could legally open the files, so he called his supervisor, who gave him the go-ahead.

McCullough later recalled seeing the words "getting raped" and "being raped" in those file names.

Deputy McCullough opened a file and did, in fact, find images of child abuse - a search that Judge King last week deemed unreasonable, finding the evidence unsubmittable.

It's interesting to note the trail of evidence that a group of documents such as these leave on a computer.

According to Judge King's filing, Arnhdt admitted to downloading child abuse images as recently as eight months prior to law enforcement obtaining warrants and searching his home and computers. He'd subsequently deleted the files, though, he said.

Arnhdt told agents that he'd used LimeWire, a peer-to-peer file-sharing application, to download the images. If agents were capable of recovering deleted files, they'd find the images, he told them - specifically, on external hard drives that he'd converted from hard drives of old computers.

Investigators did, in fact, recover traces of the files, including:

Advertising pages located in an "orphan" file - e.g., one whose parent file had been deleted. Images located in a Google Hello "scache" indicating the images had been sent or transmitted. (For a detailed look at how forensics experts find such images, check out this white paper by J. Curl: "Forensic Investigation of Google's "hello" [PDF].)An .mpg movie that had been viewed in Windows Explorer or by using a My Computer thumbnail or filmstrip view. A deleted file recovered from Ahrndt’s computer.Deleted files recovered from his USB flash drive.

Will Judge King's decision be upheld?

A commenter on The Wall Street Journal's coverage of the case thinks not:

joe doaks: … I believe that historically, you are free to look at any ambient electromagnetic radiation you are able to receive and decode. A couple decades back, an over-the-air HBO provider with not-very-sophisticated encryption, found this out the hard way.

I'm no legal expert, but I'd suggest that this argument misses the mark, given that it's not the legality of JH's unauthorized accessing of Arnhdt's network that was in question.

Rather, it was Deputy McCullough's opening of one of the files without a warrant that rendered the evidence unsubmittable.

Regardless of the legal technicalities, it's a good reminder that unsecured wireless networks render files sharable and readable.

This ruling is just one in many that get handed down in child abuse and unreasonable search cases.

I wouldn't count on the courts letting you off the hook if you're up to something reprehensible on an unsecured wireless network.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Friday, November 2, 2012

Invited to change your Twitter profile's header image? Beware, it could be drug spam

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Inventive spammers are up to their old tricks again, desperate to do whatever it takes to get you to click on a link to their websites.

The latest campaign we have seen involves messages which, to all intents and purposes, look like they have come from Twitter.

Certainly, without close inspection, there's nothing much to be suspicious about in regards to the email (although maybe they would have been more convincing if they had managed to reference your Twitter name if you have one).

Spam claiming to be from Twitter

Subject: Because you have more to show

We have something for you...

New Twitter profiles

Make your profile beautiful with a header image. Browse your new photo reel. Check out what other people are doing with their profiles.

The emails invite you to update your Twitter profile, to include the new format profile images that the micro-blogging site is attempting to push onto a slightly underwhelmed userbase.

But in this case the emails don't come from Twitter at all. Because if you click on the links you are actually taken to a "Canadian pharmacy" website claiming to sell sexual enhancement drugs.

Canadian pharmacy website

My guess is that the emails have been stolen lock-stock-and-barrel from a genuine Twitter communication, and just the links have been changed.

You should always be careful to check where a link is taking you, especially when contained in an unsolicited email, before you click on it.

In this case, it could just have easily linked to a bogus Twitter login page - asking you to enter your username and password - or a website hosting malicious code designed to infect your computer.

Follow @gcluley

View the original article here