https://www.techdirt.com/2023/09/11/fbi-federal-judge-agree-fighting-botnets-means-allowing-the-fbi-to-remotely-install-software-on-peoples-computers/ [ ] Techdirt. [ ] * Sign In * Register * Preferences Techdirt [ ] * TechDirt * GreenHouse * Free Speech * Deals * Jobs * Support Techdirt [podcast-ti] 5th Circuit v. 5th Circuit: When Can And When Can't The Government Coerce Content Moderation Decisions? Another Day, Another SLAPP Threat From A 'Wellness' Influencer Against Someone Reviewing Their 'Masterclass' FBI, Federal Judge Agree Fighting Botnets Means Allowing The FBI To Remotely Install Software On People's Computers [uses-of-te] (Mis)Uses of Technology from the all's-fair-in-love-and-cyber-war dept Mon, Sep 11th 2023 12:03pm - Tim Cushing The ends aren't always supposed to justify the means. And a federal agency that already raised the hackles of defense lawyers around the nation during a CSAM investigation probably shouldn't be in this much of hurry to start sending out unsolicited software to unknowing recipients. But that's the way things work now. As a result of the DOJ-propelled push to change Rule 41 jurisdiction limitations, the FBI is now able to infect computers anywhere in the United States using a single warrant. In the "Playpen" case, the software was used to obtain information about users and devices visiting a seized (but still live) dark web CSAM site. A couple of years later, the lack of jurisdiction limitations were used for something a bit more useful for even innocent computer users: the FBI secured a single warrant authorizing it to send its botnet-battling software to computers all over the nation, resulting in the disinfection of thousands of computers. And while this all seems like a net positive for US computer users, the underlying facts are a bit more worrying: judges will allow the FBI to place its software on any user's computer at any time, provided it can convince a court the end result will be something other than a massive number of privacy violations. It's inarguable that disrupting botnets is a public good. But is it inarguable that disruption should occur by any means necessary... or, at least, any means convenient. The disruption of another botnet has been achieved with the assistance of the FBI, a federal judge, and some government software deployed without notification to an unknown number of infected devices. The FBI quietly wiped malicious programs from more than 700,000 computers around the world in recent days, the agency said Tuesday, part of an operation to take down a major component of the cybercrime ecosystem. [...] The FBI got a court's permission to proceed with the operation on Aug. 21, according to a copy of the warrant. Agents proceeded to hack into Qakbot's central computer infrastructure four days later, the FBI announced, and forced it to tell the computers in its botnet to stop listening to Qakbot. An unnamed FBI "source" added this: Victims will not be notified that their devices had been fixed or that they had ever been compromised, he said. All of that was accomplished with a five-page warrant [PDF] that doesn't have much to say about the probable cause compelling this invasion of users' computers. The warrant authorized the FBI to, in effect, "search" every computer it sent its software to. PROPERTY TO BE SEARCHED This warrant applies to the electronic storage media contained in victim computers located in the United States onto which malicious cyber actors have installed, without authorization, the Qakbot malware, and which computers are in communication with the Qakbot botnet infrastructure. What's not immediately clear is how the FBI determined which computers were infected. Instead, it seems to authorize an intrusion into all computers it could access, with infections determined following the mass search. The warrant says "remote access techniques may be used:" To search the electronic storage media identified in Attachment A [PROPERTY TO BE SEARCHED, as shown above] and to seize or copy from those media any electronically stored information, such as encryption keys and server lists, used by the administrators of the Qakbot botnet to communicate with computers that are part of the Qakbot botnet infrastructure; and To search the electronic storage media identified in Attachment A and to seize or copy from those media any electronically stored information, such as IP addresses and routing information, necessary to determine whether any digital device identified in Attachment A continues to be controlled by the Qakbot administrators after the seizure or copying of the electronically stored information identified in Paragraph 1. At first glance, it might appear that the FBI limited its software deployment to known infected devices. But that's clearly not the case, as was noted earlier in the NBC report quoted above. Here are the facts again, given a bit more weight with the addition of the FBI's RAT warrant: The FBI got a court's permission to proceed with the operation on Aug. 21, according to a copy of the warrant. Agents proceeded to hack into Qakbot's central computer infrastructure four days later, the FBI announced... So, odds are the FBI didn't know which computers were infected when it deployed its "remote access technique." That means it was given permission to target any device it could access via the internet, with controlling factors only appearing four days after it had already performed its "search." The only mitigating factor is the last paragraph of the approved warrant. And that's only mitigating if you believe the FBI would not use this opportunity to sniff around for others things it might be interested in. This warrant does not authorize the seizure of any tangible property. Except as provided in the accompanying affidavit and in Paragraphs 1 and 2, this warrant does not authorize the seizure or copying of any content from the electronic storage media identified in Attachment A or the alteration of the functionality of the electronic storage media identified in Attachment A. All this means is the court trusts the FBI not to abuse this access. And it forces all of us to operate by the same questionable standard, since the FBI has made it clear it is not willing, nor legally obligated, to inform computer users their computers were compromised by FBI software, however briefly or usefully. Given that lack of disclosure, it's going to make it almost impossible to challenge evidence of other criminal activity that might have been obtained during this mass search. It also means users aren't able to double-check the FBI's work by ensuring their devices are free of either botnet infections or FBI software. And there's a very good chance the FBI handled this all honestly and decently and actually performed a useful public service. The point is there are now court-accepted mechanisms in place that would easily allow the FBI to engage in activities that are more abusive of people's rights without worrying too much about judicial oversight and/or victims of questionable spyware deployments ever finding out they were targeted during FBI activities ostensibly meant to take down botnets. Filed Under: 4th amendment, botnets, fbi, qakbot, remote installs, warrant 11 CommentsLeave a Comment If you liked this post, you may also be interested in... * Common Sense Media Has No Common Sense When It Comes To Internet Laws * NYPD's New Labor Day Tradition Involves Drone Surveillance Of People's Private Parties And Property * FBI Joins Investigation Of LAPD Gang Unit Officers Who Did Their Own Selective Editing Of Body Cam Recordings * Kansas State Police Tell Court It's Too Much To Ask For Troopers To Respect The Constitution * California Supreme Court Decides There's No Reason To Generate Precedent On Geofence Warrants * * * * * * * * * * * Rate this comment as insightful Rate this comment as funny You have rated this comment as insightful You have rated this comment as funny Flag this comment as abusive/trolling/spam You have flagged this comment The first word has already been claimed The last word has already been claimed Lightbulb icon Laughing icon Flag icon Lightbulb icon Laughing icon Comments on "FBI, Federal Judge Agree Fighting Botnets Means Allowing The FBI To Remotely Install Software On People's Computers" Subscribe: RSS Leave a comment * Filter comments in by Time * Filter comments as Threaded * Filter only comments rated Insightful * Filter only comments rated funny LOL * Filter only comments that are Unread 11 Comments Collapse all replies [4271c1ec16]Anonymous Coward says: September 11, 2023 at 12:18 pm The FBI view on this. To find the source of the infections we can downloaded all you files do that we can examine them for signs of infection. Anything else we find can be used under the in plain view doctrine. Ignore that big bit barn in Utah, its contents are none of your concern. Reply View in chronology Make this comment the first word Make this comment the last word [61b4def66b]Anonymous Coward says: September 11, 2023 at 12:33 pm warrant: victim computers in united states fbi: "the world is our oyster" Reply View in chronology Make this comment the first word Make this comment the last word [d85a0acdf4]Zach says: September 11, 2023 at 1:01 pm Used the botnet to install the code My understanding was the FBI used the botnet it compromised to install the code removing the botnet. They didn't randomly access whatever computers they could, they accessed the botnet! In fact, by uninstalling the botnet client software on the affected computers the FBI removed the method by which the FBI could access these computers. Collapse replies (1) Reply View in chronology Make this comment the first word Make this comment the last word Threaded [2] [4027cee2f0]Anonymous Coward says: September 11, 2023 at 1:38 pm Re: In fact, by uninstalling the botnet client software on the affected computers the FBI removed the method by which the FBI could access these computers. But did they see if they had an interesting target, like say a journalist, and give themselves access to the computer while they had the opportunity? Reply View in chronology Make this comment the first word Make this comment the last word [u20350_100x0-1]mvario (profile) says: September 11, 2023 at 1:06 pm A more detailed look BleepingComputer has a more detailed breakdown on how the botnet operated and what the FBI did to disrupt it: https://www.bleepingcomputer.com/news/security/ how-the-fbi-nuked-qakbot-malware-from-infected-windows-pcs/ Collapse replies (1) Reply View in chronology Make this comment the first word Make this comment the last word Threaded [2] [1a57bbe049]Anonymous Coward says: September 11, 2023 at 1:42 pm Re: All you need to know, in one line While this is definitely a win for law enforcement, it may not be the end of the Qakbot operation as no arrests were made. Reply View in chronology Make this comment the first word Make this comment the last word [cdbc5a538c]Anonymous Coward says: September 11, 2023 at 1:19 pm Well, at least they had a warrant! Reply View in chronology Make this comment the first word Make this comment the last word [203ea6a41c]Anonymous Coward says: September 11, 2023 at 1:35 pm the FBI secured a single warrant authorizing it to send its botnet-battling software to computers all over the nation, resulting in the disinfection of thousands of computers. The FBI quietly wiped malicious programs... ... which is much like prescribing a 4 month Tuberculosis treatment regimen, and then stopping after 3 months with "they've stopped coughing, that's good enough". Without the operators being aware that their systems were hacked, and particularly without those operators taking steps to tighten security, those systems will be reinfected quite soon. Perhaps even based on a list of nodes from the now-defunct botnet. "but those systems might be in (mission-critical/life support/etc) positions!" Right. And when the next ransomware attack comes through, I'm sure that system will continue operating as normal because ransomware gangs have a heart, right? /s Reply View in chronology Make this comment the first word Make this comment the last word [048272ca56]Anonymous Coward says: September 11, 2023 at 1:48 pm While the upshot is largely reasonable, and something to be expected via some mechanism at some point, i would agree with at least parts of some comments above that the article seesmore excess thanthere is here. Having a hell of a time checking the warrant application on this phone, so i can't tell if Attachment A is there, much less read it. But i already suspect they targeted exactly the infected nodes because they used the C&C server to reverse the infection. Possibly with the malware's own functions or its toolset, and possibly minus any FBI uh... software on the client side. Reply View in chronology Make this comment the first word Make this comment the last word [user-default]HotHead (profile) says: September 11, 2023 at 2:14 pm Rights don't exist any time a computer is involved? A general warrant, anathema to the spirit of the Fourth Amendment. Actually, this is worse than a general warrant because the warrant is focused on searching victims rather than searching for suspects. This is analogous to the FBI's being able to enter my house at any time of the day and as often as the FBI desires to search my entire house to determine whether an uninvited stranger secretly planted a bomb in my house, without evidence to suggest that an uninvited stranger ever entered, never mind planted a bomb. And of course if I'm told neither about the visit nor about whether there was a stranger in my attic, how the hell am I supposed to believe that the FBI's reasons for searching and the scope of the search are in any way related to a supposed bomb planting? Collapse replies (1) Reply View in chronology Make this comment the first word Make this comment the last word Threaded [2] [user-default]HotHead (profile) says: September 11, 2023 at 2:17 pm Re: And of course if I'm told neither about the visit nor about whether there was a stranger in my attic... I changed my analogy but forgot to update this part. I meant to say: And of course if I'm told neither about the visit nor about whether they found a bomb in my house, how the hell am I supposed to believe that the FBI's reasons for searching and the scope of the search are in any way related to a supposed bomb planting? Reply View in chronology Make this comment the first word Make this comment the last word --------------------------------------------------------------------- says: Add Your Comment Cancel reply Your email address will not be published. Required fields are marked * Have a Techdirt Account? Sign in now. Want one? Register here Name [ ] Email [ ] [ ]Subscribe to the Techdirt Daily newsletter URL [ ] Subject [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Comment Options: (*)Use markdown. ( )Use plain text. Make this the ( )First Word or ( )Last Word.(*)No thanks. (get credits or sign in to see balance) what's this? What's this? Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop >> [Post Comment][Preview] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] 5th Circuit v. 5th Circuit: When Can And When Can't The Government Coerce Content Moderation Decisions? Another Day, Another SLAPP Threat From A 'Wellness' Influencer Against Someone Reviewing Their 'Masterclass' Follow Techdirt Techdirt Daily Newsletter [ ] [Subscribe] Essential Reading The Techdirt Greenhouse Read the latest posts: * Winding Down Our Latest Greenhouse Panel: The Lessons Learned From SOPA/PIPA * From The Revolt Against SOPA To The EU's Upload Filters * Did We Miss Our Best Chance At Regulating The Internet? Read All >> --------------------------------------------------------------------- Trending Posts * Elon Musk Files Really Strong 1st Amendment Challenge To California's Terrible Social Media 'Transparency' Law * 5th Circuit Cleans Up District Court's Silly Jawboning Ruling About the Biden Admin, Trims It Down To More Accurately Reflect The 1st Amendment * FBI, Federal Judge Agree Fighting Botnets Means Allowing The FBI To Remotely Install Software On People's Computers Techdirt Deals Techdirt Insider Discord The latest chatter on the Techdirt Insider Discord channel... Loading... Become an Insider! Recent Stories Monday 13:38 Another Day, Another SLAPP Threat From A 'Wellness' Influencer Against Someone Reviewing Their 'Masterclass' (6) 12:03 FBI, Federal Judge Agree Fighting Botnets Means Allowing The FBI To Remotely Install Software On People's Computers (11) 10:41 5th Circuit v. 5th Circuit: When Can And When Can't The Government Coerce Content Moderation Decisions? (10) 10:38 Daily Deal: The Ultimate Learn Unreal Game Development Bundle (0) 5th Circuit Cleans Up District Court's Silly Jawboning Ruling 09:31 About the Biden Admin, Trims It Down To More Accurately Reflect The 1st Amendment (20) 05:29 Critics Say Rules Affixed To Biden's Massive Broadband Subsidy Program Boxes Out Small ISPs And Community Broadband (0) Sunday 12:00 Funniest/Most Insightful Comments Of The Week At Techdirt (55) Saturday 12:00 This Week In Techdirt History: September 3rd - 9th (1) Friday 19:39 Streamer In Japan Gets 2 Years Jail Time For Uploading Let's Plays, Anime Spoilers (19) 15:28 G/O Media Gives Another Crash Course On Perils Of Replacing Human Journalists With Half-Baked 'AI' (11) More arrow x Email This Story This feature is only available to registered users. You can register here or sign in to use it. Tools & Services * Twitter * Facebook * RSS * Podcast * Research & Reports Company * About Us * Advertising Policies * Privacy Contact * Help & Feedback * Media Kit * Sponsor / Advertise More * Copia Institute * Insider Shop * Support Techdirt Techdirt Brought to you by Floor64 Proudly powered by WordPress. Hosted by Pressable. [Got it] This site, like most other sites on the web, uses cookies. For more information, see our privacy policy