[HN Gopher] We Got the Phone the FBI Secretly Sold to Criminals
       ___________________________________________________________________
        
       We Got the Phone the FBI Secretly Sold to Criminals
        
       Author : el_duderino
       Score  : 121 points
       Date   : 2021-07-08 15:58 UTC (7 hours ago)
        
 (HTM) web link (www.vice.com)
 (TXT) w3m dump (www.vice.com)
        
       | sergiomattei wrote:
       | Aight, this is some next-level stuff.
       | 
       | Hell, I'd even call it badass. The FBI created a tech startup
       | (even with the .io domain!) and sold devices with a custom
       | Android distribution.
       | 
       | It's funny because you can search for the XDA-Developers thread
       | mentioned in the article, they were pretty shocked to find a
       | phone with modded software and a locked bootloader.
        
         | bserge wrote:
         | It is pretty impressive, they made a whole company marketing
         | secure phones, except the devices were wiretapped.
         | 
         | Aside from that, it sounds like a pretty decent secure phone,
         | too.
         | 
         | Did they hire one of those TV show genius detectives to plan
         | all this?
         | 
         | It sure seems more advanced than the usual FBI operations (or
         | maybe we don't hear much about the good ones).
        
           | cronix wrote:
           | Next we'll be hearing about all the fake VPN companies
           | they're running. "Sign up for our secure VPN and keep your
           | traffic away from prying eyes! Do you know how many companies
           | are spying on you and selling your data?" I've always thought
           | that would be an excellent mitm vector. Then get a bunch of
           | youtubers to promote it.
        
             | mr-wendel wrote:
             | After that, we'll hear about the security companies they
             | "own" whose agents and kernel modules are mandated all
             | across corporate America.
             | 
             | Why go through the trouble of running a VPN company
             | yourself? That is sooooo 5-10 years ago.
        
             | disambiguation wrote:
             | plot twist: letsencrypt.org
        
               | JackGreyhat wrote:
               | I seem to not get the twist. What am I missing?
        
             | pxeboot wrote:
             | Didn't Facebook already do this?
        
             | the_other wrote:
             | I already read VPN ads and even positive Tor press as if
             | it's shilling for Three Letter Agencies.
        
             | Enginerrrd wrote:
             | This is why I don't trust VPN companies that advertise.
        
               | kilroy123 wrote:
               | Which ones are good then?
        
               | imwillofficial wrote:
               | PIA has been tested in court as not keeping your data.
               | Other than that you're placing trust in others, depends
               | on what you wanna keep secret.
        
               | Tenoke wrote:
               | That's from before it got sold to Kape who has had a
               | horrible track record with VPNs.
        
               | bserge wrote:
               | Your own, purchased using untraceable means (fake ID is
               | the easiest... and likely most illegal).
        
               | ipaddr wrote:
               | Depends on what you want it for. To pretend you are in
               | the US for netflix or to evade the fbi. The ones that
               | advertise are good for the first.
               | 
               | Rolling your own fixes one issue and raises another.
        
               | anoncake wrote:
               | If you pay using the right method, Mullvad doesn't know
               | your identity.
        
               | mrzimmerman wrote:
               | Came here to promote Mullvad as well. Not that they can't
               | point back to your up address or some such but since you
               | can login to the VPN using a unique identifier instead of
               | an email address and password it's a pretty decent way to
               | decouple it from your PII.
        
               | elliekelly wrote:
               | And you can pay with cash. I always feel a bit funny
               | dropping $10 cash in the mail with no return address but
               | so far it's always made it into my account.
        
               | phyalow wrote:
               | They have your fingerprints now (and possibly your DNA
               | from the stamp)!
        
           | leetcrew wrote:
           | > Did they hire one of those TV show genius detectives to
           | plan all this?
           | 
           | maybe lester freamon? this is essentially a more
           | sophisticated version of what he did in season 3 of the wire.
           | nothing new under the sun, I guess.
        
           | hoppyhoppy2 wrote:
           | >The F.B.I.'s operation, according to court documents that
           | the Justice Department unsealed on Monday, had its origins in
           | early 2018 after the bureau dismantled a Canadian-based
           | encryption service called Phantom Secure. That company,
           | officials said, supplied encrypted cellphones to drug gangs,
           | like Mexico's Sinaloa cartel, and other criminal groups.
           | 
           | >Seeing a void in the underground market, the F.B.I.
           | recruited a former Phantom Secure distributor who had been
           | developing a new encrypted communications system called Anom.
           | The informant agreed to work for the F.B.I. and let the
           | bureau control the network for the possibility of a reduced
           | prison sentence, according to the court documents. The F.B.I.
           | paid the informant $120,000, the documents said.
           | 
           | https://www.nytimes.com/2021/06/08/world/australia/operation.
           | .. (from when it was first revealed to the public last month)
        
             | handmodel wrote:
             | to me the most impressive part isn't that they even did
             | this - but that they did so that fast.
        
               | craftinator wrote:
               | Hope they provide a grant to the numerous open source
               | projects they piggy-backed on.
        
         | 34679 wrote:
         | There are few limits to what one can accomplish with legal
         | impunity and other people's money.
        
           | fedreserved wrote:
           | The 4th amendments probable cause requirement of a crime,
           | prevented the 4 (from memory) American users from being
           | charged.
        
         | moistbar wrote:
         | I have to agree. This is a clever way to catch criminals that
         | doesn't particularly harm non-criminals. I'll take this over
         | the anti-encryption campaign the FBI has been on for the past
         | 10 or 20 years.
        
           | krisoft wrote:
           | > I'll take this over the anti-encryption campaign the FBI
           | has been on for the past 10 or 20 years.
           | 
           | The problem is that these things go hand in hand. The
           | criminals wont buy from the poisoned channel if they can get
           | the security they need from the standard consumer models. If
           | you go to T-mobile, and you get the option everyone gets and
           | it is end-to-end encrypted properly and there aren't any
           | remote exploits then the criminals will just use that.
        
           | sneak wrote:
           | Anyone who wasn't a criminal who bought one of these phones
           | for privacy was harmed.
        
             | fouric wrote:
             | What "harm" did these people experience, exactly?
        
             | Denvercoder9 wrote:
             | Non-criminal privacy focused people are much more likely to
             | use standard devices with publicly known apps such as
             | Signal. You couldn't buy this phone in stores, it was
             | specifically distributed on the black market.
             | 
             | It wasn't a good choice if you're privacy-conscious anyway,
             | since there was no source code available, so you couldn't
             | check it actually does what it claimed.
        
               | sneak wrote:
               | This is victim blaming.
               | 
               | Innocent (and clueless) people seeking privacy had their
               | privacy violated by this action.
        
               | Denvercoder9 wrote:
               | _> Innocent (and clueless) people seeking privacy had
               | their privacy violated by this action._
               | 
               | You state this as fact without any proof. The AFP and FBI
               | assert that 100% of the users were engaged in criminal
               | activity. Given the distribution method, which included
               | vetting by a known criminal organization, the requirement
               | to have an account created by administrators that are
               | again known to be criminal, and the ability to only
               | contact others on the same network, I tend to believe
               | that assertion until I see proof otherwise.
        
         | swiley wrote:
         | Not really.
         | 
         | If you use an OS built by someone else with no publicly
         | available code then they own you. Always. That's hardly news.
        
           | titzer wrote:
           | Most consumer Android phones come with Google Play Services
           | installed by default. Note that that is a completely
           | different thing than the Google Play Store. It's
           | intentionally branded to be confusing and sound like it has
           | something to do with applications. Google Play Services is an
           | entire closed-source operating system living above the
           | kernel, but has hooks all the way down, into every subsystem.
           | It offers a ton of juicy APIs to make Android development
           | "easier", but one of the things that it does (called Google
           | Location Services, or GLS) is interpose between GPS and other
           | ways of location and offer a location API to applications,
           | becoming the location provider for the device. All requests
           | for location go _through_ it.
           | 
           | GLS has scary[1] privacy implications and you cannot
           | uninstall it. You can disable most of the scary stuff it does
           | by _not agreeing_ to use  "high accuracy" mode for location,
           | aka "device only". You must "consent" to this data collection
           | because Google's lawyers believe this consent dialog meets
           | legal requirements for this data collection. Their verbiage
           | is horribly vague and absolutely does _not_ communicate what
           | data collection you are agreeing to by enabling this mode. It
           | calls this data  "anonymous" but location data, particularly
           | traces, is anything but anonymous. At the high resolution of
           | GPS these days, it _cannot be anonymized_.
           | 
           | [1] by "scary", I actually mean absolutely dystopian.
        
             | pyuser583 wrote:
             | Can you go into more detail about the scary parts of Google
             | Play Services? Or include a link?
        
               | titzer wrote:
               | > Can you go into more detail about the scary parts of
               | Google Play Services?
               | 
               | Unfortunately, I cannot.
               | 
               | > include a link?
               | 
               | That I can do. Here is their official policy:
               | 
               | https://policies.google.com/technologies/location-
               | data?hl=en...
               | 
               | "On most Android devices, Google, as the network location
               | provider, provides a location service called Google
               | Location Services (GLS), known in Android 9 and above as
               | Google Location Accuracy. This service aims to provide a
               | more accurate device location and generally improve
               | location accuracy. Most mobile phones are equipped with
               | GPS, which uses signals from satellites to determine a
               | device's location - however, with Google Location
               | Services, additional information from nearby Wi-Fi,
               | mobile networks, and device sensors can be collected to
               | determine your device's location. It does this by
               | periodically collecting location data from your device
               | and using it in an anonymous way to improve location
               | accuracy."
               | 
               | Consider the implications of Google collecting
               | "anonymous" data from billions of Android phones. The
               | technical details of scale, regularity, _which_ sensors,
               | their resolution, etc are highly germane here, but
               | unfortunately not public. This is a very large blind spot
               | in public scrutiny IMHO.
        
             | swiley wrote:
             | Yup. Unfortunately we're training children and college
             | students to accept this. OS vendors are now effectively
             | pseudo governments due to this kind of thing.
        
             | BelenusMordred wrote:
             | > GLS has scary privacy implications and you cannot
             | uninstall it.
             | 
             | I have an Android without Google Location Services, the
             | alternative location service is a Mozilla backend instead.
             | I doubt that's much better for privacy and more likely
             | stands out like a red flag to the Data Hoover collection
             | agencies, but it is certainly possible to not use GLS.
             | 
             | I've only come across one small app that didn't play well
             | with the Mozilla backend.
        
         | nradov wrote:
         | Mexican drug cartels have set up complete private cell phone
         | networks.
         | 
         | https://www.reuters.com/article/us-mexico-telecoms-cartels-s...
        
           | jasonwatkinspdx wrote:
           | I read about an instance where one of the cartels kidnapped a
           | couple telcom engineers working in Brownsville to force them
           | to help set up this kind of infrastructure.
           | 
           | Truly scary and ruthless people.
        
       | fallingknife wrote:
       | How is this not wiretapping without a warrant?
        
         | kube-system wrote:
         | Because the FBI only needs a warrant to wiretap people in the
         | US. Nobody in the US was arrested as a result of this. The 4th
         | amendment to the US constitution doesn't protect, for instance,
         | Australians in Australia.
         | 
         | https://www.abc.net.au/news/2021-06-15/no-one-in-america-arr...
         | 
         | > The AFP made more than 500 arrests but US privacy laws
         | stopped the same from happening there.
        
           | sneak wrote:
           | It's a real bummer that the US doesn't recognize that human
           | rights apply to all human beings.
        
             | fouric wrote:
             | This is inflammatory, insubstantial, and I'm pretty sure it
             | violates the HN guidelines.
        
             | threatofrain wrote:
             | The citizens of the world who believe in universal human
             | rights should gather consensus with the world lest they
             | have nothing to do but continue to talk about how much of a
             | bummer things are on a HN forum.
             | 
             | Of course, international rights also need international
             | enforcement, since a right without enforcement is just a
             | nice thought. Perhaps we'll also have a world order to
             | enforce these rights.
        
               | sneak wrote:
               | Fortunately they're not mutually exclusive.
               | 
               | Expressing discontent with the status quo is one prong of
               | consensus gathering.
        
               | threatofrain wrote:
               | Is the vision that after WW3 we'll be in search of a
               | uniting philosophy and government to make sure natural
               | human rights are codified and enforced?
        
             | veddox wrote:
             | You have to distinguish between human rights and citizens'
             | rights.
        
               | sudosysgen wrote:
               | Perhaps, but the predominant rhetoric and narrative is
               | that human rights are the topic of concern, not citizen
               | rights.
               | 
               | It's difficult to make the case that only citizens
               | deserve rights without sliding into questionable
               | ideologies.
        
             | kube-system wrote:
             | Literally speaking, the 4th Amendment is just a legal
             | right. Most human rights declarations don't require
             | warrants either, they're mostly much more loosely worded
             | than legal rights documents.
        
               | boomboomsubban wrote:
               | > The right of the people to be secure in their persons,
               | houses, papers, and effects, against unreasonable
               | searches and seizures, shall not be violated,
               | 
               | It specifically says that the natural right will not be
               | violated, how is that a legal right?
        
               | kube-system wrote:
               | The constitution is a legal document that is formally
               | upheld by the US legal system. Many of the ideas within
               | it were derived from other places, but it, itself, is a
               | codified legal document.
        
               | boomboomsubban wrote:
               | It is a legal document guaranteeing a natural right. The
               | Bill of Rights doesn't codify much of anything, it lays
               | out certain things further laws can't tread on without
               | extraordinary permission granted.
        
               | kube-system wrote:
               | It guarantees _much more_ than a natural right, and does
               | so with the backing power of a legal institution. For
               | example, the UDHR doesn 't even mention the word
               | "warrant", and it doesn't do anything to compel
               | enforcement.
               | 
               | The BoR is, by plain definition, a codification of
               | rights. To codify means to make into law, which is what
               | it is: a law, implementing the formal recognition
               | rights... and it does so by making illegal specific
               | abuses.
        
             | hacker187 wrote:
             | Also a bummer: that a legislative majority of US citizens
             | care more about the rights of unborn than the born. Almost
             | every conservative (and many centrist democrats) US citizen
             | I asked unapologetically supports mass drone strikes. And
             | so we've had thousands. Many strike entire homes, wedding
             | parties, marketplaces, etc.
             | 
             | Example: https://en.wikipedia.org/wiki/Wech_Baghtu_wedding_
             | party_airs...
        
               | [deleted]
        
         | nonameiguess wrote:
         | They had a warrant:
         | https://www.documentcloud.org/documents/20799201-operation-t...
        
           | Denvercoder9 wrote:
           | No, they didn't. That document literally discusses that they
           | only wiretap overseas messages, likely because they couldn't
           | legally wiretap US messages (though it should be noted that
           | the Australian police did have a warrant for the wiretaps in
           | their jurisdiction).
        
         | EMM_386 wrote:
         | The US helped their Five Eyes partner Australia target
         | Australians.
         | 
         | I'm sure Australia is helping find US citizens the same way.
         | 
         | It's a run-around on the laws of each country.
         | 
         | https://en.wikipedia.org/wiki/Five_Eyes
        
         | owlbynight wrote:
         | Probably had to agree to an EULA that bones your privacy rights
         | as much as every other company's
        
         | gruez wrote:
         | Probably the same reason why planting a bug in someone's home
         | is illegal, but selling an always a smart speaker (aka always
         | on microphone) to them and getting them to install isn't.
        
       | imwillofficial wrote:
       | Anyone know where I can grab one of these phones? I'd love to
       | tear into it.
        
         | sergiomattei wrote:
         | Go to eBay, likely a surplus of these Pixel 4a devices with
         | ArcaneOS.
        
           | imwillofficial wrote:
           | I didn't see anything there with ArcaneOS. Are there other
           | online stores where something liked this might be acquired?
        
             | scrps wrote:
             | Could try contacting Vice, they might be interested in
             | providing one in exchange for the analysis.
        
               | imwillofficial wrote:
               | That's a great idea! Thanks!
        
       | Judgmentality wrote:
       | I'm confused. I understand these phones were (very likely) used
       | by the FBI to surveil suspected criminals. What I don't
       | understand is how the FBI got the phones to those people, and
       | even stranger why those people would trust these phones to be
       | safe?
        
         | ChrisRR wrote:
         | Generally speaking, criminals aren't smart people. Otherwise
         | they could probably use their intelligence to earn money
         | through legitimate means
        
           | rxhernandez wrote:
           | I know a ton of intelligent people in their 30s or 40s at or
           | near the poverty line. Being intelligent doesn't in any way
           | guarantee you good money.
           | 
           | If you haven't heard of the just world fallacy, it might be
           | worth looking into.
        
           | swiley wrote:
           | Intelligence != capable of socializing. You need both in
           | order to be paid well. I think the belife that criminals are
           | uninteligent is due to 1) Intelligent people recognizing that
           | crime rarely has a positive expected profit
           | 
           | 2) There might be more unintelligent people than people who
           | are both intelligent and so incapable of socializing that
           | they can't find work.
        
             | sudosysgen wrote:
             | As long as you're not at the bottom 2-3 rungs crime can
             | have a huge positive expected profit. It's the lifestyle
             | that sucks which is why intelligent people don't get into
             | it unless something in their life makes it a compelling
             | option.
        
               | inetknght wrote:
               | It's amazing to me to see how many people run out the
               | tropes that intelligent people don't commit crimes. More
               | accurately, intelligent people _don 't get caught_
               | committing crimes.
        
               | sodality2 wrote:
               | Aka https://en.wikipedia.org/wiki/Survivorship_bias
        
           | PhasmaFelis wrote:
           | _Street_ criminals tend to be dumb. Thugs, muggers, dealers,
           | guys who just freak out and shoot /beat/rape someone for no
           | reason. People like that usually aren't together enough to
           | even think of getting a secure phone.
           | 
           | The FBI is after the upper echelons of _organized_ crime, and
           | organized crime can be terrifyingly intelligent and
           | resourceful. As another commenter mentioned, some of the
           | Mexican cartels have their own IT departments and private
           | cell providers.
        
           | jedberg wrote:
           | There are plenty of smart criminals. They just don't get
           | caught so you only hear about the dumb ones.
        
             | nicetryguy wrote:
             | It's like inverted Survivorship Bias.
        
         | jellicle wrote:
         | Law enforcement agencies created a site to sell the phones, and
         | then had informants and other such people "pass the word" in
         | the targeted communities - "hey, there's this cool site where
         | you can buy a phone that the FBI can't track!". Viral word of
         | mouth marketing.
        
         | iratewizard wrote:
         | They're not exactly intelligent. I've recovered a drug dealers
         | phone from my airbnb. They use signal and coded language to
         | send messages back and forth, but don't put a lock screen on
         | the phone and leave pictures of their product in gallery.
        
         | hooplah wrote:
         | One article at the time said they had an informant that
         | convinced top level criminals to use it and it spread from
         | there.
         | 
         | Will try to find it, but it was awhile back.
         | 
         | edit:
         | 
         | https://slate.com/news-and-politics/2021/06/encrypted-messag...
         | 
         | > The operation came into being after the FBI took down a
         | Canadian-based encryption service called Phantom Secure.
         | Phantom Secure was marketing its services to criminal elements,
         | offering secure communications through the encrypted cellphones
         | that the company provided to syndicates. When the company was
         | dismantled in 2018, the FBI sought to fill the void in the
         | black market for secure criminal communications. To make that
         | happen, the agency recruited a former distributor of Phantom
         | Secure as an informant who, in return for reduced jail time,
         | not only helped develop an encrypted communications system
         | called ANOM, but helped market it to insular networks of
         | criminal buyers.
        
         | mr-wendel wrote:
         | It's touched on in the article, and
         | https://www.vice.com/en/article/m7e733/anom-fbi-andrew-young...
         | explains it more.                 The FBI's plan was even more
         | bold. Rather than penetrate an existing encrypted phone company
         | used by criminals, it would secretly start and market its own
         | encrypted phone firm. While criminals used the devices, the FBI
         | would be able to read what they were saying.            The
         | challenge was that running a fake encrypted phone company was
         | not that different from running a real encrypted phone company.
         | "We can't just run a good investigation; we have to run a good
         | company,"            ...            It was essentially a
         | problem of marketing, Young said. The FBI needed to imbue this
         | fake company with credibility so that criminals would buy and
         | use the phones.
        
           | anonAndOn wrote:
           | Not their first real company, either. Once upon a time, the
           | FBI created RHM Trust Bank.[0]
           | 
           | [0]https://www.npr.org/sections/money/2019/02/13/694549634/ep
           | is...
        
           | chrisco255 wrote:
           | The FBI/CIA has a long history of doing this. I met a guy
           | once who ran a fake pro shop in New York to spy on visiting
           | Russians (in a part of town they were known to frequent)
           | during the Cold War.
        
             | alushta wrote:
             | Sorry, what's a "pro shop"?
        
               | lordnacho wrote:
               | Isn't that a golf shop? I didn't know it was popular in
               | Russia.
        
               | [deleted]
        
               | hoppyhoppy2 wrote:
               | >A pro shop is a sporting-goods shop within a public or
               | private-membership amateur sporting activities facility
               | of some kind, most commonly a golf course, where it will
               | typically be located in the country club building. In the
               | case of golf pro shops, such stores usually provide
               | equipment such as golf balls, clubs, shoes, and tees, as
               | well as golf-themed gift items, and sometimes snacks or
               | refreshments. Aside from golf courses, pro shops are also
               | frequently found at bowling alleys, pool and snooker
               | halls, tennis and racquetball courts, ice and roller
               | hockey rinks, and football (soccer) facilities.
               | 
               | https://en.wikipedia.org/wiki/Pro_shop
        
               | thatcat wrote:
               | Golf store that usually offers lessons, swing analysis,
               | club fitting, etc.
        
               | kadoban wrote:
               | The meaning I know for that is essentially the store and
               | sometimes a bit of a hangout spot associated with a golf
               | course (so named because of the golf professional(s)
               | available there). Not sure if there's other meanings.
        
         | tacker2000 wrote:
         | They probably were introduced into the criminals organisations
         | by members who were "converted" and working as double agents
         | for law enforcement?
        
         | fedreserved wrote:
         | https://youtu.be/sg1FbtXYvK8 Great video break down of what
         | happened but a good true crime channel the mob reporter
        
         | moftz wrote:
         | They captured one of the distributors for a secure phone
         | company they had already taken down. He was trying to start up
         | his own secure messaging app so they basically funded him,
         | added the backdoors, and used his network to market the new
         | device. It's funny to think about but who would you trust more,
         | some silicon valley company making a "secure" messaging app or
         | one made by another criminal? It's not like there is a LinkedIn
         | for international criminals so there's a physical network of
         | trust required and this guy seemed to have had it.
        
       | lrvick wrote:
       | A project I started, aosp-build, makes it easy to rapidly
       | customize and compile Android images for Pixel devices where you
       | can lock the bootloader.
       | 
       | I have had a few different, sometimes anonymous, groups reach out
       | trying to hire me based on this work or use my build system for
       | unusual use cases. One, for instance, wanted advice for their own
       | private fork of my project where they disabled the camera and
       | similar things to supposedly meet requirements for a high
       | security environment.
       | 
       | It is weird considering my open source project might have been
       | used directly or as a reference by the FBI.
        
         | BelenusMordred wrote:
         | Any reason you didn't take the work? Seriously locking down a
         | phone seems like a rewarding cross-domain engineering
         | challenge.
         | 
         | I'm honestly shocked at how most ultra-high risk people just
         | use off the shelf products, sure they are addictive devices
         | yes, but every few months there's another story of military,
         | celebrity or political compromise because of their phones. It
         | seems like a ripe field if you can somehow convince the end-
         | user it's in their interest to reduce functionality.
        
           | lrvick wrote:
           | Working on an open source project in public is one thing, but
           | doing private work where I don't have any idea what the
           | target use case is, is generally a non starter for me
           | regardless of pay.
           | 
           | Could be FBI, could be terrorists.
           | 
           | My personal mission is to help bring more privacy, security,
           | and freedom to people so I don't really have an interest in
           | work that does not further those goals.
           | 
           | I started my own security consulting firm largely so I can
           | make a good living but also pick and choose my projects.
           | 
           | If I just wanted money without caring about ethics I know
           | where to find high paying jobs at surveillance capitalism
           | companies.
        
             | Red_Leaves_Flyy wrote:
             | Thanks for remaining principled. The world would be a
             | better place if more people had your strength of character.
        
             | BelenusMordred wrote:
             | Fair call, all the best to you for it.
        
         | doublerebel wrote:
         | Looks like that project is @hashbang/aosp-build? Was just
         | looking for something similar today. I have read some people
         | attempt user-mode builds of LineageOS in order to re-lock the
         | bootloader. Wish it was more common! Do you still contribute to
         | this project?
        
       | Multicomp wrote:
       | Maybe I'm dumb. Why would a user who bought a phone that turned
       | out to be an Anom device need their identity protected from
       | 'retaliation'?
       | 
       | To be clear: I'm perfectly happy for them to be anonymous for any
       | reason or no reason. I'm specifically wondering who theoretically
       | would want to retaliate against someone purchasing said devices
       | and why. First sale doctrine still applies even to known
       | honeypotted devices, right?
        
         | Miner49er wrote:
         | Maybe the FBI? They've been known to assassinate people.
        
           | PhasmaFelis wrote:
           | I can't see the FBI actually killing someone for passing on a
           | used phone. That's a lot of risk for zero benefit.
           | 
           | I can see just generally wanting to stay off their radar,
           | though. Even law-abiding folks can get arrested for being in
           | the wrong place at the wrong time, and you don't want someone
           | to see "passed an FBI-tapped phone to a tech media site" in
           | your file. Or maybe their work requires a security clearance,
           | that could hurt you there.
        
             | Miner49er wrote:
             | Yeah, I didn't mean that they would kill someone over this,
             | just was giving an example of what they are capable of.
        
         | kube-system wrote:
         | I'm guessing that the first person who owned the phone could
         | potentially be a character who doesn't want global attention on
         | their burner phone.
        
         | Pick-A-Hill2019 wrote:
         | "They said they contacted the Australian Federal Police (AFP)
         | in case the phone or the person who sold it was of interest to
         | them"
         | 
         | Seems enough reason to me to not want your name plastered all
         | over the internet.
        
       ___________________________________________________________________
       (page generated 2021-07-08 23:02 UTC)