[HN Gopher] The Dutch government wants automatic permission to t...
       ___________________________________________________________________
        
       The Dutch government wants automatic permission to target victims
       of hackers
        
       Author : croes
       Score  : 209 points
       Date   : 2023-06-11 14:10 UTC (8 hours ago)
        
 (HTM) web link (berthub.eu)
 (TXT) w3m dump (berthub.eu)
        
       | krm01 wrote:
       | wait. so if you are hacked, then the government has a free pass
       | to hack you as well? Why do all the reasons that come to mind
       | right now fit in the 'bad idea' bucket...?
        
         | jmclnx wrote:
         | no kidding, # 1 reason, people will stop reporting hack.
        
         | t0mas88 wrote:
         | That's not how it works. It's not "when you report a hack the
         | government can now hack you at will". It is: When an
         | intelligence agency with a legal warrant to monitor another
         | entity that's a severe enough threat to national security sees
         | that entity hack you, they can follow along and monitor
         | communication from the hacked machine and/or hack into it
         | themselves. If enough precautions are taken to limit impact on
         | the victim's privacy and only if their right to privacy is less
         | important than the national security risk the original target
         | poses if not doing so.
         | 
         | Source: Read the source doc in Dutch, it's far more nuanced
         | than the English blog post.
        
           | Solvency wrote:
           | All you did was use a bunch of words to revise their
           | statement to "when you don't report a hack, the government
           | can hack you at will."
        
             | nottorp wrote:
             | Actually the way t0mas phrased it looks pretty reasonable.
             | 
             | And the stuff about reporting makes no sense. Victims of
             | hacks perpetrated by some entity that's worth a national
             | security warrant will most likely not notice they're
             | hacked.
        
       | loufe wrote:
       | Edit:
       | 
       | Title fix suggestion, no longer relevant.
        
       | spacebacon wrote:
       | Everyone is a potential honeypot as is. Not clicking anything
       | renders you moderately safe.
        
       | DerekBickerton wrote:
       | If they spent the money in the right places, i.e helping people
       | or organizations get back on their feet after a breach, that
       | would be more fruitful. This whole _' we're gonna sit in your
       | computer chasing bad guys'_ is just shenanigans.
        
       | rolph wrote:
       | this sounds so brilliant.
       | 
       | someone gets hacked, doesnt notice the first time until, a second
       | time, sees the attack and goes medieval on the attacker#2[cops]
       | 
       | i anticipate clusterfucks ahead.
       | 
       | only a minority of people even recognize a hack beyond, having a
       | slow computer, but those few special people will bork it.
        
       | t0mas88 wrote:
       | Contrary to common opinion here I think this is a small thing.
       | The way these things work in the Netherlands, an intelligence
       | agency would currently not intercept any communication from a
       | "stepping stone" hacked by a criminal organisation, because it
       | would be outside the scope of their warrant. That's a stupid
       | limitation to have because it's very common to perform attacks
       | from other hacked machines and not your own. (And for the bad
       | guy's connection to such a server to be encrypted and useless to
       | intercept)
       | 
       | What's a bit bigger in this thing is that they would be allowed
       | to actively hack into such a machine themselves instead of just
       | intercepting communications. However that has to be proportional
       | with extra emphasis on the rights of the non-target. That
       | practically means they can only do it in severe cases and not to
       | get information on the non-target.
       | 
       | Those suggesting this could be used to "just" hack random
       | citizens are exaggerating. That would not be accepted by the
       | oversight agencies.
        
         | LudwigNagasena wrote:
         | When the intelligence agencies will eventually abuse the law
         | and lose their goodwill, the law will stay there and you will
         | get nothing in return for your trust.
        
         | faangsticle wrote:
         | This blog is written by someone who used to work for such an
         | oversight committee, but left after being ignored.
         | 
         | https://berthub.eu/articles/posts/vertrek-tib/
        
         | lolinder wrote:
         | This paragraph captures the crux of the problem for me:
         | 
         | > In addition, whereas previously there was an elevated
         | standard for applying powers to non-targets, there is now
         | actually a vastly reduced standard compared to actual targets.
         | The ex-ante regulator TIB will need to be convinced that it is
         | proportional to target organization X. However, any non-targets
         | now no longer benefit from an elevated standard. The non-
         | targets in fact benefit from no standards at all anymore.
         | 
         | They're going from a situation where it was considered an
         | extreme measure to get a warrant to break into a victim's
         | machine to a situation where it's now a given that all victims
         | of the target organization are themselves targets unless the
         | oversight body takes affirmative action to deny it in a
         | specific case. If the concern were just about red tape, it
         | would make more sense to remove the special protections that
         | victims previously had and allow the warrant to be extended
         | through the regular warrant process.
         | 
         | This automatic extension solution is a problem because it
         | treats the rights of the victims as _lesser_ than the rights of
         | the suspected criminals. It treats them as collateral damage
         | that can be safely ignored unless someone from higher up
         | specifically decides it 's a problem.
        
         | InCityDreams wrote:
         | >That would not be accepted by the oversight agencies.
         | 
         | I needed a good laugh this evening, and this was it.
        
         | godelski wrote:
         | > because it would be outside the scope of their warrant.
         | 
         | And? Unless the scope of the warrant is immutable then what's
         | the issue? It might be a bit slower to get the scope extended
         | or get the victim's consent, but it seems far less abusable of
         | a situation. It appears as a big deal to me because it is part
         | of authoritative creep. Authoritarian powers don't come out of
         | democracies overnight, but rather because the pathway to hell
         | is paved with good intentions that are abused. The whole point
         | of democracy is to distribute power and set up significant
         | speedbumps for someone to agglomerate control. Things may seem
         | small, but a few small things can form a big thing. If we just
         | say that it is small in each of those situations, then the big
         | thing happens unnoticed. The better question is how ripe a
         | power is for abuse and what could an abuser do with such power.
         | This is far more important than intent or even the size of the
         | matter.
        
         | bscphil wrote:
         | > Those suggesting this could be used to "just" hack random
         | citizens are exaggerating. That would not be accepted by the
         | oversight agencies.
         | 
         | In most countries, good governance is considered to be writing
         | laws in such a way that abuse by the government is a violation
         | of the written word of the law, not merely in opposition to its
         | spirit or intent as interpreted by the government's own
         | agencies.
        
           | jfengel wrote:
           | Such things are easier said than done. Humans aren't
           | computers. They have far more behaviors, and infinite corner
           | cases. Writing laws that cover all of them is incredibly
           | difficult, and as soon as you do something pops up that you
           | didn't anticipate.
           | 
           | It's the reason all of your license agreements and other
           | contracts are so long. Every phrase and sentence is there
           | because something went wrong.
           | 
           | It doesn't let them off the hook for the fact that
           | legislatures often do badly. But even with the best of
           | intentions and the best skill things are still never as
           | thorough as a programmer would like them to be, because
           | programming people is way harder.
        
             | pessimizer wrote:
             | > They have far more behaviors, and infinite corner cases.
             | Writing laws that cover all of them is incredibly
             | difficult, and as soon as you do something pops up that you
             | didn't anticipate.
             | 
             | Pretty irrelevant in this case, where we're talking about
             | easy, obvious ways to abuse this rule. Your "it's all so
             | complicated" argument relies on ignoring the substance of
             | the objections to making ones victimization an opportunity
             | to reduce their civil rights, and moving into
             | generalization and vague abstraction.
        
       | ftxbro wrote:
       | > "automatic permission"
       | 
       | this phrasing sounds wrong somehow
        
         | belter wrote:
         | "self-facilitated approval"...."self-endorsed clearance"
        
       | MarkusQ wrote:
       | It might make more sense if we consider a physical analog: it's
       | already generally the case that the police don't need to get a
       | warrant to enter private property in a hostage situation, or when
       | there's an active shooter, etc. This doesn't mean it's
       | _necessarily_ a good thing in either case, but it's less
       | sensational if you don't frame it as something unprecedented.
        
         | wongarsu wrote:
         | Those analogs are covered under exigent circumstances. But
         | there is no imminent danger attached to a hacking case. This
         | feels more like "somebody stole my briefcase, which is
         | justification to search my home without a warrant".
        
           | zmgsabst wrote:
           | Perhaps less contrived:
           | 
           | Police observed a drug dealer drop off a package in my bush,
           | then someone else take it later -- so they can search my
           | house, just in case.
           | 
           | Traditionally, searching your house would require a warrant
           | based on those events... and likely showing more of a nexus,
           | that you were involved.
        
           | lukeschlather wrote:
           | Except the briefcase is a computer, and the computer is still
           | in your home, and this is about not needing permission to
           | search the briefcase even though it's still in your
           | possession, because the briefcase has also been stolen and
           | may be actively used in committing crimes despite the fact
           | that you are not committing crimes and it remains in your
           | possession.
        
       | deafpolygon wrote:
       | As a citizen, I am concerned. Loosely interpreted, if your
       | machine was hacked by a 3rd party - regardless of who it was, it
       | is then permitted for the police to hack your device in order to
       | determine the _extent_ of the hack.
       | 
       | Very loosely interpreted, it also means they can go after you if
       | your bittorrent traffic was found in the traffic of group "X".
       | Since sometimes, it is not possible to determine which or what
       | traffic is included.
       | 
       | The biggest thing is the last "explanatory memorandum" that is
       | attached to the law. While not the law itself, it is in practice
       | how the law will be used:
       | 
       | > the permission granted also contains authorization for, during
       | the validity of the warrant, to also enter automated works of the
       | person or organization targeted by the warrant,
       | 
       | As explained in the article;
       | 
       | > An 'automated work' in this specific Dutch law has an extremely
       | broad interpretation and includes such things as phones,
       | computers, servers, websites, databases and mailboxes.
       | 
       | This basically means that if you are part of compromised
       | traffic/target, then as interpreted legally, it's open season on
       | anything you have associated to you.
       | 
       | I really hope this doesn't become standard practice, because it
       | will just mean widespread abuses similar to how the DMCA is used
       | (but more sinister).
        
       | dukeofdoom wrote:
       | Don't mess with me, my husband is a programmer
       | https://twitter.com/Soft_Junk/status/1667920263038607360?s=1
        
       | pimlottc wrote:
       | "Target" is a bit of a confusing word choice here; "monitor"
       | might be better, or "surveil", I think.
        
       | mrangle wrote:
       | The FBI has been doing this for a few years, as far as I remember
        
       | cornflake23 wrote:
       | [flagged]
        
       | deafpolygon wrote:
       | This is ridiculous. How are they going to prevent abuse against
       | our own people? THe gov't here is generally _pretty good_ and
       | transparent but there are abuses in every level if they think
       | they can get away with it.
        
       | superq wrote:
       | In other words, don't call for help, because then you become the
       | target?
       | 
       | It seems like an incredible perversion of justice.
        
         | Muromec wrote:
         | It's more like -- if your machine is part of a botnet, cops can
         | legally hack into it too
        
       | wongarsu wrote:
       | > In the new situation, hacking, targeted interception and data
       | access operations get an automatic extension beyond the actual
       | target of the warrant. If a warrant is requested to intercept the
       | communications of a specific hacking organization, the warrant
       | now also extends to victims of this hacking group. Or, more
       | concretely, if your computer gets hacked by group X and there was
       | a warrant to intercept the traffic of group X, the Dutch services
       | now gain automatic approval to also intercept your communications
       | or hack you.
       | 
       | I guess I can see that being useful occasionally, but it also
       | seems ripe for abuse. Just plant a mole in a hacker organisation
       | of your choice, get a warrant against them, and now you can have
       | your mole hack whoever you like, giving you the automatic right
       | to hack them and intercept their communications
        
         | throwbadubadu wrote:
         | Useful occasionally, without doubt.. but the abuse potential,
         | blown proportionality, and then these legislations always only
         | know one way. Its never about that this wouldn't be useful to
         | the utopian goods vs the criminals. :/
        
         | account-5 wrote:
         | That example seems a little contrived, when with the
         | legislation used for interception is broad enough to just got
         | after the actual target straight away. Seems a long way for a
         | shortcut, so to speak.
        
           | 411111111111111 wrote:
           | The fear in this regard is more about overreach and stalking
           | by officers twisting the law for their own agenda. Dunno
           | whenever that's a widespread issue with the Dutch police.
           | 
           | As an example: It's doubtful they could get a warrent for
           | their neighbors girlfriend, but now they've got another legal
           | way in.
           | 
           | It remains to be seen wherever that's actually going to
           | happen though.
        
             | deafpolygon wrote:
             | They are good about transparency, but abuses do happen when
             | they think no one is looking. Unfortunately for us.
        
         | pmontra wrote:
         | How about asking the hacked person for permission to access
         | their (other?) communications to prosecute the hacker? Too
         | simple? Doesn't scale automatically? But if the latter is the
         | case, it's not something to be used sparingly.
        
           | godelski wrote:
           | This seems like a better check on the authoritative power
           | imo. It can come with gag orders and so on. But no free
           | citizen's property should be seized without explicit
           | permission or extreme circumstances. But I don't know if the
           | Dutch has anything similar to the US's 4th amendment (against
           | unreasonable search an seizures). I'd still argue that you're
           | not free if the government can just seize your things when
           | you have not broken any law, and don't feel like that's a
           | high bar. And we all know Goodhart, so I'm sure someone will
           | exploit this like the parent suggested.
        
           | im3w1l wrote:
           | I'm guessing they don't want the target to know they are
           | hacked.
        
             | ipaddr wrote:
             | That should not be allowed. Police should give discloser.
        
               | JumpCrisscross wrote:
               | > _That should not be allowed. Police should give
               | discloser._
               | 
               | This obviously cannot be a boundary condition for
               | policing; it's adversarial. The question is whether this
               | balances public needs against private rights. My gut
               | feeling is the extensions should require court approval
               | _or_ disclosure.
        
               | roblabla wrote:
               | We're talking about disclosing to _victims_ here. There
               | should be no adversarial relationship between the police
               | and a hacking victim that I can see.
        
               | lovemenot wrote:
               | An organisation might hack some of its allies, who would
               | act as a contact canary. Reporting contact by the police
               | to their friends.
        
       | mikece wrote:
       | Sounds like a great way to cause a massive headache for innocent
       | people: hack their computer so the government can then give them
       | a digital proctology exam.
        
       | lwn wrote:
       | An ex secret service regulator has previously warned the House of
       | Representatives (Tweede Kamer) about cheating from the secret
       | service so communication of all Dutch citizens can be tapped[1]
       | 
       | [1] (Dutch) https://decorrespondent.nl/13987/de-geheime-diensten-
       | bedonde...
        
         | fjfaase wrote:
         | This is Bert Hubert [1]. Explaining why he left (in English):
         | 'On my resignation as regulator of the Dutch intelligence and
         | security services' [2].
         | 
         | [1] https://berthub.eu/
         | 
         | [2] https://berthub.eu/articles/posts/resignation-as-
         | intelligenc...
        
         | tinus_hn wrote:
         | The Netherlands can barely be described as a state of law,
         | considering its absolutely worthless constitution, its
         | apathetic senate and its corrupted judiciary.
         | 
         | This is just business as usual, the mainstream media doesn't
         | even mention this and nobody cares.
        
       | quantum_state wrote:
       | If one makes an analogy of this to gunshot victim and shooter
       | scenario, it would show how absurd the government is.
        
       | belter wrote:
       | 3 days ago | 65 comments - "NL national security law to grant
       | automatic permission for targeted surveillance" -
       | https://news.ycombinator.com/item?id=36229557
        
       | waihtis wrote:
       | Recall the recent Chinese Volt Typhoon campaign against US
       | infrastructure in which the threat actor used US residential
       | computers as "proxies" to mask their traffic as coming from
       | legitimate, inside the US IP addresses.
       | 
       | I imagine the same type of thinking is behind the justification
       | for this.
        
       ___________________________________________________________________
       (page generated 2023-06-11 23:00 UTC)