[HN Gopher] The Dutch government wants automatic permission to t...
___________________________________________________________________
The Dutch government wants automatic permission to target victims
of hackers
Author : croes
Score : 209 points
Date : 2023-06-11 14:10 UTC (8 hours ago)
(HTM) web link (berthub.eu)
(TXT) w3m dump (berthub.eu)
| krm01 wrote:
| wait. so if you are hacked, then the government has a free pass
| to hack you as well? Why do all the reasons that come to mind
| right now fit in the 'bad idea' bucket...?
| jmclnx wrote:
| no kidding, # 1 reason, people will stop reporting hack.
| t0mas88 wrote:
| That's not how it works. It's not "when you report a hack the
| government can now hack you at will". It is: When an
| intelligence agency with a legal warrant to monitor another
| entity that's a severe enough threat to national security sees
| that entity hack you, they can follow along and monitor
| communication from the hacked machine and/or hack into it
| themselves. If enough precautions are taken to limit impact on
| the victim's privacy and only if their right to privacy is less
| important than the national security risk the original target
| poses if not doing so.
|
| Source: Read the source doc in Dutch, it's far more nuanced
| than the English blog post.
| Solvency wrote:
| All you did was use a bunch of words to revise their
| statement to "when you don't report a hack, the government
| can hack you at will."
| nottorp wrote:
| Actually the way t0mas phrased it looks pretty reasonable.
|
| And the stuff about reporting makes no sense. Victims of
| hacks perpetrated by some entity that's worth a national
| security warrant will most likely not notice they're
| hacked.
| loufe wrote:
| Edit:
|
| Title fix suggestion, no longer relevant.
| spacebacon wrote:
| Everyone is a potential honeypot as is. Not clicking anything
| renders you moderately safe.
| DerekBickerton wrote:
| If they spent the money in the right places, i.e helping people
| or organizations get back on their feet after a breach, that
| would be more fruitful. This whole _' we're gonna sit in your
| computer chasing bad guys'_ is just shenanigans.
| rolph wrote:
| this sounds so brilliant.
|
| someone gets hacked, doesnt notice the first time until, a second
| time, sees the attack and goes medieval on the attacker#2[cops]
|
| i anticipate clusterfucks ahead.
|
| only a minority of people even recognize a hack beyond, having a
| slow computer, but those few special people will bork it.
| t0mas88 wrote:
| Contrary to common opinion here I think this is a small thing.
| The way these things work in the Netherlands, an intelligence
| agency would currently not intercept any communication from a
| "stepping stone" hacked by a criminal organisation, because it
| would be outside the scope of their warrant. That's a stupid
| limitation to have because it's very common to perform attacks
| from other hacked machines and not your own. (And for the bad
| guy's connection to such a server to be encrypted and useless to
| intercept)
|
| What's a bit bigger in this thing is that they would be allowed
| to actively hack into such a machine themselves instead of just
| intercepting communications. However that has to be proportional
| with extra emphasis on the rights of the non-target. That
| practically means they can only do it in severe cases and not to
| get information on the non-target.
|
| Those suggesting this could be used to "just" hack random
| citizens are exaggerating. That would not be accepted by the
| oversight agencies.
| LudwigNagasena wrote:
| When the intelligence agencies will eventually abuse the law
| and lose their goodwill, the law will stay there and you will
| get nothing in return for your trust.
| faangsticle wrote:
| This blog is written by someone who used to work for such an
| oversight committee, but left after being ignored.
|
| https://berthub.eu/articles/posts/vertrek-tib/
| lolinder wrote:
| This paragraph captures the crux of the problem for me:
|
| > In addition, whereas previously there was an elevated
| standard for applying powers to non-targets, there is now
| actually a vastly reduced standard compared to actual targets.
| The ex-ante regulator TIB will need to be convinced that it is
| proportional to target organization X. However, any non-targets
| now no longer benefit from an elevated standard. The non-
| targets in fact benefit from no standards at all anymore.
|
| They're going from a situation where it was considered an
| extreme measure to get a warrant to break into a victim's
| machine to a situation where it's now a given that all victims
| of the target organization are themselves targets unless the
| oversight body takes affirmative action to deny it in a
| specific case. If the concern were just about red tape, it
| would make more sense to remove the special protections that
| victims previously had and allow the warrant to be extended
| through the regular warrant process.
|
| This automatic extension solution is a problem because it
| treats the rights of the victims as _lesser_ than the rights of
| the suspected criminals. It treats them as collateral damage
| that can be safely ignored unless someone from higher up
| specifically decides it 's a problem.
| InCityDreams wrote:
| >That would not be accepted by the oversight agencies.
|
| I needed a good laugh this evening, and this was it.
| godelski wrote:
| > because it would be outside the scope of their warrant.
|
| And? Unless the scope of the warrant is immutable then what's
| the issue? It might be a bit slower to get the scope extended
| or get the victim's consent, but it seems far less abusable of
| a situation. It appears as a big deal to me because it is part
| of authoritative creep. Authoritarian powers don't come out of
| democracies overnight, but rather because the pathway to hell
| is paved with good intentions that are abused. The whole point
| of democracy is to distribute power and set up significant
| speedbumps for someone to agglomerate control. Things may seem
| small, but a few small things can form a big thing. If we just
| say that it is small in each of those situations, then the big
| thing happens unnoticed. The better question is how ripe a
| power is for abuse and what could an abuser do with such power.
| This is far more important than intent or even the size of the
| matter.
| bscphil wrote:
| > Those suggesting this could be used to "just" hack random
| citizens are exaggerating. That would not be accepted by the
| oversight agencies.
|
| In most countries, good governance is considered to be writing
| laws in such a way that abuse by the government is a violation
| of the written word of the law, not merely in opposition to its
| spirit or intent as interpreted by the government's own
| agencies.
| jfengel wrote:
| Such things are easier said than done. Humans aren't
| computers. They have far more behaviors, and infinite corner
| cases. Writing laws that cover all of them is incredibly
| difficult, and as soon as you do something pops up that you
| didn't anticipate.
|
| It's the reason all of your license agreements and other
| contracts are so long. Every phrase and sentence is there
| because something went wrong.
|
| It doesn't let them off the hook for the fact that
| legislatures often do badly. But even with the best of
| intentions and the best skill things are still never as
| thorough as a programmer would like them to be, because
| programming people is way harder.
| pessimizer wrote:
| > They have far more behaviors, and infinite corner cases.
| Writing laws that cover all of them is incredibly
| difficult, and as soon as you do something pops up that you
| didn't anticipate.
|
| Pretty irrelevant in this case, where we're talking about
| easy, obvious ways to abuse this rule. Your "it's all so
| complicated" argument relies on ignoring the substance of
| the objections to making ones victimization an opportunity
| to reduce their civil rights, and moving into
| generalization and vague abstraction.
| ftxbro wrote:
| > "automatic permission"
|
| this phrasing sounds wrong somehow
| belter wrote:
| "self-facilitated approval"...."self-endorsed clearance"
| MarkusQ wrote:
| It might make more sense if we consider a physical analog: it's
| already generally the case that the police don't need to get a
| warrant to enter private property in a hostage situation, or when
| there's an active shooter, etc. This doesn't mean it's
| _necessarily_ a good thing in either case, but it's less
| sensational if you don't frame it as something unprecedented.
| wongarsu wrote:
| Those analogs are covered under exigent circumstances. But
| there is no imminent danger attached to a hacking case. This
| feels more like "somebody stole my briefcase, which is
| justification to search my home without a warrant".
| zmgsabst wrote:
| Perhaps less contrived:
|
| Police observed a drug dealer drop off a package in my bush,
| then someone else take it later -- so they can search my
| house, just in case.
|
| Traditionally, searching your house would require a warrant
| based on those events... and likely showing more of a nexus,
| that you were involved.
| lukeschlather wrote:
| Except the briefcase is a computer, and the computer is still
| in your home, and this is about not needing permission to
| search the briefcase even though it's still in your
| possession, because the briefcase has also been stolen and
| may be actively used in committing crimes despite the fact
| that you are not committing crimes and it remains in your
| possession.
| deafpolygon wrote:
| As a citizen, I am concerned. Loosely interpreted, if your
| machine was hacked by a 3rd party - regardless of who it was, it
| is then permitted for the police to hack your device in order to
| determine the _extent_ of the hack.
|
| Very loosely interpreted, it also means they can go after you if
| your bittorrent traffic was found in the traffic of group "X".
| Since sometimes, it is not possible to determine which or what
| traffic is included.
|
| The biggest thing is the last "explanatory memorandum" that is
| attached to the law. While not the law itself, it is in practice
| how the law will be used:
|
| > the permission granted also contains authorization for, during
| the validity of the warrant, to also enter automated works of the
| person or organization targeted by the warrant,
|
| As explained in the article;
|
| > An 'automated work' in this specific Dutch law has an extremely
| broad interpretation and includes such things as phones,
| computers, servers, websites, databases and mailboxes.
|
| This basically means that if you are part of compromised
| traffic/target, then as interpreted legally, it's open season on
| anything you have associated to you.
|
| I really hope this doesn't become standard practice, because it
| will just mean widespread abuses similar to how the DMCA is used
| (but more sinister).
| dukeofdoom wrote:
| Don't mess with me, my husband is a programmer
| https://twitter.com/Soft_Junk/status/1667920263038607360?s=1
| pimlottc wrote:
| "Target" is a bit of a confusing word choice here; "monitor"
| might be better, or "surveil", I think.
| mrangle wrote:
| The FBI has been doing this for a few years, as far as I remember
| cornflake23 wrote:
| [flagged]
| deafpolygon wrote:
| This is ridiculous. How are they going to prevent abuse against
| our own people? THe gov't here is generally _pretty good_ and
| transparent but there are abuses in every level if they think
| they can get away with it.
| superq wrote:
| In other words, don't call for help, because then you become the
| target?
|
| It seems like an incredible perversion of justice.
| Muromec wrote:
| It's more like -- if your machine is part of a botnet, cops can
| legally hack into it too
| wongarsu wrote:
| > In the new situation, hacking, targeted interception and data
| access operations get an automatic extension beyond the actual
| target of the warrant. If a warrant is requested to intercept the
| communications of a specific hacking organization, the warrant
| now also extends to victims of this hacking group. Or, more
| concretely, if your computer gets hacked by group X and there was
| a warrant to intercept the traffic of group X, the Dutch services
| now gain automatic approval to also intercept your communications
| or hack you.
|
| I guess I can see that being useful occasionally, but it also
| seems ripe for abuse. Just plant a mole in a hacker organisation
| of your choice, get a warrant against them, and now you can have
| your mole hack whoever you like, giving you the automatic right
| to hack them and intercept their communications
| throwbadubadu wrote:
| Useful occasionally, without doubt.. but the abuse potential,
| blown proportionality, and then these legislations always only
| know one way. Its never about that this wouldn't be useful to
| the utopian goods vs the criminals. :/
| account-5 wrote:
| That example seems a little contrived, when with the
| legislation used for interception is broad enough to just got
| after the actual target straight away. Seems a long way for a
| shortcut, so to speak.
| 411111111111111 wrote:
| The fear in this regard is more about overreach and stalking
| by officers twisting the law for their own agenda. Dunno
| whenever that's a widespread issue with the Dutch police.
|
| As an example: It's doubtful they could get a warrent for
| their neighbors girlfriend, but now they've got another legal
| way in.
|
| It remains to be seen wherever that's actually going to
| happen though.
| deafpolygon wrote:
| They are good about transparency, but abuses do happen when
| they think no one is looking. Unfortunately for us.
| pmontra wrote:
| How about asking the hacked person for permission to access
| their (other?) communications to prosecute the hacker? Too
| simple? Doesn't scale automatically? But if the latter is the
| case, it's not something to be used sparingly.
| godelski wrote:
| This seems like a better check on the authoritative power
| imo. It can come with gag orders and so on. But no free
| citizen's property should be seized without explicit
| permission or extreme circumstances. But I don't know if the
| Dutch has anything similar to the US's 4th amendment (against
| unreasonable search an seizures). I'd still argue that you're
| not free if the government can just seize your things when
| you have not broken any law, and don't feel like that's a
| high bar. And we all know Goodhart, so I'm sure someone will
| exploit this like the parent suggested.
| im3w1l wrote:
| I'm guessing they don't want the target to know they are
| hacked.
| ipaddr wrote:
| That should not be allowed. Police should give discloser.
| JumpCrisscross wrote:
| > _That should not be allowed. Police should give
| discloser._
|
| This obviously cannot be a boundary condition for
| policing; it's adversarial. The question is whether this
| balances public needs against private rights. My gut
| feeling is the extensions should require court approval
| _or_ disclosure.
| roblabla wrote:
| We're talking about disclosing to _victims_ here. There
| should be no adversarial relationship between the police
| and a hacking victim that I can see.
| lovemenot wrote:
| An organisation might hack some of its allies, who would
| act as a contact canary. Reporting contact by the police
| to their friends.
| mikece wrote:
| Sounds like a great way to cause a massive headache for innocent
| people: hack their computer so the government can then give them
| a digital proctology exam.
| lwn wrote:
| An ex secret service regulator has previously warned the House of
| Representatives (Tweede Kamer) about cheating from the secret
| service so communication of all Dutch citizens can be tapped[1]
|
| [1] (Dutch) https://decorrespondent.nl/13987/de-geheime-diensten-
| bedonde...
| fjfaase wrote:
| This is Bert Hubert [1]. Explaining why he left (in English):
| 'On my resignation as regulator of the Dutch intelligence and
| security services' [2].
|
| [1] https://berthub.eu/
|
| [2] https://berthub.eu/articles/posts/resignation-as-
| intelligenc...
| tinus_hn wrote:
| The Netherlands can barely be described as a state of law,
| considering its absolutely worthless constitution, its
| apathetic senate and its corrupted judiciary.
|
| This is just business as usual, the mainstream media doesn't
| even mention this and nobody cares.
| quantum_state wrote:
| If one makes an analogy of this to gunshot victim and shooter
| scenario, it would show how absurd the government is.
| belter wrote:
| 3 days ago | 65 comments - "NL national security law to grant
| automatic permission for targeted surveillance" -
| https://news.ycombinator.com/item?id=36229557
| waihtis wrote:
| Recall the recent Chinese Volt Typhoon campaign against US
| infrastructure in which the threat actor used US residential
| computers as "proxies" to mask their traffic as coming from
| legitimate, inside the US IP addresses.
|
| I imagine the same type of thinking is behind the justification
| for this.
___________________________________________________________________
(page generated 2023-06-11 23:00 UTC)