[HN Gopher] FBI, partners dismantle Qakbot infrastructure
___________________________________________________________________
FBI, partners dismantle Qakbot infrastructure
Author : mvdwoord
Score : 187 points
Date : 2023-08-29 17:02 UTC (5 hours ago)
(HTM) web link (www.fbi.gov)
(TXT) w3m dump (www.fbi.gov)
| dcow wrote:
| Two questions:
|
| 1. if someone installed Qakbot willingly, does the warrant apply
| (the warrant has what looks to me like specific language limiting
| it to unaware victim's machines)?
|
| 2. if the FBI's justice.exe damaged data on a victim machine
| because of an unexpected configuration, are they liable for
| damages?
| ipaddr wrote:
| If they breakdown your door by mistake who pays the repair
| damages? You do.
| dcow wrote:
| Do you have a citation for that? AFAIU breaking down the door
| is only allowed with a knock-less warrant, in which case it's
| not a mistake.
|
| > An aggrieved citizen might also have a claim for civil
| liability against the officer or the law enforcement agency
| for certain unreasonable actions taken in the search. The
| basis for such claims could include invasion of privacy,
| trespass, or property damage.
| masfuerte wrote:
| A web search turns up loads of cases where the police
| bashed in the wrong door simply because they are morons.
| Here's one that was expensive for them (for the city
| anyway): https://www.boston.com/news/local-
| news/2021/01/13/brighton-f...
| fnord77 wrote:
| that came out of taxpayer's / insurance budget
|
| that did not come out of the police budget
| m4jor wrote:
| Source: history of law enforcement being stupid
|
| - https://ij.org/press-release/after-a-swat-team-destroyed-
| a-t...
|
| - https://www.kiro7.com/news/trending-now/court-rules-
| homeowne...
|
| - https://reason.com/2023/07/27/a-swat-team-destroyed-an-
| innoc...
|
| - etc etc etc thousands of times
| 1970-01-01 wrote:
| 1. Yes.
|
| 2. No, but if they completely botched the module, possibly yes.
| See 17: 17. The FBI Supernode Module and the
| Qakbot Uninstaller do not collect content from the infected
| computers, nor do they alter the functionality of the infected
| computers' operating systems, files, or software, except as
| expressly provided in this affidavit.
|
| Legally, hacking-back is a fairly new concept, and I'm not
| aware of the FBI openly doing it at a 'supernode' scale.
|
| https://en.wikipedia.org/wiki/Hacking_back
| michaelaiello wrote:
| Some more technical details on what we observed here.
| https://www.secureworks.com/blog/law-enforcement-takes-down-...
|
| https://www.secureworks.com/blog/qakbot-campaign-delivered-b...
| 1970-01-01 wrote:
| Qbot/Qakbot/Pinkslip/Whateveritsnowcalled has been morphing since
| the very beginning, 2007/08:
|
| https://www.blackberry.com/us/en/solutions/endpoint-security...
|
| https://www.youtube.com/watch?v=DN9m27nhA00
|
| https://en.wikipedia.org/wiki/BASHLITE
| bdcp wrote:
| Is this the ransomware as a service that was hitting hospitals
| and multiple companies?
| AugustoCAS wrote:
| This is huge. Yesterday The Register published an article [1]
| mentioning that Qakbot was responsible for 30% of recorded
| intrusion attempts since the start of 2023.
|
| [1]: https://www.theregister.com/2023/08/28/top_malware_loaders/
| r3trohack3r wrote:
| The warrant application is one of the coolest, cyberpunk,
| warrants I've read in my lifetime:
| https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
|
| Feels like one of those "in world messages" you find in games
| like Cyberpunk 2077. Could have been written by NetWatch.
|
| We live in amazing times.
| 1970-01-01 wrote:
| Thanks for the link, the fun reading starts on page 12.
|
| I think I'll change my SSID to 'FBI Supernode'
| skilled wrote:
| Not going to lie, it felt pretty boring. When I read your
| comment I thought it was going to be a GFX designed warrant
| with an image of Morpheus offering Neo to take either of the
| pills, while The Silence of the Lambs was playing in the
| background.
| r3trohack3r wrote:
| Even in cyberpunk dystopias, I imagine bureaucracies are
| still bureaucracies.
|
| This just seems very cool to me:
|
| > a. First, the FBI will identify the current Tier 1 servers
| (which are also Qakbot infected victim computers) based on
| information collected by the FBI.
|
| > b. Second, an FBI-controlled computer will contact each of
| those Tier 1 servers using commands built into the Qakbot
| malware and Qakbot encryption keys known to the FBI. The FBI
| will instruct each Tier 1 server to download and install an
| FBI-created module that replaces the "supernode" module in
| the already-installed Qakbot malware ("FBI Supernode
| Module"). The FBI Supernode Module contains a new encryption
| key that will make it impossible for the Qakbot
| administrators to communicate with the Tier 1 servers. The
| proposed warrant would authorize replacement of the
| "supernode" module to allow the FBI to communicate with and
| search infected computers that make up the botnet. The
| proposed warrant therefore also authorizes law enforcement
| officers to seize or copy from the infected computers
| electronically stored information related to the Qakbot
| malware, including encryption keys and server lists used by
| the Qakbot administrators to communicate with computers that
| are part of the Qakbot infrastructure.
|
| > c. Third, the FBI will contact each of those Tier 1 servers
| using commands built into the Qakbot malware. The FBI will
| instruct those Tier 1 servers to communicate with an FBI-
| controlled server (the "FBI Server") instead of the Qakbot
| Tier 2 servers. At this point all communications from
| infected botnet computers will be routed through the Tier 1
| servers to the FBI Server, rather than to the Qakbot Tier 2
| and Tier 3 servers.
|
| > d. Fourth, infected computers subject to this warrant that
| make up the botnet would then communicate with the FBI Server
| instead of the Tier 3 server. As noted above, the Qakbot
| malware instructs the infected computers to contact the Tier
| 3 server every one to four minutes. When those infected
| computers contact the FBI Server, the server will instruct
| them to download a second file created by law enforcement
| ("the Qakbot Uninstaller"). This warrant would authorize this
| action, with the intent that computers in the United States
| that are infected with the Qakbot malware will download the
| Qakbot Uninstaller from the FBI Server via the FBI-controlled
| Tier 1 servers. The proposed warrant therefore authorizes law
| enforcement officers to seize or copy from the infected
| computers electronically stored information related to the
| Qakbot malware, including IP addresses and routing
| information necessary to determine whether the infected
| computer continues to be controlled by the Qakbot botnet.
| tgv wrote:
| That does read a bit like Neal Stephenson.
| kiddico wrote:
| A 3 letter did a thing I like? Quick, someone pinch me.
| firesteelrain wrote:
| "To disrupt the botnet, the FBI redirected Qakbot traffic to
| Bureau-controlled servers that instructed infected computers to
| download an uninstaller file. This uninstaller--created to remove
| the Qakbot malware--untethered infected computers from the botnet
| and prevented the installation of any additional malware. "
|
| That's pretty sweet that they healed hundreds of thousands of
| computers
| 1vuio0pswjnm7 wrote:
| Sometimes I wonder why the American public has to be subject to
| the all the evils of so-called "tech" companies when clearly
| the US government has the personnel to write safe, reliable
| software.
|
| Unlike so-called "tech" companies that can smugly ignore
| Americans' reasonable expectations of privacy in order to
| generate obscene profits, there are laws that prohibit the US
| government from engaging in similar shenangigans. (The
| "shenangigans" should be crimes but money has intervened.)
|
| Even if hypothetical government-issued software might be
| "inferior" to whatever the so-called "tech" companies are
| producing, it would still be "superior" from a legal/regulatory
| standpoint. Americans would have some enforceable rights as
| software users. (Other countries are making some progress.)
|
| Someone is inevitably going to make a wise crack reply about
| government contracting in the US. But I'm not referring to
| contractors. I'm referring to government employees.
|
| We'll also likely see some reply about the technical
| superiority of so-called "tech" company software. But I'm not
| referring to technical superiority, I'm referring to (a)
| legal/regulatory limits on software authors and (b) software
| user rights.
| bredren wrote:
| > there are laws that prohibit the US government from
| engaging in similar shenangigans.
|
| If the laws you're alluding to are steadfast, provide true
| equal protection and are perfectly enforced I could see
| greater reliance on government software tools.
|
| However, history is littered with government agencies failing
| to protect people. Not to pick on the FBI here but the
| organization's own J. Edward Hoover wasn't the most privacy
| focused person. The group's HQ is still named after this
| person.
|
| Perhaps other organizations could be relied on more. People
| have wanted free tax filing software for a long time.
|
| However, even the IRS has been shown vulnerable to take
| actions based on pressure from political forces.
| themagician wrote:
| >"Sometimes I wonder why the American public has to be
| subject to the all the evils of so-called "tech" companies
| when clearly the US government has the personnel to write
| safe, reliable software."
|
| It's not just the American public, it's every computer user--
| everywhere. The reason is because _it 's easy._
|
| There's plenty of secure software and systems out there. It's
| hard to use. The costs outweigh the benefits for most people
| most of the time. We could all be running Qubes or openBSD
| but we don't because it's hard. It's hard to do simple
| things. Most of the world runs on Windows and people are
| logged in as admin. It's a point and click world.
|
| I don't know if the government needs to write software, but I
| do think there is room for a vendor to step up, particularly
| in the business world, with systems that offer ironclad
| security.
|
| IMO we are in an increasingly dangerous world. I'm surprised
| the internet connected world hasn't collapsed yet. Every day
| seems to be a new kind of scam or malware. It takes
| incredible effort to safeguard systems today. One wrong click
| and in 5 minutes your entire life can be destroyed. I'm
| curious what the stats are on malware that has completely
| destroyed businesses. Cyber insurance policies are almost
| necessary now even if you consider yourself a skilled user.
| TylerE wrote:
| Government software is great if you have a decade and a
| billion dollars to spend.
| m_0x wrote:
| Using malware to combat malware.
|
| Hopefully they aren't lying.
| debarshri wrote:
| Anti viruses act like malware anyways
| koolba wrote:
| > Using malware to combat malware.
|
| Though it's only legal when they do it. Pretty sure it'd
| still be a crime if a good Samaritan tried it out.
| paxys wrote:
| Why are you making it sound like that's some profound
| revelation? Law enforcement is allowed to run stings, serve
| warrants and make arrests, you aren't. The military is
| allowed to invade countries and drop nukes, you aren't. Yes
| it is legal when they do it and not some average Joe who
| wants to play hero. That's how the world works, and it is a
| good thing.
| fluoridation wrote:
| I don't believe there's any laws that forbid individuals
| from invading countries and using nuclear weapons.
| glasshug wrote:
| 18 U.S.C. 960
|
| > Whoever, within the United States, knowingly begins or
| sets on foot or provides or prepares a means for or
| furnishes the money for, or takes part in, any military
| or naval expedition or enterprise to be carried on from
| thence against the territory or dominion of any foreign
| prince or state, or of any colony, district, or people
| with whom the United States is at peace, shall be fined
| under this title or imprisoned not more than three years,
| or both.
| fluoridation wrote:
| So what you're saying is that it's legal for an American
| to nuke a country as long as the US is already at war
| with that country.
| glasshug wrote:
| Ha! No, 42 U.S.C. 2122.
| fluoridation wrote:
| Nanny state.
| KRAKRISMOTT wrote:
| [flagged]
| koolba wrote:
| > Why are you making it sound like that's some profound
| revelation?
|
| I've never claimed any of my musings are profound
| revelations. That's an exercise left to the reader.
|
| > Law enforcement is allowed to run stings, serve
| warrants and make arrests, you aren't.
|
| Specifics matter. "The Government" is not some monolithic
| entity. Even "law enforcement" could be local, State
| level, FBI, CIA, or some other part of the executive
| branch. Each has its own restrictions on when and how it
| can operate.
|
| > The military is allowed to invade countries and drop
| nukes, you aren't.
|
| The military is expressly disallowed from interfering in
| civilian affairs:
| https://en.wikipedia.org/wiki/Posse_Comitatus_Act
|
| > Yes it is legal when they do it and not some average
| Joe who wants to play hero.
|
| It's an untested open question whether it's legal for
| them to do it to US civilians or infrastructure that they
| know is owned by US civilians.
|
| It might be the right thing to do. The world might be
| better for it. It might even be decided one day that they
| do in fact have that power (there's a pretty clear
| argument that stopping a botnet qualifies as "Hot
| pursuit": https://en.wikipedia.org/wiki/Hot_pursuit).
|
| > That's how the world works, and it is a good thing.
|
| There's plenty of "ends justify the means" situations
| involving the government that are not good things applied
| more generally. Hence, specifics matter.
| voz_ wrote:
| Yeah, it's part of the social contract? This is a good
| thing. It's the same reason I cant just grab a gun and
| start arresting people as a "good Samaritan".
| flutas wrote:
| I mean, citizens arrest is a thing in many countries.[0]
| Immunity varies, laws vary, but it's definitely a
| thing...
|
| [0]: https://en.wikipedia.org/wiki/Citizen%27s_arrest
| anonym29 wrote:
| There are a LOT of things I'd trust more than a closed-source
| binary executable served by the FBI purporting to help me.
|
| Gas station sushi, a drink from Bill Cosby, a childhood
| sleepover at Michael Jackson's place, a cup of Kool Aid from
| Jim Jones...
| pjc50 wrote:
| As compared to a closed source binary forcibly installed on
| your machine by criminals?
| [deleted]
| micromacrofoot wrote:
| To clarify a little, you mean criminals that _aren 't_ the
| FBI? because otherwise we might get stuck in a loop here.
| neovialogistics wrote:
| I'd trust it a hell of a lot more than a binary originating
| from any other USG letter agency, except maybe OSHA and the
| NWS.
| galleywest200 wrote:
| NASA has a good set of open source projects available for
| public use: https://code.nasa.gov/
| anonym29 wrote:
| Keyword: "open source", as in, you are
| permitted/encouraged to understand what it's doing.
| dcow wrote:
| And the big question is what if your machine is configure in
| a way that is incompatible with the FBI's justice.exe and you
| lose irreplaceable data?
| wutwutwat wrote:
| [dead]
| jstarfish wrote:
| > And the big question is what if your machine is configure
| in a way that is incompatible with the FBI's justice.exe
| and you lose irreplaceable data?
|
| Dude, this is just manufactured outrage. Come on:
|
| > Qakbot delivered additional malware--including ransomware
| --to their computer
|
| Bemoaning the possibility of the cops trampling your
| petunias while responding to the arsonist literally trying
| to take-hostage-or-destroy every square inch of your
| property is being petty.
| dcow wrote:
| I'm not outraged at all. I'm simply wondering.
|
| You analogy isn't accurate. The bot net wasn't burning
| down or bricking machines. It was leeching bandwidth and
| cpu cycles. So a more apt analogy might be animal control
| sniping bunnies off your petunias and hitting a window
| with your family heirloom on display instead.
|
| The only thing about this whole thing that makes me
| double take is that it happened without permission or
| notice. I really wouldn't be happy if I found out tue FBI
| was rummaging around my machine removing files without my
| consent. It's still my property and I'm sure I'd be happy
| to cooperate if the FBI raised to my attention that there
| was malicious software on my machine.
| [deleted]
| smaudet wrote:
| The analogy is not apt.
|
| In most cases the victims were not aware, meaning they
| still had ample use of their proverbial property. This is
| in fact the normally desired state of malware, to act
| like a pest or a leech - your estate suffers but not in a
| very noticeable way.
|
| I think most people would object to their yard being
| turned upside down because some e.g. illegal grasshoppers
| were present...so in that sense yes they should provide
| notice...if able.
|
| Which is where the concept of "estate" falls apart a bit.
| Unless you can positively map every node to a single
| responsible actor, then it is unreasonable to provide
| notice. Furthermore, there are so many components to
| modern tech systems that it is not reasonable that anyone
| would know or care the exact goings on of their systems
| (usually).
|
| That is, if you use the web and execute from it, in some
| sense you cannot (or should not) hold fully liable any
| one entity, in some small sense the malware has turned
| your computer into public property anyways, so the
| actions of the FBI are not entirely unreasonable.
|
| If you cry foul this action then even more so you should
| cry foul the actions of any public update service
| etc...vendor updates always carry a similar risk.
|
| What I could say, if there were some common message
| format for indicating to the user what was to happen,
| then it would be reasonable to require notification of
| such. But likely there is no such thing so mainly this
| argument is rhetorical.
| shadowgovt wrote:
| Legally speaking? While IANAL, looking at the warrant
| issued and signed, the nature of such a loss would be akin
| to any other loss incurred during a search and seizure.
|
| In general, such losses are understood as incidental and
| the searchee is not protected from them. If the police
| smash your front door in, they aren't responsible for
| paying to replace the lock; if they think you hid drugs in
| your wall and take a Sawzall to it, they don't owe you
| drywall. In the extreme, it's been found that if a
| flashbang burns your house down during a raid, they aren't
| liable to replace your house (even if the target of the
| raid wasn't on that property). Warrants basically suspend
| some civil rights temporarily; that's why they require a
| judicial concurrence.
|
| So I have no specific case citation for data loss due to a
| digital search and seizure, but my guess from analogy is
| that if you have an unusual configuration (cracked the
| botnet control program open and stored your private Bitcoin
| key in there?) and the FBI's counter-net wipes your data,
| you will not prevail in a court of law, much as if your
| front door was somehow load-bearing and the cops, upon
| hitting it with the battering ram, knocked your house over.
| But since I can't point to a _specific_ case to give
| precedent, hey, whatever you and the lawyer you can afford
| can argue, I guess. ;)
| kvetching wrote:
| "The FBI Supernode Module and the Qakbot Uninstaller DO NOT
| remediate malware that was already installed on the infected
| computer through Qakbot, such as ransomware or other malware
| that steals financial credentials. However, the Qakbot
| Uninstaller is designed to prevent additional malware from
| being installed on the infected computer through the Qakbot
| botnet by untethering the victim computer from the botnet. "
|
| -https://www.justice.gov/d9/2023-08/23mj4244_application_reda..
| .
| adolph wrote:
| > That's pretty sweet that they healed hundreds of thousands of
| computers
|
| The cynical part of me says that (1) they just installed an NSA
| backdoor in hundreds of thousands of computers; (2) the FBI
| probably didn't even realize it; (3) it'll all come to light
| some years from now when the NSA tooling is leaked by a
| careless contractor and used by various worse actors; (4) but
| the "leak" was NSA's plan all along to spy on said various
| worse actors.
|
| The meta-cynical part of me says all that is way too convoluted
| and I should take off the tin-foil fedora and tip it to m'lady.
| georgeburdell wrote:
| Imagine if a race condition in someone's backend was fixed by
| being slowed down just a little bit by this malware, and then
| the malware issue was surreptitiously fixed by the FBI and it
| broke again
|
| https://xkcd.com/1172/
| pbronez wrote:
| Pretty interesting. I bet there were a LOT of lawyer
| conversations about that.
| nickthegreek wrote:
| FBI's been doing this for awhile now. So far no one has taken
| them to court. I do wonder how that would end.
| pfdietz wrote:
| I wonder if the FBI could legally brick the machines
| involved (particular if some were devices that had never
| been patched.)
| wutwutwat wrote:
| [dead]
| tw04 wrote:
| Given the infected folks in question likely had their
| machines involved in illegal activity, I'm not sure I'd
| want to test it. If someone starts running a meth lab out
| of your unlocked cellar, at what point do you become
| culpable for not knowing?
|
| And are you really going to try to sue the police for
| shutting down the lab and locking the door on their way
| out?
| wutwutwat wrote:
| [dead]
| dcow wrote:
| > And are you really going to try to sue the police for
| shutting down the lab and locking the door on their way
| out?
|
| If the police enter your property without a warrant then
| sure. The potential presence of illegal activity does not
| grant the police special powers to skirt judicial process
| (unless there's imminent danger to someone's life or
| something, obviously). If the police unduly lock you out
| of your own property on the way out then doubly sure.
|
| Obviously most people will be relieved that their machine
| no longer has malware on it (save willing participants,
| which is a different question altogether...). What would
| piss me off is not being notified, and not being given
| the chance to remediate myself (what if the police damage
| other pieces of property on the way and I could avoid the
| damage if I'm simply made aware), etc.
|
| So let's go back to the meth lab example: do you think
| it's okay for the police to show up on your property
| unannounced in the middle of the night while you're
| sleeping to silently shut down the meth lab without
| notifying you that they're trespassing and then slap a
| lock on your basement door behind which you store your
| emergency cash, medical supplies, prescription drug
| refills, personal protection equipment, defensive
| firearms, etc. without leaving the keys or so much as a
| word?
|
| Edit (two more things):
|
| 1. It's possible someone might have been running a copy
| of the botnet for research purposes, so presumably this
| copy is not engaged in illicit activity and only
| installed on lab hardware. I wonder if the FBI's program
| considered this scenario. Maybe they only targeted IPs
| involved in actual DDOS attacks? That'd be cool.
|
| 2. You can question something without implying it's
| wrong. One can both believe the FBI is acting in a
| responsible and just way while also being curious how
| this would play out in court. The fervor in your
| responses seems slightly out of place considering the
| comment you're responding to is simply raising a
| question.
| mandevil wrote:
| Oh hey, look at that, the FBI did get a warrant
| authorizing this action, and signed off by a United
| States Magistrate Judge: https://www.justice.gov/d9/2023-
| 08/23mj4244_application_reda...
|
| Now, are judges sometimes too easy with warrants?
| Certainly. But this is definitely not the same as
| entering your house without a warrant, because the FBI
| did get a warrant. The warrant involves them promising to
| a judge under penalty of perjury that the Qakbot
| Uninstaller they are using makes no further changes and
| collects no additional data on any of the victim
| computers they are running on.
|
| So, the FBI is aware of your concerns and is taking steps
| to alleviate them. Does that make you feel better?
| dcow wrote:
| > Oh hey, look at that (...) Does that make you feel
| better?
|
| What? Why such snide?
|
| I am aware of what happened in this case. I was
| responding rhetorically to GGP since they were presenting
| an abstract scenario where the police show up and shut
| down the meth lab in your basement and then lock you out
| of your property on the way out... My goal was to
| highlight the cases where it is and isn't okay for the
| police to do whatever they want. It's not clear if GGP is
| aware that there are in fact restrictions on what the
| police can do on your private property in the US. And
| that even with a warrant there are limits on how the
| warrant is conducted.
| networkchad wrote:
| [dead]
| tw04 wrote:
| >If the police enter your property without a warrant then
| sure. The potential presence of illegal activity does not
| grant the police special powers to skirt judicial process
| (unless there's imminent danger to someone's life or
| something, obviously).
|
| So like a computer system actively participating in ID
| theft and DDoS attacks?
|
| >If the police unduly lock you out of your own property
| on the way out then doubly sure.
|
| But patching a system doesn't lock the owner out...
|
| >What would piss me off is not being notified, and not
| being given the chance to remediate myself (what if the
| police damage other pieces of property on the way and I
| could avoid the damage if I'm simply made aware), etc.
|
| So you're volunteering your tax dollars for the FBI to
| track down hundreds of thousands of people across the
| globe to let them know their systems were patched? I'm
| not. If this upsets you: don't put unpatched systems on
| the internet?
|
| >So let's go back to the meth lab example: do you think
| it's okay for the police to show up on your property
| unannounced in the middle of the night while you're
| sleeping to silently shut down the meth lab without
| notifying you that they're trespassing and then slap a
| lock on your basement door behind which you store your
| emergency cash, medical supplies, prescription drug
| refills, personal protection equipment, defensive
| firearms, etc. without leaving the keys or so much as a
| word?
|
| You're taking the analogy to a place you know doesn't
| exist. The police don't have a way to notify everyone
| that's infected, expecting them to do so before shutting
| down a major botnet is just silly and arguing for the
| sake of arguing.
|
| Nobody said they were adding a lock, I said they were
| locking the door on their way out: the lock is already
| there, you already have the key. When they patched these
| systems it didn't somehow make the owner unable to login.
| dcow wrote:
| > You're taking the analogy to a place you know doesn't
| exist. The police don't have a way to notify everyone
| that's infected, expecting them to do so before shutting
| down a major botnet is just silly and arguing for the
| sake of arguing.
|
| I don't think I am. If the FBI can remotely execute code
| on my machine then they could certainly drop a
| notification with a link to a page explaining the
| situation and how to remediate. Or they could use any
| number of emergency alert systems to make people aware of
| a potentially harmful botnet. Or they could email the
| owner of the machine instead of running their own
| malware.
|
| Anyway as I've stated I don't really disagree with the
| outcome here. I just don't think your "let the police do
| whatever they want to people's property it's for the
| greater good" mentality is healthy, especially not in the
| US where we very carefully limit the power we grant over
| violence because we recognize property and privacy
| rights.
|
| I'm not arguing for the sake of arguing. I think it's
| fair to ask: "could this have been conducted in a manner
| where people were aware and could have provided consent
| or intervened if necessary and still achieved a similar
| result"?
|
| (Misunderstood you about the lock part, thought you were
| saying they were locking the premises because it was a
| crime scene or something and not notifying you.)
| tw04 wrote:
| >I don't think I am. If the FBI can remotely execute code
| on my machine then they could certainly drop a
| notification with a link to a page explaining the
| situation and how to remediate.
|
| You're making a ton of leaps of faith that a user is
| going to both read and follow the instructions.
|
| >Or they could use any number of emergency alert systems
| to make people aware of a potentially harmful botnet.
|
| So... you want the FBI to reach out to all of the world's
| governments and have them issue an "emergency alert" to
| get people to patch their computers? And you think that's
| a reasonable stance to take?
|
| >Or they could email the owner of the machine instead of
| running their own malware.
|
| And they're getting these email addresses how?
|
| >I just don't think your "let the police do whatever they
| want to people's property it's for the greater good"
| mentality is healthy, especially not in the US where we
| very carefully limit the power we grant over violence
| because we recognize property and privacy rights.
|
| And I think you're arguing for the sake of arguing.
| Literally nobody said "let the police do whatever they
| want with people's property". The machines in question
| were ACTIVELY PARTICIPATING IN ILLEGAL ACTIVITIES. This
| isn't some philosophical debate.
| nradov wrote:
| Police can legally enter private property unannounced and
| shut down a meth lab if it presents an imminent safety
| hazard. This isn't trespassing. They will not be liable
| for any loss you suffer as a result as long as their
| actions are judged to be "reasonable". There is an
| extensive body of case law on this (at least regarding
| physical places, not computers).
| [deleted]
| reaperducer wrote:
| _If the police enter your property without a warrant then
| sure. The potential presence of illegal activity does not
| grant the police special powers to skirt judicial process
| (unless there's imminent danger to someone's life or
| something, obviously)._
|
| I guess you've never heard of "probable cause."
| dcow wrote:
| I have, in fact. _Probable cause_ is what police need to
| have in order for a judge to issue a warrant.
| hinkley wrote:
| Probably at the moment you try to sue them for taking
| away your volunteer meth lab.
| airstrike wrote:
| > If someone starts running a meth lab out of your
| unlocked cellar, at what point do you become culpable for
| not knowing?
|
| The problem with analogies is that they assume they are
| correctly "analogous" but 9/10 times they really describe
| an entirely different situation, making them unhelpful if
| not misleading
| ToValueFunfetti wrote:
| The problem with analogies is that people who disagree
| tend to just say "X is not Y" instead of "X is different
| from Y in this context due to Z". I'm not sure whether
| that is just a social behavior or if saying the second
| thing is especially hard.
| rzzzt wrote:
| A duck is not a horse due to... it not being a horse. You
| can macroexpand Z to "not having four legs", etc., but
| incomparable things will end up being different just
| based on their very essence.
| ToValueFunfetti wrote:
| "Why can't I pull a small wagon with a team of ducks? I
| can pull a large wagon with a team of horses."
|
| Useful answers: Ducks are not as intelligent as horses
| and aren't as easy to train. There is not a good way to
| strap a harness onto a duck for this task. Ducks waddle
| and this introduces turbulence. Ducks have substantially
| less pulling power. etc.
|
| Useless answer: A duck is not a horse because a duck is
| different from a horse.
|
| The person making the analogy knows that it is an
| analogy; it is not the source of confusion.
| airstrike wrote:
| It's not especially hard -- the burden of proof just
| isn't on the listener. Saying "X is not Y" is just saying
| "I'm not convinced, you must do better with your
| analogies". With enough context, one can infer as much
|
| Letting someone run a meth lab in your cellar is pretty
| obviously not the same as "letting" some malware run on
| your box, for crying out loud
| anonym29 wrote:
| >If someone starts running a meth lab out of your
| unlocked cellar, at what point do you become culpable for
| not knowing?
|
| Are you implying that the property owner is liable
| because they neglected to lock the cellar, or because
| they weren't aware a crime was taking place there?
|
| If the former, isn't that as clear an example of victim
| blaming as telling people to carry firearms/protection if
| they don't want to be sexually assaulted?
|
| In a civil society, it is not the responsibility or duty
| of the victim to set up security measures to prevent
| themselves from being victimized. It is the
| responsibility and duty of the culprit to not commit
| those unlawful crimes in the first place.
|
| Bringing the analogy back to security - who is guilty of
| a crime when a ransomware attack happens, the victim, or
| the criminal (who obtained unauthorized access, and used
| that access to perform extortion)?
| shkkmo wrote:
| Landlords can indeed be liable is many ways for some
| kinds of illegal activity that take place on their
| property (especially if it involves drugs.) There are a
| variety of local and federal laws that enable this.
| wutwutwat wrote:
| [dead]
| tw04 wrote:
| >or because they weren't aware a crime was taking place
| there?
|
| If someone is running a meth lab out of your cellar for a
| year, and you don't notice the smell, the power bill, the
| people coming and going, at what point are you no longer
| able to claim ignorance? If your answer is: you can claim
| ignorance indefinitely, what is preventing someone from
| just letting a meth lab be run from their basement and
| taking cash on the side? If the police can't find the
| cash, you're just not guilty?
|
| >It is not the responsibility of the victim to set up
| security measures to prevent themselves from being
| victimized.
|
| It is ABSOLUTELY the responsibility of the "victim" to
| not create an environment that FACILITATES crime. If you
| leave a gun unsupervised and unlocked on your front step,
| and a neighbor kid "steals" the gun off your front steps
| and proceeds to shoot and kill their friend, you are
| going to jail despite you being the "victim" of theft.
| Your internet connection in this instance is the loaded
| gun when your systems are being used in DDoS attacks.
| AndrewKemendo wrote:
| Yes, and there's plenty of case law to support that -
|
| In fact, one of the most popular TV shows of all time had
| its finale specifically addressing the fact that a law
| needed to be made to discourage "bystanders" from
| actively ignoring crime.
| lelanthran wrote:
| Which show was this?
| kevinh wrote:
| Probably Seinfeld.
| nirvdrum wrote:
| Seinfeld.
| dcow wrote:
| > and taking cash on the side
|
| With this statement you're arguing past the person you're
| responding to. If you are taking cash on the side to
| feign ignorance when the DEA comes squawking about the
| meth lab in your basement then you are clearly in the
| know.
|
| Nobody is talking about negligence here. Your rebuttal is
| essentially "well victims can be blamed if they're being
| negligent". Yeah, sure, by definition they're not just a
| victim, they're a negligent individual. (I mean I'd even
| argue they can be blamed for less--I'm not one of those
| 100% the victim is always innocent types, but that's a
| different topic.)
|
| The original question is if you are _honestly unaware
| (and not negligent)_ that your property is being used to
| commit a crime, are you culpable for the crime? The
| answer is a resounding "no".
|
| If someone hacks your PC and installs botnet software,
| and it evades your OS antivirus heuristics and
| protections because it's a sophisticated root-kit, then
| no, you're not culpable.
| tw04 wrote:
| >With this statement you're arguing past the person
| you're responding to. If you are taking cash on the side
| to feign ignorance when the DEA comes squawking about the
| meth lab in your basement then you are clearly in the
| know.
|
| Ironic that you're doing what you accused me of. I didn't
| say the person was taking cash, I asked WHEN op would
| consider the person to be culpable. You literally took an
| entire discussion and clipped four words then made up a
| bunch of stuff I didn't actually say or even imply.
|
| >The original question is if you are honestly unaware
| (and not negligent) that your property is being used to
| commit a crime, are you culpable for the crime? The
| answer is a resounding "no".
|
| That was NOT the original question. The original question
| was whether or not someone could sue the police for
| removing malware and patching their system. My example
| was the cops shutting down a meth lab and locking the
| door.
|
| Be my guest attempting to sue, and be prepared to have to
| defend yourself in a court of law that you were truly
| unaware. That's going to be a VERY expensive proposition
| - so who in their right mind would even start down that
| path?
| ip_addr wrote:
| Here's the application and search warrant.
|
| https://www.justice.gov/d9/2023-08/23mj4244_application_reda.
| ..
|
| https://www.justice.gov/d9/2023-08/23mj4244_warrant_redacted.
| ..
| libraryatnight wrote:
| This was really interesting to read, thank you for the
| links.
| doakes wrote:
| I'm getting 403'd on these links
| AtomicOrbital wrote:
| Links work
| hanniabu wrote:
| It's the government, since when are they concerned about
| legality
| revscat wrote:
| More often than you'd think.
| verve_rat wrote:
| My question: how does a US warrant apply to computers outside
| US jurisdiction?
| paxys wrote:
| They didn't access any random computers outside of their
| jurisdiction, only Qakbot servers.
| paganel wrote:
| I must have missed it, but does the article mention that
| those servers were all located inside the US? (where I
| supposed FBI has jurisdiction for stuff like this).
| [deleted]
| paxys wrote:
| > As part of the operation, the FBI gained lawful access
| to Qakbot's infrastructure and identified over 700,000
| infected computers worldwide--including more than 200,000
| in the U.S.
|
| "Lawful access" is doing a lot of heavy lifting, but at
| least they specified it.
| wutwutwat wrote:
| [dead]
| jagged-chisel wrote:
| Having been around during the 90s Cryptowars (and related
| culture and counterculture) I do wonder if in a few years we'll
| hear that NSA piggybacked some "fun" toys on this uninstaller.
| jszymborski wrote:
| Am I missing something or wouldn't the author(s) of Qakbot be
| able to avoid this attack by cryptographically signing commands
| and having clients check them?
| paxys wrote:
| It doesn't matter. If you gain access to their servers you
| can sign the commands yourself.
| rcxdude wrote:
| Depends on where the key is. Command and control servers
| don't need to have the keys for the commands they are
| relaying.
| datadeft wrote:
| I am pretty sure that is not their top priority.
| chilmers wrote:
| From https://www.secureworks.com/blog/law-enforcement-takes-
| down-...
|
| "To interact with infected hosts, the replacement servers
| required a certificate that can sign messages. It appears
| that the certificates were obtained and used for good
| intentions."
| shadowgovt wrote:
| One of my favorite tricks in dealing with botnets: if you can
| access the control plane, you can convince the network to do
| most anything... Including self-terminate.
| 1-6 wrote:
| Until bot operators learn to encrypt the control plane
| network.
| apstls wrote:
| This was the case here as well.
| [deleted]
| cynicalsecurity wrote:
| [flagged]
| soligern wrote:
| Why? Windows is not inherently less secure than MacOS or Linux.
| psd1 wrote:
| Absolutely false.
|
| If all the world's grannies used Ubuntu, malware writers would
| target Ubuntu, and the spam would include links to Ubuntu
| malware. Same for any arbitrary other OS.
| joemazerino wrote:
| Tell me you haven't worked in an Enterprise environment without
| telling me
| cynicalsecurity wrote:
| My whole life. That's why I'm begging to kill it.
| maximinus_thrax wrote:
| You need to read up on how Pwn2Own came into existence.
| politelemon wrote:
| I wish you a longer life then. There is a lot to learn
| about security, and your conclusions are not among them.
| mvdwoord wrote:
| [flagged]
| codeslave13 wrote:
| Personal attacks arent really called for. I disagree with op
| but really?
| Madmallard wrote:
| he's right in that windows is horrible spyware cancer made
| continually worse by an insanely anti-consumer corporation
| and would be better off gone at this point had it not won the
| capitalism game
| capableweb wrote:
| He's also wrong thinking that malware is more possible on
| Windows than other OSes, rather than that Windows is a more
| popular target because it's the most popular OS in the
| world.
| psd1 wrote:
| That's valid, but the thrust of the top-level comment is
| that the computers are infected because they were windows
| (sounds plausible) with the implication that if windows
| were not the dominant desktop OS, malware would not exist
| (which is improbable).
|
| Malware is only rare for MacOS and Linux because those are
| niche OSes, not because of inherently higher resistance.
| nickthegreek wrote:
| Ahhh yes, there is no way windows could be targeted because it
| is the most popular OS (especially in Business). Removing
| Windows would allow us to live a malware free utopia...
| nilsherzig wrote:
| There already are pretty advanced Linux viruses and I would
| assume that they would be even more advanced and wide spread if
| Linux was the primary desktop os
| coldblues wrote:
| > To disrupt the botnet, the FBI redirected Qakbot traffic to
| Bureau-controlled servers that instructed infected computers to
| download an uninstaller file. This uninstaller--created to remove
| the Qakbot malware--untethered infected computers from the botnet
| and prevented the installation of any additional malware.
|
| So the FBI used unauthorized access to the computers to uninstall
| the malware? Scary if you think about it. I'm sure they could
| have used that access any way they wanted.
| Angostura wrote:
| What would have been a better alternative?
| nicechianti wrote:
| [dead]
| acdha wrote:
| Say I left my car unlocked and it starts spewing smoke - is it
| scary if the fire department break in to put it out? Or if my
| abandoned building is housing rats, is it okay for the city to
| break in and deal with them?
|
| The FBI is far from perfect but this is the kind of thing they
| _should_ be doing, using their unique privileges to help with
| public menaces. Anyone on the internet could compromise them,
| too, so I'd prefer a public cleanup.
| willnonya wrote:
| The problem may be we'll within the FBI domain but their
| resolution crosses some boundaries that are meant to be
| protected. To pull this off the FBI would need to use a
| general warrant rather than a specific warrant as required by
| law.
|
| In your examples none of them invole solving problems that
| you would not be unaware of, in ways that you're not aware of
| without telling you they were there and oh btw they had to
| rifle through your undwrware drawer to fix it.
| acdha wrote:
| > In your examples none of them invole solving problems
| that you would not be unaware of, in ways that you're not
| aware of without telling you they were there and oh btw
| they had to rifle through your undwrware drawer to fix it.
|
| It's pretty common for there to be problems the owner can't
| be reached for - people travel, get hospitalized, die, etc.
| - but that doesn't prevent action. What it can do is limit
| what they're allowed to bring charges for - in your
| example, if they said they were pursuing reports of
| squatters in your house they couldn't search inside your
| dresser since that's not in plain sight.
|
| In this case, I would expect that courts would give the FBI
| considerable leeway for neutralizing a system which is
| being actively used to commit crimes but not to check your
| private data to see if you were cheating on your taxes.
| cool_dude85 wrote:
| It's context dependent. If I'm filming a movie and want to
| get a scene where a car is spewing smoke, and the FD runs up
| while I'm filming to put it out, that is troublesome to me.
|
| It seems like this might be the case here where some
| minuscule portion of the botnet base is security research
| firms / etc. who have a reason to have the botnet software
| installed and don't want it deleted; in fact, it may even
| affect their livelihood to delete it.
| Teever wrote:
| That's a very contrived example.
|
| It's Also why people normally get a permit or at least
| contact officials to tell them that they're going to do
| staging a scene that looks exactly like an accident/crime
| scene.
|
| It isn't a strike against emergency responders for
| responding to a situation that someone has staged to look
| as close to the real thing as possible.
| acdha wrote:
| > It seems like this might be the case here where some
| minuscule portion of the botnet base is security research
| firms / etc. who have a reason to have the botnet software
| installed and don't want it deleted; in fact, it may even
| affect their livelihood to delete it.
|
| This doesn't make any sense to me: no ethical security firm
| is going to allow their resources to be used to attack
| other people, or complain if the FBI shut down the people
| attacking their clients.
| Loughla wrote:
| We have to call the local FD if we want to do a controlled
| burn of a field or fence row. If we don't, nobody is
| surprised when they show up to put out the fire.
|
| I have to imagine this is similar. If your livelihood
| relies on a botnet, and you don't at least let authorities
| know, my guess is you're not a researcher. . .
| [deleted]
| WoahNoun wrote:
| The mythbuster's didn't blow stuff up or set things on fire
| without having the FD there.
| mrguyorama wrote:
| Most of the time they had to have explicit "Bomb Squad"
| presence, and did things explicitly at bomb ranges.
|
| One time they still managed to damage something outside
| of the vast location (an abandoned airport I believe)
| they were working within, and were banned from that
| location.
| bastardoperator wrote:
| Your example doesn't make sense though given the context.
| You can't just light a car on fire for filming purposes.
| You're going to need to at the very least petition the
| local government, get a permit, and follow safety protocols
| that will likely include the presence of the fire
| department.
|
| This reminds me of frivolous lawsuits. A doctor sees
| someone needing medical attention. The doctor performs CPR,
| break some ribs in the process, but ultimately saves their
| life. The person who would have otherwise died, sues the
| doctor for breaking their ribs while completely ignoring
| the good will that saved them from certain death.
| codedokode wrote:
| Today they clean your computer from botnet, tomorrow from
| bitcoin.
| riversflow wrote:
| Yup, and people actually think crypto is viable.
| gwright wrote:
| There are many situations where law enforcement is authorized
| (by law) to do something that would normally be illegal. For
| example here is some language from 18 U.S. Code SS 1030 - Fraud
| and related activity in connection with computers:
|
| > This section does not prohibit any lawfully authorized
| investigative, protective, or intelligence activity of a law
| enforcement agency of the United States, a State, or a
| political subdivision of a State, or of an intelligence agency
| of the United States.
|
| I'm not sure if this is the relevant code for this Qakbot
| incident, I'm just trying to clarify that the law generally
| accepts that law enforcement officials get special dispensation
| from the regular requirements of the law in order to carry out
| their function or to protect the public.
| waihtis wrote:
| They wouldn't need to do any redirecting if they had direct
| access to the computer, they could just directly install the
| patch/fix.
|
| Sounds like they hijacked a malware proxy server and had it
| forward the traffic to their own server.
| poyu wrote:
| Perhaps those computers count as evidence and they don't want
| to mess with it?
| waihtis wrote:
| perhaps, but more likely it's a bit dubious for the FBI to
| penetrate into computers unauthorized, even if the
| intentions are good
| r3trohack3r wrote:
| > So the FBI used unauthorized access to the computers to
| uninstall the malware? Scary if you think about it. I'm sure
| they could have used that access any way they wanted.
|
| The access was always possible. Not just by the FBI. In fact,
| it was already being accessed by the botnet operators. The
| issue here is _permission_ and _precedent_. The government gave
| itself permission to go into these computers and cleanup the
| botnet. What explicit permission did they grant themselves and
| what precedent does that set?
|
| I'm pretty hesitant/paranoid about the U.S. government and the
| powers we (citizens) grant them. But this one surprisingly sits
| right with me. It looks thoughtfully applied and constrained -
| a very tactical operation to go in and cleanup a botnet without
| accessing any unnecessary data in the process.
|
| https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
| ipaddr wrote:
| The access was possible but not legal but they gave
| themselves legal access. It's a slippy slope. They have
| placed an unknown file as well on your computer.
| pjc50 wrote:
| Police have huge amounts of leeway to wreck stuff and kill
| people, which do not appear to have happened in this case
| compared to the mere _possibility_ of abuse.
|
| Meanwhile in the physical world
| https://reason.com/volokh/2021/11/30/federal-court-rules-tak...
| apstls wrote:
| This was clearly a large-scale coordinated effort spanning
| multiple countries, multiple organizations within the US
| including DOJ lawyers, named and unnamed industry partners,
| etc. This is not a context in which a single group could do
| unethical clandestine things without the knowledge and buy-in
| of other parties, nor would it be something the FBI team
| working this case would have any incentive to do. They were
| tasked with dismantling this botnet and removing the malware
| from victim machines, and that is what they did.
| [deleted]
| mzs wrote:
| They got a warrant to run the uninstaller and gather evidence:
| https://www.justice.gov/d9/2023-08/23mj4244_application_reda...
| hanniabu wrote:
| _this_ time they got a warrant
| jordana36 wrote:
| [flagged]
| jordana36 wrote:
| [flagged]
| jordana36 wrote:
| [flagged]
| jordana36 wrote:
| [flagged]
| jordana36 wrote:
| [flagged]
| yafbum wrote:
| Cool use of the botnet's capabilities against itself
|
| But no arrests announced? I wish the people responsible for this
| were made an example of, as opposed to being basically free to
| start over (it seems).
| 0xDEF wrote:
| Most of the large-scale botnet and ransomware activities are
| operating out of Russia. Not exactly a country that is going to
| collaborate with US law enforcement.
| hnburnsy wrote:
| Yes where are the arrests or elimiation of the threat. There
| are 17 three letter agencies listed in Wikipedia entry for DNI.
| Couldn`t one of them worked to `take care` of this botnet
| operator?
| paxys wrote:
| > Couldn`t one of them worked to `take care` of this botnet
| operator?
|
| Unless they want to start a war with Russia, probably not.
| whimsicalism wrote:
| They are probably outside of US jursidiction and also seizing
| servers is much easier than catching a cybercriminal who
| actually knows how to cover their tracks.
| hnburnsy wrote:
| This feels like the fire department congratulating it self
| for putting out fires instead of capturing the arsonist.
| simpleuser27 wrote:
| Isn't that exactly what the fire department should be
| doing?
|
| I don't understand the criticism, could you explain why you
| view this in a negative light?
| rurp wrote:
| Arresting people is a pretty core part of the FBI's job.
| I_Am_Nous wrote:
| I think the point they are trying to make is that there
| will still be fires started by the arsonist, so
| celebrating a single fire being put out while the
| arsonist is likely busy trying to start another fire
| looks bad. Even though, as you point out, the Fire
| Department isn't going to be making any arrests for
| arson, that's the Police Department's job.
|
| I'm not sure the analogy applies perfectly anyway, since
| it was "only" a single "fire" in which "only" 700,000
| victims were affected.
| mrguyorama wrote:
| Russia, North Korea, Iran, and the other places that harbor
| cybercrime enterprises rarely agree to extradition.
| autoexec wrote:
| If it's really finally fully down that's great, but it took
| forever and replacements can be churned out and new networks
| grown in a very short amount of time.
|
| I'm glad the FBI invested 15+ years and who knows how much money
| to rid the world of QBot, but this isn't a scalable solution to
| the botnet problem.
| ryukoposting wrote:
| I don't think it's the FBI's job to figure out a scalable
| solution to botnets. That's our job.
| badrabbit wrote:
| I wouldn't make a big deal out of this, unlike worms, "bots" like
| this will come back after weeks/months because of the number of
| people involved and the spread of the malware "kit" (including
| server side stuff). They are constantly adapting anyways, there
| isn't a fixed set if domains and IPs you can block to stop it
| permanently.
|
| They took down emotet as well but it's had a resurgence.
|
| Qakbot in recent years has shifted to a initial access broker
| monetization scheme where it sells access (cobaltrsike,etc...) to
| more serious actors who will pay the access fee instead of hiring
| talent themselves to do the hacking. So they have a strong
| community of customers. They will need to arrest a lot of people
| at once and hope they got all the people needed to revive it.
___________________________________________________________________
(page generated 2023-08-29 23:00 UTC)