Wednesday, 17 September 2008

Tracking down hackers

An interesting article from CCRC about unresolved cybercrimes. The last three are from 2008, so it may be a bit early to say the offenders have not been tracked down, although as with any type of forensics, time is of the essence. "The 10 Most Mysterious Cyber Crimes" http://www.crime-research.org/news/26.09.2008/3597/ (27 September 2008)
Overall, the article highlights the main difficulty of cybercrime: tracking down the authors.
Comp. with "Cybercrime expert to educate MSU engineers on "Gen Next Terror" "(23 September 2008)

See in comparison "Second TJX hacker pleads guilty" (24 Septembre 2008) and the track for Palin's hacker which seems quite disproportionate in comparison with more damaging cybercrimes that just this one, "FBI Closing In On Palin Hacker " (22 September 2008)
"FBI on the trail of hackers after Palin's emails made public" (The Guardian, 19 September 2008)

and for statistics by DOJ (US) in september 2008

Hackers and their skills for policing purposes

A recurrent theme, this time in New Zealand,
"New Zealand Hacker Released As Police, Judge, Prosecutors All Praise His Mad Hacking Skillz"(16 July 2008)
as the charge was dropped "NZ teenage hacker charges dropped " (BBC, 16 July 2008)

see also my post of 14 March 2008

Saturday, 30 August 2008

Criminal responsiblity for lack of security features?

A recurrent idea, with the FTC (in the US) putting it forward once more. Note that the COnvention of cybercrime lets the member states parties free to narrow the offences (hacking and misuse of computers) by including a condition, that of having up-to-date security features. Now the problem is what is up to date?
http://www.techdirt.com/articles/20080825/2320012094.shtml (26 August 2008)

In the same line of thought is the comment of a Nigerian official who points out that victims of 419 scams should be held responsible "Nigerian Official Blames The Victims Of Nigerian 419 Advance Fee Scams" http://www.techdirt.com/articles/20080822/0315012062.shtml (22 August 2008)

And earlier, "Banks slip through virus loophole" (TheGuardian, 12 June 208): "A quiet rule change allows British banks to refuse to compensate the victims of online fraud if they do not have "up-to-date" anti-virus protection, says Danny Bradbury"

Hacking - insiders

"Bank Changes Man's Password After They Realize It Insults Them" http://www.techdirt.com/articles/20080828/0938222122.shtml (28 August 2008) and for the BBC link as the case is in the UK
http://news.bbc.co.uk/2/hi/uk_news/england/hereford/worcs/7585098.stm

  1. The employee does not work for Lloyds anymore. Has disciplinary action been taken? Concerning criminal proceedings, the behaviour falls under the CMAct 1990, for the employee modified computer data without authorisation
  2. Althought there has been no harm here (just a change of password without taking money or the like), the facts illustrate that crime can be generated from the inside. Security policies must be stronger to avoid this type of situation, despite a survey stating that insider crimes diminish "Insiders No Longer The Biggest Threat To Computer Networks" (TechDirt, 17 June 2008)

Scams -Nigeria and the challenge of cybercrime

An interesting article, a bit non-mainstream when it comes to cybercrime in Africa. The Nigerian commission admitted that cybercrime was a challenge difficult for its Government to tackle. Not often authorities admit that.

http://www.crime-research.org/news/27.08.2008/3537/ (27 August 2008)

although one can validly argue that victims are now really fools to fall for 419 scams after all the publicity surronding them for the past few years. http://www.techdirt.com/articles/20080822/0315012062.shtml (22 August 2008) "Nigerian Official Blames The Victims Of Nigerian 419 Advance Fee Scams"

Friday, 29 August 2008

Hacking (Nasa hacker) - jurisdiction and policies

The last hope of hacker McKinnon vanished today. The ECtHR rejected his emergency appeal from the House of Lords' decision on his extradition case. Obliged to be tried now in the US, Mr McKinnon faces an unenvious position in a country where plea bargaining is rife. Having refused the plea made to him, the sentence is likely to be less lenient, especially if the prosecution is exasperated by the litigation process.
Three things here interest me:
  1. First, Mr McKinnon's admission that he hacked but to find documents on UFOs. In strict terms of criminal law, his motive (UFOs, pure fun, or terrorism) bears no influence on the existing offence. Mens rea, the mental component of an offence, discards motives which cannot be its component. Motives may come into play later, as an excuse (insanity for example) or justification. This is why the Asperger's syndrome argument becomes important as a ground for an excuse (constraint? barely insanity in today's understanding of the defence)
  2. Second, the procedural aspect of the case. 95% of criminal cases end up in a plea; plea bargaining is supposed to be a transaction between two parties and a minimum of fairness is supposed to exist, rules of the Supreme Court. But the conception of fairness is relative, especially in the eyes of Europeans: American fairness in relation to plea bargaining is not often perceived, rightly or wrongly, as fairness in the sense of ENglish law or European Human Rights. Pressures are great to accept the plea and not to do so is taking a huge risk.
  3. It is unclear what has been the attitude of the authorities. Pressure was claimed to have been exercised. Mistatements were supposedly made about the extent of the hack and its threat...

Overall, let's hope one thing: that Mr McKinnon's misapprehensions of his original actions does not cost him more than it is necessary. He should not be sanctioned for the symbol that some may want to see of him in the fight against cybercrime; he should be sanctioned for his actions only, not for political or policies reasons. He hacked into the computers; this is an offence. If hacking into governmental networks is an aggravating circomstance, fine; it is not, then he should be left alone.

"US: tackling cyber-crime" (22 August 2008)

http://news.zdnet.co.uk/security/0,1000000189,39475039,00.htm (28 August 2008)

http://www.crime-research.org/news/29.08.2008/3542/ (29 August 2008)

Earlier, "Nasa hacker to fight US extradition on Monday" (ZDNet.uk, 13 June 2008)

Crime in virtual world

Back from holidays, late on posting, but could not resist this one: according to McAfee, one of the multiple anti-virus companies, illegal behaviours are now numerous. Viruses, scams, phishing etc... all flourish and it is not a virtual behaviour. The financial consequences are real because virtual currency can be converted into "real" currency. Maybe it should be time to stop talking of virtual and real, and use concepts like "online"/"offline" currencies, both being real in their existence, and not always immediately tangible.
http://news.zdnet.co.uk/security/0,1000000189,39466789,00.htm

Monday, 21 July 2008

Fraud & social networking

Nor surprisingly, people still fall for Nigerian Scams, not aware that the new forms they take, using social netwoking tools, do not conceal the fact they remain scams. "Nigerian 419 Advance Fee Scammers Move To... LinkedIn?" http://www.techdirt.com/articles/20080602/0003451286.shtml (4 June 2008)


whether fake profiles on facebook are illegal depends on the offences looked at. Defamation/libel could be constituted providing the contents fit the description of libel and are not merely a joke. they could also be an instrument to fraud if they help attracting potential victims to depart with money "Is A Fake Facebook Profile Illegal?" http://www.techdirt.com/articles/20080604/0152031306.shtml (5th June 2008)

Saturday, 19 July 2008

Recurring behaviours: fraud?

An interesting case for a lawyer.. Does taking a few pennies (legally each time) constitute fraud? The answer is yes if there is a scheme to defraud. This is a typical case of an offence by habit: the isolated behaviour is not in itself illegal (it can be, like practising medecine illegally, but the offence often is punishable only after the behaviour has been repeated twice); its repetition makes it illegal because a pattern emerges and an intention to behave illegally appears. In this, case, to use the possibility to take legally one penny numerous time to obtain money (plus under false identities) clearly is fraud. "Is It Fraud If You Collect One Penny Legally Over And Over Again?" http://www.techdirt.com/articles/20080528/0134101246.shtml (28 May 2008)

Web2& Social networking: helping police?

OK, I can't find the post about it; so here we are. "City Council Tells 'Dumbest Criminal' To Stop Posting So Much Evidence To YouTube" - Leeds city council seems to be also dumb? http://www.techdirt.com/articles/20080521/1350411194.shtml (22 May 2008) http://www.dailymail.co.uk/news/article-1020951/Britains-dumbest-criminal-banned-boasting-offences-internet.html?ITO=1490

But a more direct move from a social networking site is not funny at all: people have been banned because of their age (over 36) for fear of porn and sex abuse. Apart from the ridicule of the situation (how on earth all over 36 can be suspected?), it is a pretty dangerous move: it's called private justice for fear of prosecution. "Social Networking Site Bans Anyone Over Age 36 To (Sorta) Deal With Sex Offender Law" http://www.techdirt.com/articles/20080522/2356201207.shtml (23 May 2008)

Hate crime and terrorism

The new trend, at least in the US, is to tackle hate crime via terrorism, by redifining some discourses as terrorist, instead of hate. The assimilation is dangerous for what is terrorism one day can become legal the next, and what is labelled terrorism does not necessarily promote hatred although it often does so. "Senator Lieberman Tries Hunting Down Terrorist Videos On YouTube" http://www.techdirt.com/articles/20080519/1810061172.shtml (20 May 2008)

Tuesday, 15 July 2008

Fraud: new trend or beyond credit card data

See "Forget Credit Cards, Scammers Now Want Your VoIP Accounts?" (15 May 2008) http://www.techdirt.com/articles/20080514/1756561118.shtml

although the old way remains profitable "Stark warning as UK faces cybercrime boom" http://news.zdnet.co.uk/security/0,1000000189,39431415,00.htm?r=1 (9 june 2008)

Investigation and security

Not sure I agree entirely with the comments below. That police forces have USB keys to enter Microsof products' security features does not necessarily mean that criminals will jump on the loopholes. To take an analogy, for police officers to wiretap never meant that criminals had eavedropped more... A shield can always become a sword in the wrong hands, but it does not mean it should not exist.http://www.techdirt.com/articles/20080429/095514977.shtml (29 April 2008)

Cybercrime and the EU

The COuncil of Europe created the Convention of Cybercrime. Time for the EU, despite the drawback about the treaty of Lisbon, to look at cybercrime a bit more seriously than it has done so up to now.
A study is expected: http://www.crime-research.org/news/02.05.2008/3344/ (2 May 2008)

and the Commission recently took a Framework Decision about cyber attacks in order to clarify legal issues to facilitate responses to crime http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=COM:2008:0448:FIN:EN:PDF (14 July 2008)

Sunday, 13 July 2008

Cyber-Investigations and human rights

To monitor the internet to detect (and deter?) crime seems a good idea at first sight. Yet objections are many:

  • practical objection: is it realistic to consider being able to control the internet? It's like wanting to monitor the mail correspondance of users throughout the world. Can we imagine the FBI or Europol controlling data held by post offices? Inachievable and therefore a pretence. I don't see how the physical world of letters could be much different from the cyberworld.
  • second practical objection: how on earth can you succesfully detect crime when faced with a mass of information? the old fashioned way of doing detective work (on the web understandibly) is a much more efficient than trying to cast a net so vast it would take centuries to find the problematic fish.
  • theoritical objection: again, parallels with the so-called physical world enlighten thoughts. Data "held" by post offices are private even when their contents are terrorist or criminal; why should data on the web not considered as private and thus submitted to the same regulations as for obtaining private correspondance? Where are the human rights?

And yet the FBI seriously considers asking the ISPs retention of data http://www.techdirt.com/articles/20080423/184451932.shtml (23rd April 2008)

as well as Russia's authorities who would even go further by blocking traffic like China does http://www.techdirt.com/articles/20080423/185834933.shtml (24th April 2008)

Similar problem with the 9th U.S. Circuit Court of Appeals (so federal law) agreed to let searches of laptop with no specific purposes that looking in the hard drive. Why should we set up conditions for the search of a house, but not the search of a computer when nowadays the computer is like a portable home with sometimes all the documents one needs? Where are the human rights of the accused here? Gone with the wind of fear of crime...

"Is This The Best Homeland Security Can Do In Defending Laptop Searches At The Border?" (TechDirt, 10 July 2008)

http://www.techdirt.com/articles/20080422/235343924.shtml (23rd April 2008) with an update for the Electronic Frontier Foundation asks for Congress to intervene http://www.eff.org/press/archives/2008/05/01 (1 May 2008)

Social networking, privacy and investigations

For once, I can stop criticising social networking. Manchester Police force uses Facebook in an innovative way, to promote communication and gather information about crime; http://www.facebook.com/apps/application.php?id=9878600737&ref=s
I wonder how effective it is and if privacy, which is the biggest problem on social networking, can be maintained. I would be curious to see the results of any study made on this matter.
http://www.techdirt.com/articles/20080418/164250892.shtml (21st April 2008)

As an illustration of privacy issues, see this acknowledgment by Facebook that spammers' attacks increased, notably because the users' contact details such as e-mail adresses are available even if the users have not opted for such "transparency". "Facebook admits to increased attacks by spammers" http://news.zdnet.co.uk/security/0,1000000189,39397448,00.htm (22 April 2008)

And this is without counting on the fact that users often do not realise Facebook is about publicity not keeping details private. See this story about a US military who published photographs of his base!! http://www.techdirt.com/articles/20080423/183304931.shtml (23rd April 2008) or those Oxford students the University disciplined after scrolling Facebook postings http://www.techdirt.com/articles/20080504/2148451026.shtml (6 May 2008)

So it's not surprising that the University of Wales launches academic studies of the social networking phenomenon in relation to cyber security http://www.crime-research.org/news/09.05.2008/3355/ (9 May 2008)

Yet the reaction from N-Y to punish those incriminating themselves on YouTube (I agree, it's not social networking in the proper sense- but its audience makes it similar to social networking) is quite surprising . How can such crime deter people to put videos of illegal activities? What is the purpose of such potential legislation? "New York Wants To Punish Criminals For Incriminating Selves On YouTube" (13 May 2008)http://www.techdirt.com/articles/20080512/1802591092.shtml

Monday, 23 June 2008

Botnets - DDOS

on the phenomenon of botnets, describing its key feature (the difficulty to track down who did what and with or without a criminal intention), see FBI cyber division's sparse comments http://www.crime-research.org/news/16.04.2008/3312/ (16 April 2008)

Cyberterrorism - Definition

An interesting comment about cyberterrorism by the Estonian defense ministry official Christian-Marc Liflander. For him, the last year attack on Estonia belongs to the realm of cyberterrorism; but as pointed out by Stephen Cummings, director of the British government's Centre for the Protection of National Infrastructure, this is far from certain. I would agree: not sure the evidence points out towards terrorism; to threaten governmental institutions does not by itself constitute terrorism - there must be an additional element, that of inspiring terror to the civil population. Although attacking official institutions is often linked to this purpose, the two can be separated. Finally, Mr Liflander partly contradicts himself as he said that little evidence can be gathered about where the attacks came from; so if no evidence of who did it, how can there be evidence of a purpose to terrorise?

http://www.crime-research.org/news/17.04.2008/3316/ (16 April 2008)

compare with the FBI assertion that the internet is used by terrorists groups to communicate, which seems to suggest that it is rarely used to attack institutions: http://www.crime-research.org/news/16.04.2008/3312/ (16 April 2008)


Related to terrorism is the question of national security. The US, or at least some US MPs, seem to have a broad vision of security and include governmental websites. Timothee Lee, from Techdirt, disagrees on the basis that those websites are not linked with the military's protocols on the net. Well, I would argue that it depends of what those websites are supposed to do. If they are the main portal to a wide range of services less and less available in the "physical" world, they may be considered as primary and integrated part of the life of a nation. The building of a city hall or city council where Government offers a range of services could be classified as national security; why not the websites? Maybe the question is linked with what we mean by national security: military or beyond?
Keeping Defense.gov Up Isn't A National Security Issue http://www.techdirt.com/articles/20080518/1934151159.shtml (21 May 2008)

Tuesday, 15 April 2008

Tangible/intangible? digital goods' nature at stake

Given that the debate in criminal law always turns towards the tangible/intangible nature of what is stolen, deceived..., this proposal from a Californian politician is quite interesting, although at first sight it does not concern criminal law, but simply tax law.

"California Lawmaker Wants To Change Law To Tax iTunes; Pretending Infinite Goods Are Tangible" (9 April 2008) http://www.techdirt.com/articles/20080408/152311789.shtml

Fraud and crime - statistics

As noted in David Wall's new book on Cybercrime - The transformation of crime in the information age -, statistics about e-crime are scarce; so it is interesting to have those of the joint research of the FBI and the NWCCC, in the 2007 Internet Crime Report. Fraud, not surprisingly, is the trendy crime (= big money for small efforts to make. See http://www.crime-research.org/news/07.04.2008/3294/ : “A cyber criminal is only looking for a less than 1% return on all the e-mails he sends out, because he can still make money hand over fist,” said Hambrick, FBI -); but surprise, surprise, the UK is on top of the list as a harbour/haven for criminals.

"UK nears US in cyber-crime, ahead of Nigeria, Romania" (10 April 2008)
http://www.crime-research.org/news/10.04.2008/3303/
"UK a hotbed of cybercriminal activity" (9 April 2008)
http://news.zdnet.co.uk/security/0,1000000189,39382596,00.htm

Will that make the Government think a bit more about establishing a specific task force? or at least give money to tackle more efficiently the problem? Or at least the police? See this article about what seems to be the US:
"Cyber crime: Police not taking it seriously" (8 April 2008)
http://www.crime-research.org/news/08.04.2008/3299/

For more statistics: "Cybercrime Losses Decline for Third Consecutive Year " (31 March 2008) http://www.crime-research.org/news/31.03.2008/3282/